URL Protocol Checker
Paste a list of links and see which protocol each uses and whether it is a problem. The checker flags insecure http and ws links, dangerous javascript:, vbscript: and data: URLs, protocol-relative and local-file links, and recognises contact and app schemes. Insecure web links are rewritten to https for you to test.
- Runs in your browser
- No sign-up
- Free to use
Only the text is analysed. No connection is made to any of the addresses.
| URL | Protocol | Assessment |
|---|
How to use URL Protocol Checker
- Paste links, one per line.
- Read the protocol and assessment of each.
- Check the summary counts.
- Copy the https versions of insecure links and test that they work.
URL Protocol Checker features
Every scheme
https, http, wss, ws, ftp, sftp, file, data, javascript, mailto, tel and custom app schemes.
Security assessment
Secure, insecure or dangerous, with a reason.
Mixed-content help
Lists http resources that an https page cannot load.
https rewrite
Insecure web links rewritten for testing.
Summary
Counts per category.
Offline
No connection is made to any address.
When to use URL Protocol Checker
- Auditing links exported from a website before switching to HTTPS.
- Finding mixed-content resources on an https page.
- Checking user-submitted links for script URLs.
- Reviewing links in e-mail templates.
URL Protocol Checker FAQ
Why is http a problem?
Traffic is not encrypted, so it can be read and altered on the way. Browsers mark http pages as not secure and block http resources on https pages.
Why are javascript: URLs dangerous?
They run code when the link is opened. If an application lets users supply links, javascript: URLs are a classic way to inject scripts (cross-site scripting).
What is a protocol-relative URL?
One starting with //, which inherits the page’s scheme. It was a workaround in the past; today https:// should be written explicitly.
Does the tool check whether the https version works?
No. It works only on the text. Test the rewritten links, or use the HTTP Status Checker on this site.
Are mailto: and tel: links unsafe?
No, they open the visitor’s mail or phone app.
Is anything sent?
No.
The scheme decides how a link behaves
The first part of a URL, up to the colon, decides what happens when someone follows it. https and wss connect over encrypted channels; http and ws send everything in the clear; mailto and tel hand over to another application; javascript and data do not fetch anything at all but run or display content directly.
On a modern website, unencrypted links are a liability. Search engines prefer HTTPS, browsers warn about plain HTTP, and an HTTPS page that loads scripts, styles or images over HTTP suffers mixed-content blocking. Finding every remaining http:// link is a routine part of a migration.
Script URLs are a security issue, not just a quality one. Applications that accept links from users must reject javascript:, vbscript: and data: schemes or they open the door to cross-site scripting. A quick pass over stored links with this checker shows whether any have slipped through.
The rewritten https list is a starting point. Most sites serve the same content over HTTPS, but not all, so test the rewritten links before replacing them.