We check every product on this page once a day and record whether it still answers.
Monitors your website's uptime, SSL, DNS, and email deliverability, and gives specific repair steps tailored to your actual hosting/CMS setup instead of generic advice.
What to know▼
How it works
Detects your tech stack, then generates setup-specific fix instructions when something breaks
What's different
Gives tailored instructions instead of a generic alert
Best for
Site owners/agencies who don't want to diagnose issues themselves
We check every product on this page once a day and record whether it still answers.
Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.
No sign-up
What to know▼
How it works
Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
What's different
Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
We check every product on this page once a day and record whether it still answers.
A free, open-source Chrome DevTools extension for testing APIs — capture, inspect, edit, and replay HTTP requests without an external proxy, plus a quick header and secrets audit.
FreeOpen source
What to know▼
How it works
A Chrome DevTools extension that captures, inspects, edits, and replays HTTP/HTTPS requests without an external proxy, plus a Quick Security Check that audits headers and flags secrets or PII.
What's different
Works without needing to route traffic through an external proxy, unlike typical API testing setups.
Pricing
Free and open-source.
Best for
Developers testing API security directly inside Chrome DevTools.
We check every product on this page once a day and record whether it still answers.
An IP intelligence API that flags VPNs, proxies, Tor nodes and other fraud signals for geolocation, access control and fraud prevention. A developer and business security API.
What to know▼
How it works
An API that returns IP intelligence — location, network, VPN, proxy, and Tor node detection — with real-time data for fraud and risk signals.
Best for
Developers and businesses building fraud prevention, geolocation, or access-control features.
We check every product on this page once a day and record whether it still answers.
Zero-knowledge secrets manager that lets small dev teams share encrypted .env files and revoke a person's access in one command, instead of pasting secrets in chat or shared docs.
Free
What to know▼
How it works
Secrets are encrypted client-side (AES-256-GCM, X25519 device keys) before upload; servers only ever hold ciphertext, and the audit log is hash-chained and publicly anchored.
Pricing
Solo is free; Team is $19 flat for up to 10 people with a 14-day trial.
We check every product on this page once a day and record whether it still answers.
Paste a suspicious text or email and get a 0-99 scam-risk score based on urgency, impersonation and gift-card-demand patterns. Free, instant, no account needed.
FreeNo sign-upNothing to install
What to know▼
How it works
Paste a suspicious SMS, email, or DM and get a 0-99 scam-risk score based on pattern matching for urgency language, lookalike domains, gift-card demands, and bank/USPS impersonation.
Pricing
Free.
Best for
Anyone who receives a suspicious message and wants a quick risk check without creating an account.
We check every product on this page once a day and record whether it still answers.
Debugging tool for developers that captures and explains SAML AuthnRequests/Responses across common identity providers.
Can export my data
What to know▼
How it works
Captures AuthnRequests and SAML Responses, correlates requests with responses, explains common configuration mistakes, flags protocol/security issues, and exports redacted diagnostics.
What's different
Built for Keycloak, Okta, Entra ID, Auth0, ADFS, Ping Identity, and any SAML 2.0 provider.
We check every product on this page once a day and record whether it still answers.
Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.
No sign-upWorks offlineData stays with you
What to know▼
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
We check every product on this page once a day and record whether it still answers.
A tool that checks public HTTPS endpoints for SSL certificate expiry, trust, hostname match, and chain issues, and exports results to an Apify dataset or API.
Can export my data
What to know▼
How it works
Checks expiry, trust, hostname match, TLS, HSTS, redirects, issuer, SANs, and certificate-chain data for public endpoints.
Best for
Developers, agencies, and IT teams exporting certificate health into an existing workflow.
We check every product on this page once a day and record whether it still answers.
A mobile threat and CVE alerting app that filters ongoing exploit activity down to what applies to your specific tech stack, instead of tracking every vulnerability disclosure yourself.
What to know▼
How it works
You enter your tech stack once; it then watches actively exploited vulnerabilities, filters to what applies to your stack, and sends a short daily briefing on what to do.
Best for
CISOs and security teams who need to prioritize which vulnerabilities actually matter to them.
We check every product on this page once a day and record whether it still answers.
A Windows DLL injector with stealth/evasion techniques built for security researchers and low-level Windows tinkerers testing memory manipulation, not a general consumer tool.
Watch out · Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
What to know▼
How it works
A Windows DLL injector built in C++20 offering 8 injection methods and evasion parameters designed to bypass static heuristic detection engines.
Best for
Security researchers and advanced Windows users doing memory manipulation and security testing.
Watch out
Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
We check every product on this page once a day and record whether it still answers.
Centralizes TLS certificate, ACME, secrets, and SSH access management with infrastructure health monitoring, built for SRE and DevOps teams.
What to know▼
How it works
Centralizes management of TLS certificates, ACME automation, secrets, and SSH access tokens, with infrastructure health monitoring via endpoint probes across bare metal, VMs, and hybrid environments.
We check every product on this page once a day and record whether it still answers.
A macOS app storing API keys in the Keychain, unlocked via Touch ID and a hotkey, with a CLI for injecting secrets.
Watch out · macOS only.
No tracking
What to know▼
How it works
Press a hotkey (⌃⌥⌘K) anywhere on macOS to open a vault requiring Touch ID for every copy; keys are stored in the macOS Keychain and organized by platform and tag with multi-select copying; ships with a CLI (keyholdr pick / run) to inject secrets as env vars without a .env file.
What's different
Single-purpose, unlike full password managers — no accounts, sync, analytics, or network access.
We check every product on this page once a day and record whether it still answers.
A free web-app penetration testing service that shows the volume of security findings before charging to unlock the full report.
Free
What to know▼
How it works
Runs an automated penetration test on a web application in under 24 hours, identifying critical, high, and medium security issues and showing the volume of findings before purchase.
Pricing
Free to run; pay to unlock the full detailed report with proofs of concept and specific fixes.
We check every product on this page once a day and record whether it still answers.
A WordPress security plugin adding firewall, malware scanning, and login hardening in one dashboard — for site owners, agencies, and developers managing WordPress sites.
Free
What to know▼
How it works
A WordPress security plugin combining security hardening, firewall and bot protection, login security with 2FA and CAPTCHA, vulnerability monitoring, audit logs, and cloud-assisted malware scanning.
What's different
Essential security hardening is available for free via simple toggles, without complicated configuration.
Pricing
Free tier for core hardening features.
Best for
WordPress site owners, agencies, and developers who want protection without complex setup.
We check every product on this page once a day and record whether it still answers.
An attack surface monitoring tool for small and mid-size businesses that finds exposed subdomains, open ports, and misconfigured cloud buckets before attackers do.
What to know▼
Best for
SMBs wanting to see their external security exposure.
We check every product on this page once a day and record whether it still answers.
A WordPress security suite bundling a firewall, malware scanner, 2FA, and CVE alerting.
What to know▼
How it works
Bundles a WordPress firewall, malware scanner with one-click repair, 2FA/captcha/lockouts, IP/country blocking, live traffic view, and CVE alerts with an audit log.
What's different
Alerts reach you by email, Telegram, or Slack, and scanner repairs infected files in one click.
Best for
WordPress site owners wanting an all-in-one security suite.
We check every product on this page once a day and record whether it still answers.
A read-only scanner that checks Microsoft 365 and Azure tenants for security gaps and estimates the dollar cost of unused licenses, starting with a free scan.
What to know▼
How it works
A read-only scanner that connects to Microsoft 365 and Azure via admin consent, then produces a 0-100 health score, a prioritized fix list, and dollar estimates for wasted licenses. It also checks MFA gaps, Global Admin sprawl, Conditional Access, legacy auth, guest access and SharePoint sharing.
What's different
Read-only and agentless — no stored credentials, tokens minted on demand — and combines security risk with dollar cost in one score instead of a raw alert list.
Pricing
Free scan available with score, severity breakdown and top findings.
Best for
IT admins and MSPs managing Microsoft 365/Azure tenants who need a prioritized, dollar-quantified fix list.
We check every product on this page once a day and record whether it still answers.
A cybersecurity tool that rehearses realistic attack paths against a company's authorized environment and produces executive-ready, prioritized remediation reports, instead of just listing vulnerabilities.
What to know▼
How it works
simulates attacker paths without requiring passwords or making production changes.
Best for
security teams needing business-focused, executive-ready reporting.
We check every product on this page once a day and record whether it still answers.
Windows software that checks your passwords and email addresses against known data-breach databases locally on your PC, without sending sensitive data elsewhere.
Free
What to know▼
How it works
Windows software that checks your passwords and email addresses against known data-breach databases directly on your PC.
What's different
Runs the check locally on your PC without sending sensitive data elsewhere.
Pricing
Free to check.
Best for
Windows users who want to know if their credentials have appeared in known data leaks.
We check every product on this page once a day and record whether it still answers.
A post-quantum encryption gateway that compresses ML-KEM handshake payloads below the network MTU to cut latency spikes from packet fragmentation.
What to know▼
How it works
Compresses hybrid ML-KEM-768 post-quantum handshake payloads below the network MTU using geometric lattice constraints, avoiding the packet fragmentation that spikes latency.
What's different
Keeps p99.9 tail latency flat at 6.8ms under concurrent load versus 38.2ms for standard payloads, per its own benchmark telemetry.
We check every product on this page once a day and record whether it still answers.
A security platform combining vulnerability management, device management, C-suite reporting, and security training, integrating with tools like Qualys and Microsoft 365.
What to know▼
How it works
Combines vulnerability management, device management, C-suite reporting, security training, and forensics, set up in under 10 minutes.
What's different
Integrates with Qualys, Microsoft 365, Azure, Defender EDR+VM, and Huntress.
We check every product on this page once a day and record whether it still answers.
A continuous security scanner that re-checks targets on a schedule and alerts only on new vulnerability findings.
FreeOpen source
What to know▼
How it works
Schedules recurring security scans (daily/weekly/monthly) with 50+ detectors across recon, web, API, and mobile, alerting via email/Discord/Slack only on new findings versus the previous run; tracks attack surface over time and ships a CLI plus GitHub Action to fail CI builds on new criticals.
What's different
Alerts only on new findings instead of re-reporting everything on each run, and remembers triage decisions across re-scans.
We check every product on this page once a day and record whether it still answers.
Scans a web app for TLS, header and vulnerability issues and returns a graded report in minutes, aimed at dev teams who'd otherwise pay for a manual pentest.
What to know▼
How it works
Runs an automated web security audit in under 5 minutes, checking TLS/SSL configuration, security headers, WAF effectiveness, exposed ports, email spoofing risks (SPF/DKIM/DMARC), tech-stack exposure, and over 50,000 Nuclei templates for CVEs and misconfigurations, then returns a severity-based A-F report with remediation steps.
What's different
Automates checks across 8 areas that would otherwise require hiring a consultant for a manual pentest.
Best for
Development teams who want a fast security posture check without hiring a pentest consultant.
We check every product on this page once a day and record whether it still answers.
Independent UX, security and payment-flow audits performed by AuditFlare's own engineers and designers — for founders who want issues caught before users find them.
What to know▼
How it works
Engineers, security specialists and product designers review a web app's core journeys, mobile usability, authentication, permissions, edge cases, APIs, database access, payments, webhooks and conversion friction. Each finding comes with evidence, impact, reproduction steps and remediation guidance.
Best for
Founders who want UX, security and payment-flow issues caught by outside reviewers before users encounter them.
We check every product on this page once a day and record whether it still answers.
Scans any domain in about 60 seconds and produces a 0-100 security score with letter grades across 10 areas, for anyone checking a website's security posture without signing up.
FreeNo sign-up
What to know▼
How it works
Scans a domain in about 60 seconds across 10 security areas and returns a score, letter grades, and recommended fixes.
We check every product on this page once a day and record whether it still answers.
Scans GitHub pull requests for secrets, SSRF, CSRF, and taint-flow issues with 50+ rules, giving each PR a security score before merge, for dev teams.
What to know▼
How it works
Applies 50+ security rules to every GitHub pull request to detect secrets, SSRF, CSRF, and taint-flow issues, producing a security score and risk index for each PR.
Best for
Development teams who want automated security checks on code changes before they're merged.
We check every product on this page once a day and record whether it still answers.
Real-time bot-detection API that blocks malicious traffic by IP, ASN, hostname or VPN reputation, verifies emails and phone numbers, and runs bot-aware smart URLs through one API key.
What to know▼
How it works
single API key for bot and traffic blocking, email and phone verification, and smart URLs, with a dashboard for logs and blacklists
We check every product on this page once a day and record whether it still answers.
A browser tool for developers, pentesters, and security researchers that audits a website's security headers, cookies, and CORS configuration and reports issues instantly.
Pay once
What to know▼
How it works
Install it and open any site to see security misconfigurations and how to fix them; Pro tier adds cookie auditing, CORS analysis, bulk scanning across 30 domains, and PDF reports.
Pricing
Pay once, keep it forever (Pro tier unlocks additional features).
Best for
Developers, pentesters, and security researchers checking site security quickly.
We check every product on this page once a day and record whether it still answers.
A 36-chapter written guide to hardening Windows 11 step by step — reading material with exact settings, registry keys and rollback steps, not an app.
What to know▼
How it works
A 36-chapter written guide to hardening Windows 11, with exact Settings paths, Group Policy nodes, registry keys, and verification commands, built from CIS, STIGs, and Microsoft baselines.
What's different
Includes risk ratings and rollback steps for each change, plus a quick 15-minute path, rather than opaque scripts or shallow tips.
Best for
Windows 11 users who want a step-by-step hardening guide they can verify and undo.
We check every product on this page once a day and record whether it still answers.
A secure way for teams to share .env files and secrets via expiring links and role-based access, instead of pasting them into Slack, email, or chat history.
Free
What to know▼
How it works
Generates expiring share links, invites teammates by email, and manages access via workspace roles, with row-level security and encryption at rest.
We check every product on this page once a day and record whether it still answers.
A website security scanner that runs the checks a hacker would make in the first ten minutes and returns a plain-English report, aimed at people without security expertise.
What to know▼
How it works
Scans a submitted URL and reports common vulnerabilities in non-technical language.
We check every product on this page once a day and record whether it still answers.
A free web scanner that checks apps built with Lovable, Bolt or v0 for leaked API keys, open databases and missing security headers, no signup needed.
FreeNo sign-up
What to know▼
How it works
Scans apps built with tools like Lovable, Bolt or v0 for issues those builders tend to skip: leaked API keys, publicly readable databases, and missing security headers.
What's different
Targets the specific gaps left by AI app-building tools rather than doing generic security scanning.
Pricing
Free, no signup.
Best for
People who built an app with an AI app builder and want a quick check for exposed keys or open databases.
We check every product on this page once a day and record whether it still answers.
A free, open-source macOS app for editing your $PATH, aliases and environment variables through a drag-and-drop UI instead of hand-editing shell config files.
Open source
What to know▼
How it works
A macOS app with a drag-and-drop dashboard for editing your $PATH, toggling shell aliases, and managing environment variables, with sensitive keys secured behind Touch ID.
What's different
Replaces hand-editing shell config files with a visual UI, and is under 1.4MB, open source, built in SwiftUI.
Pricing
Open source.
Best for
Developers on macOS who are tired of manually editing dotfiles to manage PATH, aliases and env variables.
We check every product on this page once a day and record whether it still answers.
A zero-dependency Go CLI that pulls secrets from private GitHub repos into your runtime, so you stop hardcoding keys or passing them around in Slack messages.
What to know▼
How it works
A zero-dependency Go CLI that pulls configuration maps from private GitHub repos and injects them directly into your runtime.
What's different
Replaces hardcoding secrets in local env files or passing them around in Slack.
Best for
Developers who want secrets pulled securely from a private GitHub repo instead of stored or shared manually.
We check every product on this page once a day and record whether it still answers.
A data masking tool that protects sensitive Salesforce data using role-based access rules, for companies that need to secure Salesforce data instead of exposing it to all users.
What to know▼
How it works
masks sensitive Salesforce data using role-based access rules
We check every product on this page once a day and record whether it still answers.
A lightweight Linux security operations dashboard combining fleet monitoring, SIEM-lite detection and MITRE ATT&CK mapping, instead of costly enterprise SIEM.