We check every product on this page once a day and record whether it still answers.
Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.
No sign-up
What to know▼
How it works
Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
What's different
Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
We check every product on this page once a day and record whether it still answers.
Paste a suspicious text or email and get a 0-99 scam-risk score based on urgency, impersonation and gift-card-demand patterns. Free, instant, no account needed.
FreeNo sign-upNothing to install
What to know▼
How it works
Paste a suspicious SMS, email, or DM and get a 0-99 scam-risk score based on pattern matching for urgency language, lookalike domains, gift-card demands, and bank/USPS impersonation.
Pricing
Free.
Best for
Anyone who receives a suspicious message and wants a quick risk check without creating an account.
We check every product on this page once a day and record whether it still answers.
Local firewall binary that sits between AI agents and the network to block secret leaks, prompt injection, SSRF, and MCP tool poisoning, for developers running autonomous agents, producing a signed offline-verifiable receipt instead of blind trust.
No sign-upWorks offlineOpen source
What to know▼
How it works
A single Go binary scans every outbound request from an agent and writes a signed receipt you verify offline against a published key when it blocks something.
Pricing
Apache 2.0, install via brew.
Best for
Developers whose AI agents have shell access, secrets, and an open line to the internet.
We check every product on this page once a day and record whether it still answers.
Scans apps built with Lovable, Supabase, Base44, or Bolt for the security misconfigurations AI builders commonly leave, like an unprotected Supabase database.
FreeNo sign-up
What to know▼
How it works
auto-detects your platform and checks 8 security layers including exposed API keys
We check every product on this page once a day and record whether it still answers.
Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.
No sign-upWorks offlineData stays with you
What to know▼
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
We check every product on this page once a day and record whether it still answers.
An intent-based firewall for AI agents that blocks unauthorized actions even when they pass rule-based spending limits.
No sign-up
What to know▼
How it works
Adds an AI intent firewall between your agents and the real world that can block actions whose intent doesn't match authorization, even when they pass spend-limit rules.
What's different
Includes a human approval gate and a tamper-evident ledger you can try breaking yourself.
Pricing
Live demo available with no signup or API key required.
We check every product on this page once a day and record whether it still answers.
A free external security scan that finds exposed AI/MCP endpoints and other misconfigurations before attackers do, instead of relying only on inside-the-cloud visibility.
FreeNo sign-up
What to know▼
How it works
Passive scan across MCP/AI exposure, TLS, headers, exposed ports, and disclosure using just your domain; findings map to PCI requirements.
Pricing
Free for the first scan, no account required.
Best for
Teams running AI agents/MCP servers who want an outside-in exposure check.
We check every product on this page once a day and record whether it still answers.
An AI security agent that scans a live app for vulnerabilities like exposed keys and broken access control, proves each exploit is real, and opens a pull request with the fix, for developers shipping AI-built apps, instead of manual security audits.
FreeNo sign-up
What to know▼
How it works
Scans your live app, reproduces each exploit to prove it's real, then opens the fix as a pull request you approve; keeps watching after launch.
We check every product on this page once a day and record whether it still answers.
Scores open-source projects on safety, maintenance and popularity so developers can compare tools before adopting them, instead of picking by star count alone.
FreeNo sign-upNo ads
What to know▼
How it works
Scores open-source projects on safety (via OSSF Scorecard and advisories), maintenance, popularity, and lightweightness, and lets you AI-compare projects side by side.
What's different
Scores tools on safety and maintenance signals rather than letting users pick by star count alone.
Pricing
Free, no login, no ads.
Best for
Developers evaluating which open-source project to trust and adopt.
We check every product on this page once a day and record whether it still answers.
Scans any domain in about 60 seconds and produces a 0-100 security score with letter grades across 10 areas, for anyone checking a website's security posture without signing up.
FreeNo sign-up
What to know▼
How it works
Scans a domain in about 60 seconds across 10 security areas and returns a score, letter grades, and recommended fixes.
We check every product on this page once a day and record whether it still answers.
A free web scanner that checks apps built with Lovable, Bolt or v0 for leaked API keys, open databases and missing security headers, no signup needed.
FreeNo sign-up
What to know▼
How it works
Scans apps built with tools like Lovable, Bolt or v0 for issues those builders tend to skip: leaked API keys, publicly readable databases, and missing security headers.
What's different
Targets the specific gaps left by AI app-building tools rather than doing generic security scanning.
Pricing
Free, no signup.
Best for
People who built an app with an AI app builder and want a quick check for exposed keys or open databases.
We check every product on this page once a day and record whether it still answers.
Free external security check for AI-built web apps you own or have permission to test — checks what a normal visitor can see (security headers, public configuration, client-side secrets, data-store references) and explains it in plain language. No login, exploitation or private-network scanning.