Cookie security audit
We fetch your URL once, parse every Set-Cookie header, and grade Secure, HttpOnly, and SameSite per cookie. Three flags that decide whether XSS can exfiltrate sessions.
Keep hardening your site
This is one check of many. Run the rest — every tool is free, no account.
Security headers scan
Grade your live response headers
TLS certificate scan
Grade chain, expiry, and key strength
Security headers builder
Emit a ready-to-paste header block
CSP analyzer
Grade your Content-Security-Policy
Mixed-content scanner
Find http:// assets on https pages
Open-redirect detector
Probe redirect params for abuse
HSTS preload checker
Grade against Chrome's preload list
CORS policy analyzer
Catch wildcard + credentials bugs