Google Safe Browsing
Whether the URL is on Google's malware, phishing or unwanted-software blacklist — the list that triggers the full-page red warning in Chrome and Firefox.
Enter an address and get an honest report in about ten seconds: Google's blacklist verdict, HTTPS and header configuration, the software versions your site is advertising, and any injected-script patterns in the HTML.
Whether the URL is on Google's malware, phishing or unwanted-software blacklist — the list that triggers the full-page red warning in Chrome and Firefox.
Whether the page is served over TLS, and whether anything on it still loads over plain HTTP, which browsers block or downgrade.
HSTS, Content-Security-Policy, X-Content-Type-Options and clickjacking protection, with the exact header to add for each one missing.
Whether the page announces which CMS and version it runs. That is how automated attacks choose their targets.
Obfuscated eval calls, hidden iframes and long encoded payloads — the shapes injected scripts usually take.
Server and X-Powered-By headers that tell an attacker what you are running before they have tried anything.
Send the report over. I will tell you what actually matters, what can wait, and what it costs to put right — including when the answer is that it does not need doing.