Topic

Tools for finding security holes in code · Doesn't mention AI

60

match your filters

60

answered today

5

arrived this week

0

stopped answering

Watching this group for 26 days, checked once a day · how we check

Kapient

LiveWatched 12d

Monitors your website's uptime, SSL, DNS, and email deliverability, and gives specific repair steps tailored to your actual hosting/CMS setup instead of generic advice.

What to know
How it works
Detects your tech stack, then generates setup-specific fix instructions when something breaks
What's different
Gives tailored instructions instead of a generic alert
Best for
Site owners/agencies who don't want to diagnose issues themselves
Details →

Keelscan

LiveWatched 12d

A scanner that continuously checks your app's code and Supabase/Firebase config for security holes that could stall a B2B deal.

What to know
How it works
Scans code, live app and Supabase/Firebase for security issues, produces plain-English fixes and a shareable report
Best for
founders preparing for B2B or healthcare deal security reviews
Details →

Merges CVSS, EPSS, KEV, and CVE.org data into one unified per-vulnerability severity record, for anyone deciding what to patch first instead of checking four separate sources.

No sign-up
What to know
How it works
Ingests NVD, CISA KEV, FIRST EPSS, and CVE.org into one pipeline covering hundreds of thousands of CVEs, running them through a priority-based severity engine to serve a unified record — CVSS, EPSS percentile, KEV status, affected vendors/products, and weaknesses — per CVE.
What's different
Built on Cloudflare's edge with a continuously running collection pipeline and visible source-freshness status.
Details →

WebSlurp

LiveWatched 16d

A free, open-source Chrome DevTools extension for testing APIs — capture, inspect, edit, and replay HTTP requests without an external proxy, plus a quick header and secrets audit.

FreeOpen source
What to know
How it works
A Chrome DevTools extension that captures, inspects, edits, and replays HTTP/HTTPS requests without an external proxy, plus a Quick Security Check that audits headers and flags secrets or PII.
What's different
Works without needing to route traffic through an external proxy, unlike typical API testing setups.
Pricing
Free and open-source.
Best for
Developers testing API security directly inside Chrome DevTools.
Details →

IPCheckly

LiveWatched 24d

An IP intelligence API that flags VPNs, proxies, Tor nodes and other fraud signals for geolocation, access control and fraud prevention. A developer and business security API.

What to know
How it works
An API that returns IP intelligence — location, network, VPN, proxy, and Tor node detection — with real-time data for fraud and risk signals.
Best for
Developers and businesses building fraud prevention, geolocation, or access-control features.
Details →

Versio

LiveWatched 14d

Paste in a package.json and get a dependency health dashboard, CVE vulnerability report, and project-specific migration guide.

What to know
How it works
Paste a package.json and get a dependency health dashboard, CVE vulnerability report, and a project-specific migration guide.
Best for
Developers who want to understand and fix risky or outdated dependencies quickly.
Details →

Keyline

LiveWatched 13d

Zero-knowledge secrets manager that lets small dev teams share encrypted .env files and revoke a person's access in one command, instead of pasting secrets in chat or shared docs.

Free
What to know
How it works
Secrets are encrypted client-side (AES-256-GCM, X25519 device keys) before upload; servers only ever hold ciphertext, and the audit log is hash-chained and publicly anchored.
Pricing
Solo is free; Team is $19 flat for up to 10 people with a 14-day trial.
Best for
Small dev teams sharing environment secrets.
Details →

Paste a suspicious text or email and get a 0-99 scam-risk score based on urgency, impersonation and gift-card-demand patterns. Free, instant, no account needed.

FreeNo sign-upNothing to install
What to know
How it works
Paste a suspicious SMS, email, or DM and get a 0-99 scam-risk score based on pattern matching for urgency language, lookalike domains, gift-card demands, and bank/USPS impersonation.
Pricing
Free.
Best for
Anyone who receives a suspicious message and wants a quick risk check without creating an account.
Details →

Debugging tool for developers that captures and explains SAML AuthnRequests/Responses across common identity providers.

Can export my data
What to know
How it works
Captures AuthnRequests and SAML Responses, correlates requests with responses, explains common configuration mistakes, flags protocol/security issues, and exports redacted diagnostics.
What's different
Built for Keycloak, Okta, Entra ID, Auth0, ADFS, Ping Identity, and any SAML 2.0 provider.
Best for
Developers and identity engineers.
Details →

Shieldome

LiveWatched 11d

A vulnerability scanner and dark-web breach monitor for agencies and freelancers who want enterprise-grade security scans without a subscription.

No subscription
What to know
How it works
DAST scanning plus dark-web leak monitoring, accessible via API
What's different
pay-per-scan tokens instead of subscription, white-label resale for agencies
Pricing
pay-as-you-go tokens or SaaS plan
Details →

VulnWatch Agency

LiveWatched 6d

Branded website security reports for digital agencies

What to know
How it works
Aylık tam rapor tarama kredisi ile müşteriye kendi logonuzla rapor verirsiniz, imzalı paylaşımlarda SaaS arayüzü gizlenir.
Details →

Cairn

LiveWatched 9d

Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.

No sign-upWorks offlineData stays with you
What to know
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
What's different
No account, no upload, zero network calls.
Pricing
Free, MIT licensed.
Details →

A tool that checks public HTTPS endpoints for SSL certificate expiry, trust, hostname match, and chain issues, and exports results to an Apify dataset or API.

Can export my data
What to know
How it works
Checks expiry, trust, hostname match, TLS, HSTS, redirects, issuer, SANs, and certificate-chain data for public endpoints.
Best for
Developers, agencies, and IT teams exporting certificate health into an existing workflow.
Details →

A mobile threat and CVE alerting app that filters ongoing exploit activity down to what applies to your specific tech stack, instead of tracking every vulnerability disclosure yourself.

What to know
How it works
You enter your tech stack once; it then watches actively exploited vulnerabilities, filters to what applies to your stack, and sends a short daily briefing on what to do.
Best for
CISOs and security teams who need to prioritize which vulnerabilities actually matter to them.
Details →

Scans your codebase for quantum-vulnerable cryptography ahead of the post-quantum transition.

What to know
How it works
Scans code to flag cryptographic algorithms vulnerable to quantum attacks.
Best for
Engineering teams preparing for post-quantum cryptography migration.
Details →

Depheal

LiveWatched 13d

An offline scanner that checks Python projects for known CVE vulnerabilities using local AST analysis, instead of a cloud-based dependency scanner.

Works offlineOpen source
What to know
How it works
Static AST analysis run entirely locally, with no internet connection or external dependencies required.
Pricing
Open source, published on PyPI.
Best for
Developers who want fast vulnerability scanning without sending code to a cloud service.
Details →

Aether Injector

LiveWatched 15d

A Windows DLL injector with stealth/evasion techniques built for security researchers and low-level Windows tinkerers testing memory manipulation, not a general consumer tool.

Watch out · Marketed around stealth and bypassing detection engines — intended for security testing, not general use.

What to know
How it works
A Windows DLL injector built in C++20 offering 8 injection methods and evasion parameters designed to bypass static heuristic detection engines.
Best for
Security researchers and advanced Windows users doing memory manipulation and security testing.
Watch out
Marketed around stealth and bypassing detection engines — intended for security testing, not general use.
Details →

CertLocker

LiveWatched 14d

Centralizes TLS certificate, ACME, secrets, and SSH access management with infrastructure health monitoring, built for SRE and DevOps teams.

What to know
How it works
Centralizes management of TLS certificates, ACME automation, secrets, and SSH access tokens, with infrastructure health monitoring via endpoint probes across bare metal, VMs, and hybrid environments.
Best for
SRE and DevOps teams.
Details →

Python Code Audit

LiveWatched 11d

Scans Python code for security vulnerabilities using static analysis, aimed at developers checking code they use or ship.

What to know
How it works
static application security testing (SAST) for Python packages and files
Details →

PreRiskAI

LiveWatched 7d

Lets SaaS teams self-assess security readiness before an audit instead of paying for consulting review.

Free
What to know
Pricing
free self-assessment
Details →

Sentinel DNS

LiveWatched 7d

Lets ISPs and telecoms run DNS filtering and threat intelligence instead of relying on closed enterprise appliances.

Open source
What to know
Best for
ISPs, datacenters and telecoms
Details →

Keyholdr

LiveWatched 15d

A macOS app storing API keys in the Keychain, unlocked via Touch ID and a hotkey, with a CLI for injecting secrets.

Watch out · macOS only.

No tracking
What to know
How it works
Press a hotkey (⌃⌥⌘K) anywhere on macOS to open a vault requiring Touch ID for every copy; keys are stored in the macOS Keychain and organized by platform and tag with multi-select copying; ships with a CLI (keyholdr pick / run) to inject secrets as env vars without a .env file.
What's different
Single-purpose, unlike full password managers — no accounts, sync, analytics, or network access.
Watch out
macOS only.
Details →

Kosuke Pentest

LiveWatched 16d

A free web-app penetration testing service that shows the volume of security findings before charging to unlock the full report.

Free
What to know
How it works
Runs an automated penetration test on a web application in under 24 hours, identifying critical, high, and medium security issues and showing the volume of findings before purchase.
Pricing
Free to run; pay to unlock the full detailed report with proofs of concept and specific fixes.
Details →

A WordPress security plugin adding firewall, malware scanning, and login hardening in one dashboard — for site owners, agencies, and developers managing WordPress sites.

Free
What to know
How it works
A WordPress security plugin combining security hardening, firewall and bot protection, login security with 2FA and CAPTCHA, vulnerability monitoring, audit logs, and cloud-assisted malware scanning.
What's different
Essential security hardening is available for free via simple toggles, without complicated configuration.
Pricing
Free tier for core hardening features.
Best for
WordPress site owners, agencies, and developers who want protection without complex setup.
Details →

Affordable security audits for early-stage SaaS teams, offering OWASP/API penetration testing with plain-English fix reports.

What to know
How it works
Delivers a report with proof-of-concept for each vulnerability and clear fix steps
Pricing
Quick scan from $50, full audit $250, delivered in days
Details →

An attack surface monitoring tool for small and mid-size businesses that finds exposed subdomains, open ports, and misconfigured cloud buckets before attackers do.

What to know
Best for
SMBs wanting to see their external security exposure.
Details →

WordSec

LiveWatched 9d

A WordPress security suite bundling a firewall, malware scanner, 2FA, and CVE alerting.

What to know
How it works
Bundles a WordPress firewall, malware scanner with one-click repair, 2FA/captcha/lockouts, IP/country blocking, live traffic view, and CVE alerts with an audit log.
What's different
Alerts reach you by email, Telegram, or Slack, and scanner repairs infected files in one click.
Best for
WordPress site owners wanting an all-in-one security suite.
Details →

CVEScan

LiveWatched 9d

Free runtime CVE scanner that matches installed software or scan results against known vulnerabilities and suggests patches.

FreeNo sign-up
What to know
How it works
Scans installed software, nmap XML output, or a public site, matches products to CPEs and CVEs against the NVD, and helps you find official patches.
Pricing
Free.
Best for
Security-conscious users on Mac, Linux, or Windows checking for known vulnerabilities.
Details →

Tenant Hawk

LiveWatched 24d

A read-only scanner that checks Microsoft 365 and Azure tenants for security gaps and estimates the dollar cost of unused licenses, starting with a free scan.

What to know
How it works
A read-only scanner that connects to Microsoft 365 and Azure via admin consent, then produces a 0-100 health score, a prioritized fix list, and dollar estimates for wasted licenses. It also checks MFA gaps, Global Admin sprawl, Conditional Access, legacy auth, guest access and SharePoint sharing.
What's different
Read-only and agentless — no stored credentials, tokens minted on demand — and combines security risk with dollar cost in one score instead of a raw alert list.
Pricing
Free scan available with score, severity breakdown and top findings.
Best for
IT admins and MSPs managing Microsoft 365/Azure tenants who need a prioritized, dollar-quantified fix list.
Details →

Free website security scanner that checks for malware, vulnerable plugins, and blocklist status with no signup.

FreeNothing to install
What to know
How it works
Scans front-end and back-end for malware, WordPress plugin vulnerabilities, and blocklist status
Pricing
free instant scan; $9/site/year for daily automated scans with email reports
Best for
Site owners wanting a quick security check without installing anything
Details →

Janus Shield

LiveWatched 13d

A cybersecurity tool that rehearses realistic attack paths against a company's authorized environment and produces executive-ready, prioritized remediation reports, instead of just listing vulnerabilities.

What to know
How it works
simulates attacker paths without requiring passwords or making production changes.
Best for
security teams needing business-focused, executive-ready reporting.
Details →

LeakCheck

LiveWatched 21d

Windows software that checks your passwords and email addresses against known data-breach databases locally on your PC, without sending sensitive data elsewhere.

Free
What to know
How it works
Windows software that checks your passwords and email addresses against known data-breach databases directly on your PC.
What's different
Runs the check locally on your PC without sending sensitive data elsewhere.
Pricing
Free to check.
Best for
Windows users who want to know if their credentials have appeared in known data leaks.
Details →

Offload Security

LiveWatched 10d

A unified security platform combining cloud, code, container and Kubernetes vulnerability findings into one risk dashboard.

What to know
How it works
Consolidates CNAPP, vulnerability management and compliance findings across infrastructure into one view
Pricing
Not stated
Best for
Security teams needing a single view across cloud/code/container risk
Details →

Cleanton

LiveWatched 10d

Mac app that clears build-cache disk space and scans your installed npm/pip packages for supply-chain malware before you approve deleting or acting.

What to know
How it works
reclaims disk space from build caches/apps/junk, learns your normal packages, flags new or changed suspicious ones
What's different
deletions go to Trash by default, requires your review before acting
Best for
Mac developers managing disk space and package security
Details →

Z6 PQC-Gateway

LiveWatched 16d

A post-quantum encryption gateway that compresses ML-KEM handshake payloads below the network MTU to cut latency spikes from packet fragmentation.

What to know
How it works
Compresses hybrid ML-KEM-768 post-quantum handshake payloads below the network MTU using geometric lattice constraints, avoiding the packet fragmentation that spikes latency.
What's different
Keeps p99.9 tail latency flat at 6.8ms under concurrent load versus 38.2ms for standard payloads, per its own benchmark telemetry.
Details →

VulnScanners

LiveWatched 24d

A hosted console that runs Nmap, Nuclei and OWASP ZAP vulnerability scans with client-ready reports, aimed at MSPs, pentesters and security teams.

Nothing to install
What to know
How it works
A hosted console that runs Nmap, Nuclei and OWASP ZAP vulnerability scans with no local install, producing client-ready reports; credits don't expire.
Best for
MSPs, pentesters and security teams who need to run scans and hand clients a report.
Details →

Stamptcha

LiveWatched 11d

Replaces reCAPTCHA-style image-grid puzzles with a 4-second wax-seal interaction to prove you're human without tracking cookies.

Watch out · self-hosted/open-source version not yet released

What to know
How it works
a 4-second wax-seal ritual instead of image-grid puzzles
What's different
no cookies, no Google tracking, ~17kb, works on mobile
Watch out
self-hosted/open-source version not yet released
Details →

Spring Sentinel

LiveWatched 11d

Open-source static analysis tool that scans Spring Boot codebases for performance, security and architecture problems before they ship.

Open source
What to know
How it works
static analysis across Maven/Gradle/SpotBugs projects, outputs HTML/JSON/SARIF/CI reports
Pricing
open source
Best for
Spring Boot developers wanting automated code review in CI
Details →

ReadySECURE

LiveWatched 11d

A security platform combining vulnerability management, device management, C-suite reporting, and security training, integrating with tools like Qualys and Microsoft 365.

What to know
How it works
Combines vulnerability management, device management, C-suite reporting, security training, and forensics, set up in under 10 minutes.
What's different
Integrates with Qualys, Microsoft 365, Azure, Defender EDR+VM, and Huntress.
Details →

BugBounty Arsenal

LiveWatched 15d

A continuous security scanner that re-checks targets on a schedule and alerts only on new vulnerability findings.

FreeOpen source
What to know
How it works
Schedules recurring security scans (daily/weekly/monthly) with 50+ detectors across recon, web, API, and mobile, alerting via email/Discord/Slack only on new findings versus the previous run; tracks attack surface over time and ships a CLI plus GitHub Action to fail CI builds on new criticals.
What's different
Alerts only on new findings instead of re-reporting everything on each run, and remembers triage decisions across re-scans.
Pricing
Free, open source.
Details →

Pentestr

LiveWatched 17d

Scans a web app for TLS, header and vulnerability issues and returns a graded report in minutes, aimed at dev teams who'd otherwise pay for a manual pentest.

What to know
How it works
Runs an automated web security audit in under 5 minutes, checking TLS/SSL configuration, security headers, WAF effectiveness, exposed ports, email spoofing risks (SPF/DKIM/DMARC), tech-stack exposure, and over 50,000 Nuclei templates for CVEs and misconfigurations, then returns a severity-based A-F report with remediation steps.
What's different
Automates checks across 8 areas that would otherwise require hiring a consultant for a manual pentest.
Best for
Development teams who want a fast security posture check without hiring a pentest consultant.
Details →

AuditFlare

LiveWatched 18d

Independent UX, security and payment-flow audits performed by AuditFlare's own engineers and designers — for founders who want issues caught before users find them.

What to know
How it works
Engineers, security specialists and product designers review a web app's core journeys, mobile usability, authentication, permissions, edge cases, APIs, database access, payments, webhooks and conversion friction. Each finding comes with evidence, impact, reproduction steps and remediation guidance.
Best for
Founders who want UX, security and payment-flow issues caught by outside reviewers before users encounter them.
Details →

Prosopo

LiveWatched 12d

Bot-detection and security platform that scores visitor risk in real time instead of showing everyone a CAPTCHA.

What to know
How it works
Risk-scoring engine analyzes behavioral and network signals per request
What's different
Adaptive verification instead of blanket CAPTCHA challenges
Best for
Sites needing bot/scraping protection without hurting legitimate user experience
Details →

A side-by-side comparison platform for cybersecurity buyers evaluating MDR, CSPM, compliance, and GRC vendors on features and pricing.

What to know
How it works
vendor comparison across features, pricing, certifications
Best for
cybersecurity buyers at startups or enterprises
Details →

RedScore

LiveWatched 26d

Scans any domain in about 60 seconds and produces a 0-100 security score with letter grades across 10 areas, for anyone checking a website's security posture without signing up.

FreeNo sign-up
What to know
How it works
Scans a domain in about 60 seconds across 10 security areas and returns a score, letter grades, and recommended fixes.
Pricing
Free, no account required.
Details →

Codelivly

LiveWatched 21d

Codelivly is an online learning platform where people study cybersecurity through interactive courses and real-world scenarios.

What to know
How it works
Interactive courses, guided scenarios, and real-world projects.
Details →

Redfox Cybersecurity

LiveWatched 15d

A penetration testing and offensive security service for web, API, network, mobile, and cloud targets.

What to know
How it works
Provides penetration testing and offensive security services covering web, API, network, mobile, and cloud targets.
What's different
Trusted by 2,000+ clients across industries.
Details →

WraithWall

LiveWatched 15d

A deception-based cyber defense platform that lets security teams deploy decoys and monitor live attacker activity.

What to know
How it works
Deploys deception infrastructure, monitors live attacker activity, detects credential abuse, tracks BGP hijacks, and collects behavioral intelligence through a unified workspace.
What's different
Turns the tables on attackers instead of only issuing alerts.
Best for
Security defenders who want active deception-based detection.
Details →

Launchioo

LiveWatched 17d

Scans GitHub pull requests for secrets, SSRF, CSRF, and taint-flow issues with 50+ rules, giving each PR a security score before merge, for dev teams.

What to know
How it works
Applies 50+ security rules to every GitHub pull request to detect secrets, SSRF, CSRF, and taint-flow issues, producing a security score and risk index for each PR.
Best for
Development teams who want automated security checks on code changes before they're merged.
Details →

STOPBOT.NET

LiveWatched 17d

Real-time bot-detection API that blocks malicious traffic by IP, ASN, hostname or VPN reputation, verifies emails and phone numbers, and runs bot-aware smart URLs through one API key.

What to know
How it works
single API key for bot and traffic blocking, email and phone verification, and smart URLs, with a dashboard for logs and blacklists
Best for
developers securing web apps against bots
Details →

Spectra

LiveWatched 17d

A browser tool for developers, pentesters, and security researchers that audits a website's security headers, cookies, and CORS configuration and reports issues instantly.

Pay once
What to know
How it works
Install it and open any site to see security misconfigurations and how to fix them; Pro tier adds cookie auditing, CORS analysis, bulk scanning across 30 domains, and PDF reports.
Pricing
Pay once, keep it forever (Pro tier unlocks additional features).
Best for
Developers, pentesters, and security researchers checking site security quickly.
Details →

A 36-chapter written guide to hardening Windows 11 step by step — reading material with exact settings, registry keys and rollback steps, not an app.

What to know
How it works
A 36-chapter written guide to hardening Windows 11, with exact Settings paths, Group Policy nodes, registry keys, and verification commands, built from CIS, STIGs, and Microsoft baselines.
What's different
Includes risk ratings and rollback steps for each change, plus a quick 15-minute path, rather than opaque scripts or shallow tips.
Best for
Windows 11 users who want a step-by-step hardening guide they can verify and undo.
Details →

Share-Env

LiveWatched 19d

A secure way for teams to share .env files and secrets via expiring links and role-based access, instead of pasting them into Slack, email, or chat history.

Free
What to know
How it works
Generates expiring share links, invites teammates by email, and manages access via workspace roles, with row-level security and encryption at rest.
Pricing
free
Best for
development teams sharing environment secrets
Details →

Verisite

LiveWatched 19d

A website security scanner that runs the checks a hacker would make in the first ten minutes and returns a plain-English report, aimed at people without security expertise.

What to know
How it works
Scans a submitted URL and reports common vulnerabilities in non-technical language.
Details →

Bleek.dev

LiveWatched 23d

A free web scanner that checks apps built with Lovable, Bolt or v0 for leaked API keys, open databases and missing security headers, no signup needed.

FreeNo sign-up
What to know
How it works
Scans apps built with tools like Lovable, Bolt or v0 for issues those builders tend to skip: leaked API keys, publicly readable databases, and missing security headers.
What's different
Targets the specific gaps left by AI app-building tools rather than doing generic security scanning.
Pricing
Free, no signup.
Best for
People who built an app with an AI app builder and want a quick check for exposed keys or open databases.
Details →

PathDeck

LiveWatched 23d

A free, open-source macOS app for editing your $PATH, aliases and environment variables through a drag-and-drop UI instead of hand-editing shell config files.

Open source
What to know
How it works
A macOS app with a drag-and-drop dashboard for editing your $PATH, toggling shell aliases, and managing environment variables, with sensitive keys secured behind Touch ID.
What's different
Replaces hand-editing shell config files with a visual UI, and is under 1.4MB, open source, built in SwiftUI.
Pricing
Open source.
Best for
Developers on macOS who are tired of manually editing dotfiles to manage PATH, aliases and env variables.
Details →

ghostenv

LiveWatched 23d

A zero-dependency Go CLI that pulls secrets from private GitHub repos into your runtime, so you stop hardcoding keys or passing them around in Slack messages.

What to know
How it works
A zero-dependency Go CLI that pulls configuration maps from private GitHub repos and injects them directly into your runtime.
What's different
Replaces hardcoding secrets in local env files or passing them around in Slack.
Best for
Developers who want secrets pulled securely from a private GitHub repo instead of stored or shared manually.
Details →

BiuTrap

LiveWatched 24d

A cybersecurity deception platform that uses real-world attack data to give security teams threat awareness and vulnerability intelligence.

What to know
Best for
Security teams wanting attack deception and threat intelligence.
Details →

openbait

LiveWatched 23d

An anti-phishing security product aimed at mid-market companies; the listing gives no detail on how the protection actually works.

What to know
How it works
An anti-phishing SaaS product.
Best for
Mid-market companies wanting phishing protection.
Details →

Codevetta

LiveWatched 12d

Scans vibe-coded apps to check them before users are asked to trust them.

What to know
How it works
Scans a vibe-coded app to check it before users are asked to trust it.
Details →

The ones we've read

A data masking tool that protects sensitive Salesforce data using role-based access rules, for companies that need to secure Salesforce data instead of exposing it to all users.

What to know
How it works
masks sensitive Salesforce data using role-based access rules
Details →

Locki Security v2

LiveWatched 23d

Scans any web app for PII and other sensitive information to help protect it.

What to know
How it works
Detects personally identifiable and sensitive information within a web app.
Details →

Domain Scan Tools

LiveWatched 23d

Monitors a domain's SPF, DKIM, DMARC, SSL certificate, and security headers from one dashboard, for people managing email and domain security.

What to know
How it works
Scans and tracks a domain's email-authentication records, SSL certificate, and security headers in a single dashboard.
Best for
IT admins and website owners managing email deliverability and domain security.
Details →

Checks any IP address for bot, VPN, proxy or click-fraud signals — a fraud-detection lookup, likely for advertisers protecting ad spend.

What to know
How it works
Looks up any IP address and returns bot, VPN, proxy and click-fraud risk signals.
Best for
Advertisers screening traffic for click fraud.
Details →

Just arrived

Details →

Autheona (v2)

LiveFirst seen today
Details →

ScamDrill

LiveWatched 1d
Details →

Soterios

LiveWatched 2d
Works offlineOpen source
Details →

EmmaTech™

LiveWatched 2d
Details →

smp-pqc-testkit

LiveWatched 2d
Details →

ShieldLabs

LiveWatched 3d
Details →

Watched the longest, still answering

DNS Assistant

LiveWatched 9d

A DNS posture management tool for monitoring and managing DNS configuration — no further detail given.

Details →

Wuthering Veil

LiveWatched 8d

A lightweight Linux security operations dashboard combining fleet monitoring, SIEM-lite detection and MITRE ATT&CK mapping, instead of costly enterprise SIEM.

Details →

Kavyr

LiveWatched 7d

Blocks npm/pnpm/yarn/bun supply-chain attacks before install instead of discovering malware after it lands.

Details →

SurveilX

LiveWatched 7d

Lets businesses get a cyber risk report in 20 minutes instead of a lengthy security audit.

Details →

qsa.sh

LiveWatched 5d
FreeNo sign-up
Details →

ThreatLens

LiveWatched 5d
FreeOpen source
Details →

Impersona

LiveWatched 6d

Free EU-hosted brand-protection tool that watches Certificate Transparency logs for typosquat and lookalike domains.

FreeNo sign-up
Details →

Rebrief

LiveWatched 4d
FreeWorks offlineOpen source
Details →