SYS:susipere.de./en/journal/free-server-health-check/

We built a free Linux server health check

A free, read-only script that audits a Linux server for dead vhosts, TLS and firewall gaps — including what it found on our own: 0.3% swap free.

Try it now, on your own box, in about 5 seconds:

curl -fsSL https://susipere.de/tools/server-report.sh | bash

Prefer to read it before running it? Same script, no pipe:

curl -fsSL -o server-report.sh https://susipere.de/tools/server-report.sh
less server-report.sh
bash server-report.sh

No install, no signup, no account. It's a static shell script (https://susipere.de/tools/server-report.sh) that runs entirely on your machine and prints a report to your terminal. Nothing is uploaded anywhere — we never see the output unless you paste it to us.

What it checks

  • what's actually listening, and whether it's reachable only from the box itself (loopback) or from the public internet
  • nginx vhosts that route to a backend that isn't actually running — a dead service still standing behind a live-looking URL
  • memory and swap headroom, disk pressure per mount
  • TLS certificate expiry per vhost, and whether renewal is actually wired up — not just installed once and forgotten
  • systemd units that are enabled-but-failed, or flapping (restarting repeatedly)

Root is optional. Without it, the firewall and cert checks are skipped with a one-line note — it never guesses.

What it found on our own server

We ran it against the box this site runs on before publishing it, and re-measured again while writing this, as of 26 September 2026. Two numbers we're not going to round off or hide: swap at 0.3% free (6,872 kB free out of 2,097,148 kB total), and Committed_AS at 8,316,240 kB against a CommitLimit of 4,101,756 kB — 202.7% of the kernel's own commit limit. That second one means the processes on this box have collectively promised more memory than it can ever actually back — it runs fine for months on that kind of optimistic overcommit, right up until it doesn't.

We're publishing our own numbers because a tool that only ever finds problems on other people's servers isn't a very convincing one. This is the exact class of finding the €750 audit exists to chase down and document — the free script's job stops at telling you it's there.

What it can't tell you

  • It's a local self-check. It can tell you a route points at a backend with nothing listening; it can't tell you whether a firewall or cloud security group would actually stop a probe from the outside. Closing that gap without phoning home or scanning your IP without consent isn't something a script that runs once and exits can do — that's what the paid audit is for.
  • The reverse-proxy check only understands proxy_pass http(s)://host:port pointed at a loopback address. Unix-socket backends, non-nginx proxies, and remote upstreams aren't checked — it says nothing about them rather than guessing.
  • Run it without root and you'll get a shorter report; that's disclosed in the output itself, not silently swallowed.

Why a script instead of a hosted scanner

We considered a "paste your server details, we'll scan it" hosted version. We rejected it: it would mean taking in a stranger's system data and running new inbound load on our own infrastructure — the same infrastructure this script was written to distrust. A static file that runs on your machine moves all of the compute and all of the exposure off ours. It's two files, about 18 KB together, and adds zero new processes or listening ports to the server that serves it.

Verified, not assumed

Read-only and no-network were not just intentions — we checked:

  • Ran it inside a network namespace with no route to the outside world. It completed normally. If it depended on any outbound call, this would have hung or failed.
  • Ran it inside a mount namespace with the hostname changed and the certificate/nginx config hidden, to see how it behaves on a machine it knows nothing about. No crash — the sections it couldn't determine printed exactly that, instead of guessing.

One honest gap: both of those are namespace isolation on the same machine, not a genuinely separate host. We don't have a second box to test against yet. If that changes, the caveat goes.

What the script can't see

That's the paid audit: €750, fixed price, one server. €1,200 for two.

The offer page isn't live yet. Want it now anyway? Reach us at susipere.de/kontakt — there's nothing to buy or sign up for yet, just a way to talk to a person. The script above stays free regardless, and it's useful on its own.

cd /en/journal