Free

Ten checks. No score.

Paste a token, a policy, or a URL. Client tools never leave the browser. URL tools use the same SSRF guard as the scanner, persist nothing, and never run RLS or API recon. When you want the X-ray, see the whole map.

~60 checks in a full scan · 40+ secret patterns here. Not 150. Not a grade.

  • Decode a token you paste. Nothing is sent. Unsigned and long-lived tokens are called out.

    stays in the browser

  • Find provider keys in a paste. Matches stay in the browser; we show the name and the length, never the value.

    stays in the browser

  • Paste a Content-Security-Policy, or fetch one from a URL. Points at unsafe-inline, wildcards, missing object-src and base-uri.

    stays in the browser

  • HTTPS, CSP, HSTS on the first response. The floor of the house.

    one URL, nothing saved

  • OPTIONS with a foreign Origin. Flags * , reflected origins with credentials, and Origin: null.

    one URL, nothing saved

  • RFC 9116 — is there a Contact, and has Expires passed?

    one URL, nothing saved

  • Does the chain validate, and how many days until it expires.

    one URL, nothing saved

  • SPF, DMARC and MX on the registrable domain. No DKIM guessing.

    one URL, nothing saved

  • Who may issue certificates for this domain.

    one URL, nothing saved

  • Fetch a third-party script or stylesheet and return the integrity hash. We do not store the file.

    one URL, nothing saved

Tools — VibeCheck