We check every product on this page once a day and record whether it still answers.
An open-source runtime for building and running production AI agent systems, for developers who don't want to hand-roll retrieval, memory, and execution logic.
Open sourceSelf-hosted
What to know▼
How it works
Handles retrieval, memory, model routing, and verification instead of hardcoded pipelines
What's different
Self-hostable, open-source, with governed execution including planning, verification, and replay
Best for
Developers building production AI systems in Python or Go
We check every product on this page once a day and record whether it still answers.
Local macOS scanner that blocks secrets and PII from leaking into AI coding-tool prompts, for engineers who don't want to rely on cloud DLP.
FreeWorks offline
What to know▼
How it works
A macOS app that scans prompts in real time before they reach AI coding tools like Cursor, Claude Code, and Copilot, flagging leaked API keys, credentials, and PII using 47 local detection rules in under 50ms.
What's different
Detection happens on-device before data leaves the machine, and uses soft notifications instead of hard blocks so it doesn't interrupt the coding flow.
Pricing
Free 15MB macOS application for engineers; an early-access dashboard is offered separately for organizations.
Best for
Engineers using AI coding assistants who want to avoid pasting live secrets into prompts.
We check every product on this page once a day and record whether it still answers.
Monitors your website's uptime, SSL, DNS, and email deliverability, and gives specific repair steps tailored to your actual hosting/CMS setup instead of generic advice.
What to know▼
How it works
Detects your tech stack, then generates setup-specific fix instructions when something breaks
What's different
Gives tailored instructions instead of a generic alert
Best for
Site owners/agencies who don't want to diagnose issues themselves
We check every product on this page once a day and record whether it still answers.
Open-source malware scanner and runtime guard for AI agents
FreeWorks offlineOpen source
What to know▼
How it works
Vets AI agent skills and MCP servers for malicious behavior before install, scans what's already installed, and blocks hijack attempts at runtime, using 768 open ATR rules.
What's different
Scanned 96,096 published skills and found 751 malicious; rules already merged into Microsoft, Cisco, MISP, and OWASP tooling.
We check every product on this page once a day and record whether it still answers.
Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.
No sign-up
What to know▼
How it works
Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
What's different
Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
We check every product on this page once a day and record whether it still answers.
A free, open-source Chrome DevTools extension for testing APIs — capture, inspect, edit, and replay HTTP requests without an external proxy, plus a quick header and secrets audit.
FreeOpen source
What to know▼
How it works
A Chrome DevTools extension that captures, inspects, edits, and replays HTTP/HTTPS requests without an external proxy, plus a Quick Security Check that audits headers and flags secrets or PII.
What's different
Works without needing to route traffic through an external proxy, unlike typical API testing setups.
Pricing
Free and open-source.
Best for
Developers testing API security directly inside Chrome DevTools.
We check every product on this page once a day and record whether it still answers.
An IP intelligence API that flags VPNs, proxies, Tor nodes and other fraud signals for geolocation, access control and fraud prevention. A developer and business security API.
What to know▼
How it works
An API that returns IP intelligence — location, network, VPN, proxy, and Tor node detection — with real-time data for fraud and risk signals.
Best for
Developers and businesses building fraud prevention, geolocation, or access-control features.
We check every product on this page once a day and record whether it still answers.
Zero-knowledge secrets manager that lets small dev teams share encrypted .env files and revoke a person's access in one command, instead of pasting secrets in chat or shared docs.
Free
What to know▼
How it works
Secrets are encrypted client-side (AES-256-GCM, X25519 device keys) before upload; servers only ever hold ciphertext, and the audit log is hash-chained and publicly anchored.
Pricing
Solo is free; Team is $19 flat for up to 10 people with a 14-day trial.
We check every product on this page once a day and record whether it still answers.
Paste a suspicious text or email and get a 0-99 scam-risk score based on urgency, impersonation and gift-card-demand patterns. Free, instant, no account needed.
FreeNo sign-upNothing to install
What to know▼
How it works
Paste a suspicious SMS, email, or DM and get a 0-99 scam-risk score based on pattern matching for urgency language, lookalike domains, gift-card demands, and bank/USPS impersonation.
Pricing
Free.
Best for
Anyone who receives a suspicious message and wants a quick risk check without creating an account.
We check every product on this page once a day and record whether it still answers.
Debugging tool for developers that captures and explains SAML AuthnRequests/Responses across common identity providers.
Can export my data
What to know▼
How it works
Captures AuthnRequests and SAML Responses, correlates requests with responses, explains common configuration mistakes, flags protocol/security issues, and exports redacted diagnostics.
What's different
Built for Keycloak, Okta, Entra ID, Auth0, ADFS, Ping Identity, and any SAML 2.0 provider.
We check every product on this page once a day and record whether it still answers.
Local firewall binary that sits between AI agents and the network to block secret leaks, prompt injection, SSRF, and MCP tool poisoning, for developers running autonomous agents, producing a signed offline-verifiable receipt instead of blind trust.
No sign-upWorks offlineOpen source
What to know▼
How it works
A single Go binary scans every outbound request from an agent and writes a signed receipt you verify offline against a published key when it blocks something.
Pricing
Apache 2.0, install via brew.
Best for
Developers whose AI agents have shell access, secrets, and an open line to the internet.
We check every product on this page once a day and record whether it still answers.
Scans apps built with Lovable, Supabase, Base44, or Bolt for the security misconfigurations AI builders commonly leave, like an unprotected Supabase database.
FreeNo sign-up
What to know▼
How it works
auto-detects your platform and checks 8 security layers including exposed API keys
We check every product on this page once a day and record whether it still answers.
An open-source local tool for planning and executing encrypted-file key rotation with AI-assisted threat interpretation and policy controls.
Open source
What to know▼
How it works
An open-source local tool that turns recipient changes into reviewable key-rotation plans, with AI interpreting threat signals while deterministic policy controls approval and execution.
What's different
Keys, plaintext, and ciphertext never pass through the model; includes a bundled post-quantum sample vault run with Docker.
We check every product on this page once a day and record whether it still answers.
Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.
No sign-upWorks offlineData stays with you
What to know▼
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
We check every product on this page once a day and record whether it still answers.
Uptime, free security scan and GitHub-connected CVE/secret monitoring for solo founders' sites, with copy-paste AI fixes.
Free
What to know▼
How it works
Watches sites at three depths: a free public security scan (SSL, headers, DNS, spoofing), a read-only GitHub App finding CVEs and leaked secrets, and an SDK covering DB, Stripe webhooks, and cron jobs, with checks every 60s and copy-paste AI fixes.
We check every product on this page once a day and record whether it still answers.
A tool that checks public HTTPS endpoints for SSL certificate expiry, trust, hostname match, and chain issues, and exports results to an Apify dataset or API.
Can export my data
What to know▼
How it works
Checks expiry, trust, hostname match, TLS, HSTS, redirects, issuer, SANs, and certificate-chain data for public endpoints.
Best for
Developers, agencies, and IT teams exporting certificate health into an existing workflow.
We check every product on this page once a day and record whether it still answers.
Runs multiple security scanners (gitleaks, semgrep, trivy, syft) on your Git repos and uses AI to de-duplicate findings and flag logic/business-flow bugs the scanners miss into one report.
Self-hosted
What to know▼
How it works
combines multiple scanners, AI reviewer verifies and de-dupes findings
What's different
self-hostable, catches logic bugs pattern scanners miss
We check every product on this page once a day and record whether it still answers.
A mobile threat and CVE alerting app that filters ongoing exploit activity down to what applies to your specific tech stack, instead of tracking every vulnerability disclosure yourself.
What to know▼
How it works
You enter your tech stack once; it then watches actively exploited vulnerabilities, filters to what applies to your stack, and sends a short daily briefing on what to do.
Best for
CISOs and security teams who need to prioritize which vulnerabilities actually matter to them.
We check every product on this page once a day and record whether it still answers.
A Windows DLL injector with stealth/evasion techniques built for security researchers and low-level Windows tinkerers testing memory manipulation, not a general consumer tool.
Watch out · Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
What to know▼
How it works
A Windows DLL injector built in C++20 offering 8 injection methods and evasion parameters designed to bypass static heuristic detection engines.
Best for
Security researchers and advanced Windows users doing memory manipulation and security testing.
Watch out
Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
We check every product on this page once a day and record whether it still answers.
Centralizes TLS certificate, ACME, secrets, and SSH access management with infrastructure health monitoring, built for SRE and DevOps teams.
What to know▼
How it works
Centralizes management of TLS certificates, ACME automation, secrets, and SSH access tokens, with infrastructure health monitoring via endpoint probes across bare metal, VMs, and hybrid environments.
We check every product on this page once a day and record whether it still answers.
A macOS app storing API keys in the Keychain, unlocked via Touch ID and a hotkey, with a CLI for injecting secrets.
Watch out · macOS only.
No tracking
What to know▼
How it works
Press a hotkey (⌃⌥⌘K) anywhere on macOS to open a vault requiring Touch ID for every copy; keys are stored in the macOS Keychain and organized by platform and tag with multi-select copying; ships with a CLI (keyholdr pick / run) to inject secrets as env vars without a .env file.
What's different
Single-purpose, unlike full password managers — no accounts, sync, analytics, or network access.
We check every product on this page once a day and record whether it still answers.
A free web-app penetration testing service that shows the volume of security findings before charging to unlock the full report.
Free
What to know▼
How it works
Runs an automated penetration test on a web application in under 24 hours, identifying critical, high, and medium security issues and showing the volume of findings before purchase.
Pricing
Free to run; pay to unlock the full detailed report with proofs of concept and specific fixes.
We check every product on this page once a day and record whether it still answers.
An intent-based firewall for AI agents that blocks unauthorized actions even when they pass rule-based spending limits.
No sign-up
What to know▼
How it works
Adds an AI intent firewall between your agents and the real world that can block actions whose intent doesn't match authorization, even when they pass spend-limit rules.
What's different
Includes a human approval gate and a tamper-evident ledger you can try breaking yourself.
Pricing
Live demo available with no signup or API key required.
We check every product on this page once a day and record whether it still answers.
A WordPress security plugin adding firewall, malware scanning, and login hardening in one dashboard — for site owners, agencies, and developers managing WordPress sites.
Free
What to know▼
How it works
A WordPress security plugin combining security hardening, firewall and bot protection, login security with 2FA and CAPTCHA, vulnerability monitoring, audit logs, and cloud-assisted malware scanning.
What's different
Essential security hardening is available for free via simple toggles, without complicated configuration.
Pricing
Free tier for core hardening features.
Best for
WordPress site owners, agencies, and developers who want protection without complex setup.
We check every product on this page once a day and record whether it still answers.
A free external security scan that finds exposed AI/MCP endpoints and other misconfigurations before attackers do, instead of relying only on inside-the-cloud visibility.
FreeNo sign-up
What to know▼
How it works
Passive scan across MCP/AI exposure, TLS, headers, exposed ports, and disclosure using just your domain; findings map to PCI requirements.
Pricing
Free for the first scan, no account required.
Best for
Teams running AI agents/MCP servers who want an outside-in exposure check.
We check every product on this page once a day and record whether it still answers.
An attack surface monitoring tool for small and mid-size businesses that finds exposed subdomains, open ports, and misconfigured cloud buckets before attackers do.
What to know▼
Best for
SMBs wanting to see their external security exposure.
We check every product on this page once a day and record whether it still answers.
A WordPress security suite bundling a firewall, malware scanner, 2FA, and CVE alerting.
What to know▼
How it works
Bundles a WordPress firewall, malware scanner with one-click repair, 2FA/captcha/lockouts, IP/country blocking, live traffic view, and CVE alerts with an audit log.
What's different
Alerts reach you by email, Telegram, or Slack, and scanner repairs infected files in one click.
Best for
WordPress site owners wanting an all-in-one security suite.
We check every product on this page once a day and record whether it still answers.
A read-only scanner that checks Microsoft 365 and Azure tenants for security gaps and estimates the dollar cost of unused licenses, starting with a free scan.
What to know▼
How it works
A read-only scanner that connects to Microsoft 365 and Azure via admin consent, then produces a 0-100 health score, a prioritized fix list, and dollar estimates for wasted licenses. It also checks MFA gaps, Global Admin sprawl, Conditional Access, legacy auth, guest access and SharePoint sharing.
What's different
Read-only and agentless — no stored credentials, tokens minted on demand — and combines security risk with dollar cost in one score instead of a raw alert list.
Pricing
Free scan available with score, severity breakdown and top findings.
Best for
IT admins and MSPs managing Microsoft 365/Azure tenants who need a prioritized, dollar-quantified fix list.
We check every product on this page once a day and record whether it still answers.
A cybersecurity tool that rehearses realistic attack paths against a company's authorized environment and produces executive-ready, prioritized remediation reports, instead of just listing vulnerabilities.
What to know▼
How it works
simulates attacker paths without requiring passwords or making production changes.
Best for
security teams needing business-focused, executive-ready reporting.
We check every product on this page once a day and record whether it still answers.
Windows software that checks your passwords and email addresses against known data-breach databases locally on your PC, without sending sensitive data elsewhere.
Free
What to know▼
How it works
Windows software that checks your passwords and email addresses against known data-breach databases directly on your PC.
What's different
Runs the check locally on your PC without sending sensitive data elsewhere.
Pricing
Free to check.
Best for
Windows users who want to know if their credentials have appeared in known data leaks.
We check every product on this page once a day and record whether it still answers.
Enterprise security · Built for SMEs
Self-hosted
What to know▼
How it works
A security and compliance platform combining shadow AI, prompt injection, and deepfake detection with cloud, endpoint, and identity scanning (35+ scanners, agents for Linux/Windows/macOS/K8s), a self-hosted LLM gateway, and automated ISO 27001/GDPR compliance.
What's different
Built for 10-500 person companies that don't have a dedicated SOC team, unlike enterprise security tools that assume one.
Pricing
From $149/month, live within 30 minutes.
Best for
Small and mid-size companies without an in-house security operations team.
We check every product on this page once a day and record whether it still answers.
A free, open-source, MIT-licensed penetration-testing agent bundling 90+ recon tools (nmap, nuclei, sqlmap and more) into a three-agent pipeline — for security engineers running assessments from the command line.
FreeOpen source
What to know▼
How it works
A reconnaissance agent that runs from inside the environment being tested (desktop, mobile, terminal or headless), bundling 90+ pentest tools like nmap, nuclei, sqlmap and aircrack-ng, plus native port scanning, device enumeration, WiFi discovery and packet capture. A three-agent pipeline (red team, validator, report) turns recon into verified findings.
What's different
Single Rust/Dioxus codebase across desktop, mobile, terminal and headless environments, and is MIT licensed so it can be inspected and extended.
Pricing
Free and open-source, MIT licensed.
Best for
Security engineers running penetration tests who want a bundled, extensible recon and reporting agent.
We check every product on this page once a day and record whether it still answers.
A post-quantum encryption gateway that compresses ML-KEM handshake payloads below the network MTU to cut latency spikes from packet fragmentation.
What to know▼
How it works
Compresses hybrid ML-KEM-768 post-quantum handshake payloads below the network MTU using geometric lattice constraints, avoiding the packet fragmentation that spikes latency.
What's different
Keeps p99.9 tail latency flat at 6.8ms under concurrent load versus 38.2ms for standard payloads, per its own benchmark telemetry.
We check every product on this page once a day and record whether it still answers.
A security platform combining vulnerability management, device management, C-suite reporting, and security training, integrating with tools like Qualys and Microsoft 365.
What to know▼
How it works
Combines vulnerability management, device management, C-suite reporting, security training, and forensics, set up in under 10 minutes.
What's different
Integrates with Qualys, Microsoft 365, Azure, Defender EDR+VM, and Huntress.
We check every product on this page once a day and record whether it still answers.
A continuous security scanner that re-checks targets on a schedule and alerts only on new vulnerability findings.
FreeOpen source
What to know▼
How it works
Schedules recurring security scans (daily/weekly/monthly) with 50+ detectors across recon, web, API, and mobile, alerting via email/Discord/Slack only on new findings versus the previous run; tracks attack surface over time and ships a CLI plus GitHub Action to fail CI builds on new criticals.
What's different
Alerts only on new findings instead of re-reporting everything on each run, and remembers triage decisions across re-scans.
We check every product on this page once a day and record whether it still answers.
AI-run external penetration tests that produce SOC 2/ISO 27001-ready reports and certificates, paid per test with no subscription - the free scan is just an entry point, not the whole product.
No subscription
What to know▼
How it works
Runs AI-driven external penetration tests mapped to SOC 2 and ISO 27001, then generates auditor-ready pentest reports and shareable certificates. Starts with a free posture scan before you purchase individual tests.
What's different
Flat per-test pricing with no recurring subscription, and explicitly positioned to also work for vibe-coded apps.
Pricing
Free posture scan to start; individual tests purchased for a flat fee, no subscription.
Best for
Companies needing SOC 2 or ISO 27001-mapped pentest reports without committing to a subscription service.
We check every product on this page once a day and record whether it still answers.
Scans a web app for TLS, header and vulnerability issues and returns a graded report in minutes, aimed at dev teams who'd otherwise pay for a manual pentest.
What to know▼
How it works
Runs an automated web security audit in under 5 minutes, checking TLS/SSL configuration, security headers, WAF effectiveness, exposed ports, email spoofing risks (SPF/DKIM/DMARC), tech-stack exposure, and over 50,000 Nuclei templates for CVEs and misconfigurations, then returns a severity-based A-F report with remediation steps.
What's different
Automates checks across 8 areas that would otherwise require hiring a consultant for a manual pentest.
Best for
Development teams who want a fast security posture check without hiring a pentest consultant.
We check every product on this page once a day and record whether it still answers.
A tool that runs AI agents in cloud emulators to autonomously test Android apps for security vulnerabilities.
What to know▼
How it works
Deploys AI agents in cloud emulators to run static and dynamic analysis (using adb, jadx, apktool, frida, hermes-dec) on Android apps, including authenticated user flows, and generates reproducible security findings.
What's different
Only requires an Android package name, no APK/AAB upload needed.
We check every product on this page once a day and record whether it still answers.
A free, locally-run guardrail that intercepts hallucinated or malicious npm packages before AI coding agents like Claude Code or Cursor can install them.
What to know▼
How it works
Integrates at the hook level to intercept hallucinated and malicious npm packages before AI coding agents like Claude Code or Cursor can execute them, checking against a 60,000+ threat database in under 2ms.
We check every product on this page once a day and record whether it still answers.
A demo cybersecurity project that encrypts and monitors simulated brain-computer-interface signal data for injection, replay, and flatline attacks, visualized in a live dashboard.
Watch out · Runs on simulated data rather than real BCI hardware and was built as a learning project by a self-taught builder.
What to know▼
How it works
Uses AES-256 encryption, HMAC device authentication, and real-time anomaly detection on simulated EEG data, shown in a live browser dashboard.
Watch out
Runs on simulated data rather than real BCI hardware and was built as a learning project by a self-taught builder.
We check every product on this page once a day and record whether it still answers.
Scans any domain in about 60 seconds and produces a 0-100 security score with letter grades across 10 areas, for anyone checking a website's security posture without signing up.
FreeNo sign-up
What to know▼
How it works
Scans a domain in about 60 seconds across 10 security areas and returns a score, letter grades, and recommended fixes.
We check every product on this page once a day and record whether it still answers.
Find & fix live vulnerabilities in Vibe Apps with 1-prompt.
Watch out · Automated one-prompt fixes are the vendor's claim; the page doesn't say how fixes are verified before or after they're applied.
What to know▼
How it works
Scans apps built with AI coding tools (Replit, Lovable, Claude Code, Cursor and similar) for live access-control vulnerabilities and can fix them automatically from a single prompt.
What's different
Targets 'vibe-coded' apps specifically — code generated by AI tools — rather than general application security scanning.
Best for
People who shipped an app using an AI coding tool without security expertise and want vulnerabilities found and patched automatically.
Watch out
Automated one-prompt fixes are the vendor's claim; the page doesn't say how fixes are verified before or after they're applied.
We check every product on this page once a day and record whether it still answers.
Scans your codebase to generate standard SBOM files plus an inventory of the AI models, API providers and MCP servers your code uses. A free CLI for developers, not an API product itself.
Free
What to know▼
How it works
Scans a repo and produces standard SBOM output (CycloneDX, SPDX) plus an AI-BOM listing the models, API providers and MCP servers the code calls, each with its authority scope.
What's different
Standard SBOM tools don't surface a codebase's AI stack or the agents in it; SBOMix adds that layer.
Pricing
Free CLI, with an optional dashboard.
Best for
Developers who need to inventory not just dependencies but the AI models and agents their code relies on.
We check every product on this page once a day and record whether it still answers.
A single-binary desktop app that scans websites, APIs and OSINT sources for security issues — a scanning tool for security-minded developers, not a hosted API service itself.
What to know▼
How it works
A zero-dependency desktop security scanner, built with Wails and Svelte 5, that runs from a single binary to scan websites, APIs, and OSINT sources for security issues.
Best for
Security-focused developers who want a local scanning tool rather than a hosted scanning service.
We check every product on this page once a day and record whether it still answers.
An AI security agent that scans a live app for vulnerabilities like exposed keys and broken access control, proves each exploit is real, and opens a pull request with the fix, for developers shipping AI-built apps, instead of manual security audits.
FreeNo sign-up
What to know▼
How it works
Scans your live app, reproduces each exploit to prove it's real, then opens the fix as a pull request you approve; keeps watching after launch.
We check every product on this page once a day and record whether it still answers.
Scores open-source projects on safety, maintenance and popularity so developers can compare tools before adopting them, instead of picking by star count alone.
FreeNo sign-upNo ads
What to know▼
How it works
Scores open-source projects on safety (via OSSF Scorecard and advisories), maintenance, popularity, and lightweightness, and lets you AI-compare projects side by side.
What's different
Scores tools on safety and maintenance signals rather than letting users pick by star count alone.
Pricing
Free, no login, no ads.
Best for
Developers evaluating which open-source project to trust and adopt.
We check every product on this page once a day and record whether it still answers.
A secure way for teams to share .env files and secrets via expiring links and role-based access, instead of pasting them into Slack, email, or chat history.
Free
What to know▼
How it works
Generates expiring share links, invites teammates by email, and manages access via workspace roles, with row-level security and encryption at rest.
We check every product on this page once a day and record whether it still answers.
A free web scanner that checks apps built with Lovable, Bolt or v0 for leaked API keys, open databases and missing security headers, no signup needed.
FreeNo sign-up
What to know▼
How it works
Scans apps built with tools like Lovable, Bolt or v0 for issues those builders tend to skip: leaked API keys, publicly readable databases, and missing security headers.
What's different
Targets the specific gaps left by AI app-building tools rather than doing generic security scanning.
Pricing
Free, no signup.
Best for
People who built an app with an AI app builder and want a quick check for exposed keys or open databases.
We check every product on this page once a day and record whether it still answers.
An open-source reference guide covering AI and ML security practices, including LLM, RAG, agent, and MLOps supply-chain controls, for developers and ML engineers.
Open source
What to know▼
How it works
Documents practical MLSecOps guidance across AI security, ML security, LLM/RAG/agent security, and ML supply-chain controls.
Best for
Developers and ML engineers securing AI/ML systems.
We check every product on this page once a day and record whether it still answers.
A free, open-source macOS app for editing your $PATH, aliases and environment variables through a drag-and-drop UI instead of hand-editing shell config files.
Open source
What to know▼
How it works
A macOS app with a drag-and-drop dashboard for editing your $PATH, toggling shell aliases, and managing environment variables, with sensitive keys secured behind Touch ID.
What's different
Replaces hand-editing shell config files with a visual UI, and is under 1.4MB, open source, built in SwiftUI.
Pricing
Open source.
Best for
Developers on macOS who are tired of manually editing dotfiles to manage PATH, aliases and env variables.
We check every product on this page once a day and record whether it still answers.
A drop-in CAPTCHA replacement — a short reaction game easy for humans and hard for bots — that collects no visitor IP, fingerprint or tracking data, with an open-source widget.
Open sourceNo tracking
What to know▼
How it works
Replaces the usual CAPTCHA puzzle with a short reaction-based game; every round is re-checked on the server, so it's easy for humans but hard for bots and AI solvers.
What's different
Collects no IP, fingerprint, or tracking data about visitors, and the widget and games are open source for developers to inspect and restyle.
Best for
Developers who want a privacy-respecting, open-source CAPTCHA alternative for their site.
We check every product on this page once a day and record whether it still answers.
Free external security check for AI-built web apps you own or have permission to test — checks what a normal visitor can see (security headers, public configuration, client-side secrets, data-store references) and explains it in plain language. No login, exploitation or private-network scanning.
Tools for finding security holes in code — the short answers
Every number here comes from our own daily check — not from a vendor list.
Tools for finding security holes in code — how many are there?
Tablif is tracking 202 of them. 198 answered our check today, and 3 we couldn't reach — we don't claim those are dead.
Which ones are still maintained?
Tablif knocks on every door once a day and records the answer. 198 of these 202 responded on the latest run, so that number is what "still here" means on this page — not a review score.
Are any of them free?
39 of the live ones say so in their own words, and 23 let you start without making an account. Tablif records the claim the product makes; we don't verify pricing.
Any open-source options?
27 of the live ones on Tablif mention being open source.
What's the newest one?
VibeCodersLegal — Tablif first saw it today.
Did a person actually look at these?
200 of them Tablif opened and read, then wrote a one-line summary in our own words instead of reusing the founder's tagline. The rest carry keyword labels we haven't confirmed by reading yet — and we say so rather than hiding it.