WebGuarder
    Free ToolsSign InGet Started

    Free Security Scanning Tools

    114 free security tools — no signup required. Scan any domain for vulnerabilities, misconfigurations, and risks.

    Domain Reputation Score

    RECOMMENDED

    Get a comprehensive 0-100 security reputation rating. Combines DNS, email auth, SSL, and headers into one actionable score with letter grade.

    8+ security signalsWeighted scoringRisk level assessmentActionable recommendations

    Security Radar

    RECOMMENDED

    Visualize your security posture as an interactive radar chart across 6 axes: DNS, Email, SSL, Headers, Infrastructure, and Attack Surface. Compare against industry averages instantly.

    6-axis radar chartIndustry benchmark overlayParallel scanningFree — no signup required

    Domain Exposure Score

    RECOMMENDED

    Measure how visible your attack surface is on the public internet. Analyzes subdomains, open ports, WHOIS privacy, email infrastructure, DNS footprint, and technology leakage. Lower is better.

    6 exposure categoriesAttack surface quantificationActionable reduction tipsFree — competitors charge $50+/mo

    Security Watch (Free Monitoring)

    RECOMMENDED

    Monitor any domain's security score continuously — for free. Get webhook or email alerts when something changes. Competitors charge $500+/month for this.

    6-hour scan intervalWebhook & email alertsScore history trackingNo signup needed

    AI Bot Protection Scanner

    RECOMMENDED

    Check if your website is protected against AI crawlers like GPTBot, ClaudeBot, and CCBot. Analyzes robots.txt, meta tags, WAF, and 20+ AI bots. Get copy-paste fixes.

    20+ AI bots checkedrobots.txt analysisWAF & rate limit detectionCopy-paste fix snippets

    Security Checklist

    RECOMMENDED

    Comprehensive security audit with actionable fix guides. Check 20+ security controls across SSL, DNS, email, headers, and best practices. Get copy-paste remediation snippets for every finding.

    20+ security checksCopy-paste fix guidesPriority-ranked findingsNo signup required

    Cloud Exposure Scanner

    RECOMMENDED

    Discover exposed cloud resources — S3 buckets, Azure blob storage, GCP buckets, Firebase databases, Elasticsearch, and Docker registries. Finds misconfigurations before attackers do.

    Multi-cloud scanningBucket enumerationFirebase DB checkRisk assessment

    Secret & API Key Leak Scanner

    RECOMMENDED

    Scan any website's public HTML and JavaScript files for accidentally exposed API keys, tokens, passwords, and secrets. Detects AWS, Google, GitHub, Stripe, and 20+ more patterns.

    25+ secret patternsJS file analysisSeverity gradingRemediation advice

    IP Intelligence Hub

    RECOMMENDED

    Comprehensive IP analysis — geolocation, open ports, threat intelligence, blacklist checks, reverse DNS, ASN data, and hosted domains. Your free Shodan alternative.

    Port & banner scanThreat intelligenceBlacklist checkReverse IP lookup

    Bulk Domain Scanner

    RECOMMENDED

    Scan up to 10 domains at once. Compare security grades, risk levels, and vulnerabilities side-by-side. Export results as CSV.

    10 domains at onceCSV exportVendor risk assessmentSide-by-side comparison

    Full Security Report

    RECOMMENDED

    Get a comprehensive security analysis combining all tools into one unified report. Email, SSL, DNS, headers, and subdomain scanning.

    5 scans in oneDownloadable reportPriority recommendationsInstant results

    Subdomain Finder

    RECOMMENDED

    Discover all subdomains using 10+ OSINT sources. Each result enriched with IP, HTTP status, server, cloud provider, and page title. Export as CSV.

    10+ OSINT sourcesHTTP probingCloud detectionCSV export

    Deep SSL/TLS Analysis

    RECOMMENDED

    SSL Labs-style deep analysis: cipher suites, protocol versions (TLS 1.0–1.3), certificate chain, forward secrecy, HSTS preload, OCSP stapling.

    Cipher suite auditProtocol testingForward secrecyHSTS & OCSP

    Associated Domains Discovery

    RECOMMENDED

    Find domains related to any target through shared infrastructure — same IP, SSL certificates, MX servers, and nameservers. SecurityTrails charges $50+/mo for this.

    Reverse IP lookupSSL/CT log correlationShared MX & NS detectionConfidence scoring

    Attack Surface Overview

    RECOMMENDED

    Instant reconnaissance — see open ports, known CVEs, technologies, DNS records, and WHOIS data in one unified view. Powered by Shodan InternetDB.

    Open ports & CVEsTechnology detectionDNS + WHOISRisk scoring

    Vulnerability Intelligence Feed

    RECOMMENDED

    Browse the latest CVEs from NIST NVD in real-time. Filter by technology (Apache, Nginx, WordPress, etc.), severity, and timeframe. Free Shodan exploit search alternative.

    Real-time NVD feedTech keyword filterSeverity filteringFree — no signup

    Security Header Fix Generator

    RECOMMENDED

    Scan any website and get ready-to-use server configurations to fix missing security headers. Supports Nginx, Apache, Cloudflare Workers, Express.js, and Caddy.

    Auto-detect serverCopy-paste configs5 server typesBest-practice values

    Domain Security Comparison

    RECOMMENDED

    Compare the security posture of two domains side by side. See who has better DNS, email auth, SSL, and header security across 8 signals.

    Side-by-side comparison8 security signalsCategory breakdownKey insights

    HSTS Preload Checker

    RECOMMENDED

    Verify HSTS header configuration and preload eligibility. Check max-age, includeSubDomains, preload directive, and Chrome preload list status.

    HSTS header analysisPreload eligibilityChrome preload listHTTPS redirect check

    Sensitive File Finder

    RECOMMENDED

    Scan any domain for exposed sensitive files — .env, .git, database dumps, config backups, admin panels, and 35+ common paths attackers look for.

    35+ sensitive pathsSoft 404 detectionSeverity gradingRemediation advice

    JWT Analyzer

    RECOMMENDED

    Decode and analyze JSON Web Tokens for security vulnerabilities. Check for algorithm none attacks, key confusion, expired tokens, sensitive data exposure, and header injection risks.

    Algorithm analysisExpiry validationSensitive data detectionHeader injection checks

    SAML Decoder

    RECOMMENDED

    Decode and inspect SAML 2.0 Responses, AuthnRequests, and Assertions. Analyze attributes, conditions, signatures, time validity, and security misconfigurations — 100% client-side.

    Base64/XML decodeAttribute extractionSignature checkSecurity grading

    Open Redirect Scanner

    RECOMMENDED

    Test for open redirect vulnerabilities across 26 common redirect parameters with 6 bypass techniques. Detect phishing attack vectors before attackers exploit them.

    26 redirect params6 bypass payloadsRisk gradingCWE-601 detection

    Clickjacking Tester

    RECOMMENDED

    Test if a website is vulnerable to clickjacking (UI redressing) attacks by checking X-Frame-Options and CSP frame-ancestors headers.

    X-Frame-Options checkCSP frame-ancestorsVulnerability gradingFix recommendations

    Permissions Policy Analyzer

    RECOMMENDED

    Analyze Permissions-Policy and Feature-Policy headers. Check which browser features (camera, mic, geolocation, payment, USB) are restricted or exposed.

    Permissions-Policy auditFeature-Policy (legacy)High-risk feature detectionBrowser API restrictions

    Rate Limit Detector

    RECOMMENDED

    Check if a website has rate limiting configured on its endpoints. Detects standard and vendor-specific rate limit headers.

    IETF standard headersVendor header detectionMulti-endpoint check429 throttle detection

    URL Unshortener

    RECOMMENDED

    Expand shortened URLs to reveal the final destination. Trace every redirect hop, detect HTTPS downgrades, suspicious TLDs, and excessive redirect chains.

    Redirect chain traceHTTPS downgrade detectionSuspicious URL flaggingKnown shortener detection

    Wayback Machine Checker

    RECOMMENDED

    Discover what the Wayback Machine has archived for any domain. Find historically exposed admin panels, config files, API endpoints, and sensitive paths.

    Archive timelineSensitive path detectionYearly breakdownDirect snapshot links

    Website Status Checker

    RECOMMENDED

    Check if a website is up or down. Multi-point verification with DNS resolution, HTTPS support, and response time analysis.

    Multi-point checksDNS verificationHTTPS detectionResponse time

    Typosquatting Checker

    RECOMMENDED

    Discover registered lookalike domains targeting your brand. Detects character omissions, swaps, homoglyphs, TLD variations, and more.

    8+ typo techniquesDNS registration checkRisk scoringBrand protection

    HTTP Response Inspector

    RECOMMENDED

    Inspect the full HTTP response — status, headers, redirects, cookies, timing, body preview, and security analysis. Like curl -v in your browser.

    Full header dumpRedirect chainCookie analysisSecurity grading

    DNS-over-HTTPS (DoH) Tester

    RECOMMENDED

    Test encrypted DNS resolution across Google, Cloudflare, Quad9, NextDNS, AdGuard, and Mullvad. Check consistency, DNSSEC validation, and response times.

    6 DoH providersDNSSEC validationConsistency checkResponse timing

    DNS Consistency Checker

    RECOMMENDED

    Compare DNS resolution across Google, Cloudflare, Quad9, and OpenDNS to detect poisoning, hijacking, or propagation issues.

    Multi-resolver comparisonPoisoning detectionHijacking alertsResponse time analysis

    DNS Rebinding Checker

    RECOMMENDED

    Detect DNS rebinding vulnerabilities by analyzing IP resolution for private addresses, TTL values, wildcard DNS, and CORS misconfigurations.

    Private IP detectionTTL analysisWildcard DNS checkCORS audit

    DNS Tunneling Detector

    RECOMMENDED

    Detect covert data channels hidden in DNS traffic — high-entropy records, encoded payloads, unusual record types, wildcard DNS, and suspicious nameservers.

    Entropy analysisTXT payload inspectionWildcard detectionCT log analysis

    DNS Zone Transfer Checker

    RECOMMENDED

    Test if nameservers allow unauthorized AXFR zone transfers, exposing internal hostnames, mail servers, and full network topology.

    AXFR detectionRecord leak analysisPer-NS testingTSIG guidance

    DNS Bulk Export

    RECOMMENDED

    Export all DNS records for any domain in JSON, CSV, or BIND zone file format. Queries 17 record types including A, AAAA, MX, TXT, NS, SOA, SRV, CAA, DNSKEY, and more.

    17 record typesJSON/CSV/BIND exportZone file generationRecord diversity grading

    CAA Record Analyzer

    RECOMMENDED

    Analyze Certificate Authority Authorization records to see which CAs can issue SSL certificates. Checks wildcard restrictions, violation reporting, parent domain inheritance, and grades your configuration.

    CA authorization checkWildcard controliodef reportingParent inheritance

    Nameserver Security Audit

    RECOMMENDED

    Deep security analysis of nameserver infrastructure — redundancy, version disclosure, open resolvers, EDNS, TCP, DNSSEC, and provider diversity.

    9 security checksOpen resolver detectionVersion disclosureProvider diversity

    GraphQL Introspection Checker

    RECOMMENDED

    Detect exposed GraphQL endpoints and analyze schemas for sensitive types, dangerous mutations, and data exposure risks.

    Endpoint discoverySchema analysisSensitive field detectionMutation exposure check

    Endpoint Discovery

    RECOMMENDED

    Scan any domain for exposed API documentation, admin panels, configuration leaks (.env, .git), debug endpoints, and authentication routes.

    API docs detectionConfig leak scanAdmin panel finderDebug endpoint check

    ASN Lookup

    RECOMMENDED

    Look up Autonomous System Numbers, IP addresses, or domains to discover network ownership, BGP peers, announced prefixes, and abuse contacts.

    ASN/IP/Domain lookupBGP peer discoveryPrefix enumerationAbuse contact finder

    HTTP Protocol Checker

    RECOMMENDED

    Test HTTP/2, HTTP/3 (QUIC), ALPN negotiation, and TLS version support. Ensure your server uses modern protocols for optimal performance.

    HTTP/2 detectionHTTP/3 (QUIC) checkALPN analysisTLS version

    Website Latency Tester

    RECOMMENDED

    Measure website response time with detailed timing breakdown — DNS, TCP, TLS, TTFB, and download. Get performance grades and optimization tips.

    TTFB measurementTiming breakdownPerformance gradeCDN detection

    SMTP TLS Checker

    RECOMMENDED

    Test STARTTLS support on mail servers, verify MTA-STS enforcement policy, and check SMTP TLS Reporting (TLSRPT) — ensure email is encrypted in transit.

    STARTTLS testingMTA-STS policy checkTLSRPT validationTLS version & cipher analysis

    BIMI Record Checker

    RECOMMENDED

    Check Brand Indicators for Message Identification (BIMI) — verify brand logo display in email clients, VMC/CMC certificates, and DMARC compliance.

    BIMI record lookupLogo validationVMC/CMC checkDMARC compliance

    Email Harvester

    RECOMMENDED

    Discover email addresses and email infrastructure for any domain. OSINT-powered email enumeration using DNS records, web scraping, and pattern analysis.

    Email scrapingMail provider detectionSPF/DMARC analysisEmail security score

    DNS Resolver Benchmark

    RECOMMENDED

    Benchmark DNS resolution speed across 12 major public resolvers — Cloudflare, Google, Quad9, OpenDNS & more. Find the fastest DNS and get security insights.

    12 public resolversMulti-iteration timingDNSSEC detectionSpeed ranking

    DNSSEC Analyzer

    RECOMMENDED

    Validate DNSSEC chain of trust, DNSKEY/DS records, RRSIG signature expiry, NSEC/NSEC3 zone enumeration protection, and algorithm security grading.

    Chain of trustKey analysisSignature expiryNSEC3 config

    DANE/TLSA Checker

    RECOMMENDED

    Check DNS-based Authentication of Named Entities (DANE) — verify TLSA records for certificate pinning via DNS across HTTPS, SMTP, and more.

    TLSA record lookupDNSSEC verificationMulti-port checkUsage type analysis

    Metadata & Social Preview Analyzer

    RECOMMENDED

    Analyze website meta tags, Open Graph previews, Twitter Cards, JSON-LD structured data, and security-related metadata. See how your site looks when shared.

    Social preview mockupsJSON-LD inspectionSecurity meta auditSEO completeness score

    Website Privacy Analyzer

    RECOMMENDED

    Audit any website for trackers, cookies, fingerprinting, consent management, and privacy policy compliance. Get GDPR & CCPA recommendations.

    Tracker detectionCookie analysisPrivacy policy reviewConsent mechanism check

    Website Carbon Footprint

    RECOMMENDED

    Estimate the CO₂ emissions of any web page. Analyze page weight, resource breakdown, green hosting status, and get tips to reduce environmental impact.

    CO₂ per page viewResource breakdownGreen hosting checkOptimization tips

    Security Score Badge

    RECOMMENDED

    Generate an embeddable SVG badge showing your domain's security grade (A+ to F). Add it to your README, website, or docs as a trust signal.

    Embeddable SVG badge10 security checksMarkdown & HTML embedAuto-refreshing

    WebSocket Security Analyzer

    RECOMMENDED

    Detect WebSocket endpoints, check WSS encryption, origin validation, CSWSH vulnerabilities, compression risks, and identify real-time libraries like Socket.IO and SignalR.

    WSS/WS detectionCSWSH checkOrigin validationLibrary detection

    Security Leaderboard

    RECOMMENDED

    Public ranking of domains by security score. See which websites have the best security posture and compete for the top spot.

    Public rankingsSecurity scoresGrade comparisonOpt-in system

    Domain Score History

    Track how a domain's security reputation score changes over time. See trends, improvements, and regressions with historical data.

    • Score timeline
    • Trend analysis
    • Best/worst tracking
    • Progress monitoring

    Website Screenshot & Preview

    Capture a visual snapshot of any website with metadata, tech detection, redirect chains, external connections, and console error analysis. Desktop & mobile views.

    • Visual preview
    • Tech detection
    • Network analysis
    • Console errors

    Pentest Scope Generator

    Automatically discover assets, subdomains, services, and risk areas to build a penetration testing scope document. Export-ready for security assessments.

    • Asset discovery
    • Subdomain enumeration
    • Port scanning
    • Risk prioritization

    Security.txt Checker

    Verify if a domain has a properly configured security.txt file per RFC 9116. Check for required fields, expiration, PGP signing, and compliance.

    • RFC 9116 compliance
    • Field validation
    • PGP signing check
    • Grade scoring

    Subdomain Takeover Scanner

    Discover your subdomains and check for takeover vulnerabilities. Find dangling CNAMEs before attackers do.

    • Subdomain discovery
    • CNAME analysis
    • 17+ vulnerable services
    • Risk assessment

    Email Header Analyzer

    Paste raw email headers to trace the delivery path, verify SPF/DKIM/DMARC authentication, and detect phishing indicators.

    • Hop-by-hop tracing
    • Auth verification
    • Delay detection
    • Spoof detection

    Email Security Checker

    Check your SPF, DKIM, and DMARC configuration. Prevent email spoofing and phishing attacks.

    • SPF validation
    • DMARC policy check
    • DKIM verification
    • MX record check

    DMARC Report Analyzer

    Paste or upload DMARC aggregate XML reports to visualize authentication pass/fail rates, source IP breakdown, alignment checks, and policy recommendations. 100% client-side.

    • XML parsing
    • Pass/fail breakdown
    • Alignment check
    • Policy recommendations

    SPF Flattener

    Resolve all SPF includes into flat IP addresses. Stay under the 10-lookup limit and prevent email delivery failures.

    • Include resolution
    • IP4/IP6 extraction
    • Lookup counter
    • Copy-ready record

    DNS Record Generator

    Build DNS records interactively — SPF, DMARC, DKIM, MX, CAA, A, AAAA, CNAME, and TXT. Form-based builder with copy-paste ready output and BIND zone format.

    • 9 record types
    • Interactive builder
    • Copy-paste output
    • Best practice tips

    DKIM Record Lookup

    Deep DKIM selector discovery — tests 50+ selectors, validates key strength, detects weak or revoked keys.

    • 50+ selector scan
    • Key strength analysis
    • Algorithm detection
    • ADSP check

    SSL Certificate Checker

    Verify your SSL certificate validity, expiration, and configuration. Ensure secure connections.

    • Certificate validity
    • Expiration alerts
    • Protocol version
    • Trust chain

    DNS Topology Visualizer

    Interactive infrastructure map — visualize DNS records, subdomains, CNAME chains, CDN providers, and IP geolocation in a network graph.

    • Visual network graph
    • Subdomain discovery
    • CDN detection
    • IP geolocation

    DNS Health Report

    Comprehensive DNS analysis: nameservers, CAA records, SOA configuration, TTL optimization, and more.

    • Nameserver health
    • CAA records
    • SOA analysis
    • TTL optimization

    HTTP Security Headers

    Analyze your website's HTTP security headers. Check for HSTS, CSP, X-Frame-Options, and more.

    • HSTS check
    • CSP analysis
    • X-Frame-Options
    • Referrer-Policy

    WHOIS Lookup

    Check domain registration details, expiration dates, and ownership. Verify transfer locks and privacy protection.

    • Registration info
    • Expiration dates
    • Name servers
    • Privacy check

    Reverse WHOIS Lookup

    Find all domains registered by the same organization, email, or person. Uncover hidden infrastructure and domain portfolios. SecurityTrails charges $50+/mo for this.

    • Organization search
    • Email search
    • Domain portfolio mapping
    • CSV export

    Reverse IP Lookup

    Find all domains hosted on the same IP address. Discover shared hosting neighbors, virtual hosts, and associated domains.

    • Shared hosting detection
    • ASN & org info
    • Domain discovery
    • Security assessment

    Port Scanner

    Scan common ports on any domain or IP. Identify open services, detect risky exposures, and assess your attack surface.

    • 29 common ports
    • Service detection
    • Banner grabbing
    • Risk assessment

    DNS Infrastructure Map

    Visualize your domain's entire DNS infrastructure as an interactive network graph. See nameservers, mail servers, IPs, and subdomains at a glance.

    • Interactive graph
    • Subdomain discovery
    • Record mapping
    • Visual analysis

    DNS History Lookup

    Track how a domain's DNS infrastructure has changed over time. View historical records, certificate issuances, hosting changes, and registration timeline — like SecurityTrails, but free.

    • Certificate history
    • WHOIS timeline
    • Web Archive snapshots
    • Hosting changes

    Broken Link Checker

    Scan any webpage to find broken links that hurt SEO, user experience, and security. Detects 404s, timeouts, and connection errors.

    • 404 detection
    • Timeout detection
    • Internal & external links
    • Link grading

    Mixed Content Scanner

    Detect insecure HTTP resources loaded on HTTPS pages. Find scripts, stylesheets, images, and iframes that weaken your TLS security.

    • Active mixed content
    • Passive mixed content
    • Severity grading
    • CSP recommendations

    SRI Checker

    Verify that external scripts and stylesheets use Subresource Integrity hashes to prevent CDN tampering attacks.

    • External resource detection
    • Integrity hash validation
    • Crossorigin audit
    • CDN security grading

    Cookie Security Scanner

    Analyze website cookies for missing Secure, HttpOnly, and SameSite flags. Detect CSRF and XSS risks in cookie configurations.

    • Secure flag check
    • HttpOnly analysis
    • SameSite validation
    • XSS/CSRF risk detection

    Robots.txt & Sitemap Analyzer

    Analyze robots.txt for exposed sensitive paths and sitemap.xml for crawl configuration. Discover hidden endpoints before attackers do.

    • Sensitive path detection
    • Crawl config analysis
    • Sitemap parsing
    • Security grading

    Tech Stack Detector

    Discover what technologies power any website. Identify servers, frameworks, CMS, analytics, CDN, and more.

    • Server detection
    • CMS identification
    • Analytics tracking
    • Framework detection

    Redirect Chain Tracer

    Trace every HTTP redirect hop from start to finish. Detect loops, HTTPS downgrades, excessive chains, and measure latency at each step.

    • Full chain trace
    • HTTPS downgrade detection
    • Loop detection
    • Latency per hop

    CVE Vulnerability Scanner

    Detect technologies on any website and check for known CVEs from the National Vulnerability Database. Find security flaws before attackers do.

    • Tech stack detection
    • Real-time NVD lookup
    • CVSS scoring
    • Upgrade recommendations

    Data Breach Checker

    Check if your domain has been involved in known data breaches. See exposed data types, account counts, and get risk assessments.

    • 800+ breaches checked
    • Risk assessment
    • Exposed data types
    • Recommendations

    CORS Misconfiguration Checker

    Test any domain for dangerous CORS policies. Detect origin reflection, wildcard misuse, null origin attacks, and credential leaks.

    • Origin reflection test
    • Wildcard detection
    • Null origin check
    • Credential leak analysis

    CT Log Monitor

    Search Certificate Transparency logs for all certificates ever issued for your domain. Discover subdomains, detect unauthorized issuance, and monitor CA activity.

    • Subdomain discovery
    • Unauthorized cert detection
    • CA tracking
    • Issuance monitoring

    DNS Propagation Checker

    Check DNS record propagation across 12 global resolvers. Verify that your DNS changes have propagated worldwide and identify inconsistencies.

    • 12 global resolvers
    • Multiple record types
    • Propagation %
    • Response times

    CNAME Chain Tracer

    Follow CNAME chains hop-by-hop to their final resolution. Detect dangling CNAMEs, identify cloud providers, and assess subdomain takeover risks at each level.

    • Full chain tracing
    • Takeover risk detection
    • Cloud provider ID
    • Dangling CNAME alerts

    Google Dork Generator

    Generate 50+ targeted Google dork queries for OSINT reconnaissance. Discover exposed files, admin panels, sensitive data, and vulnerability indicators on any domain.

    • 50+ dork queries
    • 6 categories
    • Risk-rated
    • One-click Google search

    Favicon Hash Lookup

    Compute the MurmurHash3 of any website's favicon for Shodan, Censys, and ZoomEye searches. Discover related infrastructure and hidden assets using favicon fingerprinting.

    • MurmurHash3
    • Shodan/Censys queries
    • Auto favicon detection
    • OSINT recon

    Password Strength Analyzer

    Check how strong your password is. Analyzes entropy, estimated crack time, keyboard patterns, common passwords, and leet speak detection. 100% client-side — nothing leaves your browser.

    • Entropy calculation
    • Crack time estimate
    • Pattern detection
    • Password generator

    SSH Key Analyzer

    Analyze SSH public keys for type, strength, fingerprints, and security issues. Supports RSA, Ed25519, ECDSA, DSA, and FIDO2 security keys. 100% client-side — nothing leaves your browser.

    • Key type detection
    • Strength grading
    • SHA-256 & MD5 fingerprints
    • Security recommendations

    Dependency Vulnerability Checker

    Scan your project dependencies for known CVEs using the OSV database. Supports package.json, requirements.txt, go.mod, Cargo.toml, and Gemfile. CSV export included.

    • Multi-ecosystem support
    • OSV database
    • Severity grading
    • CSV export

    CVSS v3.1 Calculator

    Calculate vulnerability severity scores using the Common Vulnerability Scoring System v3.1. Includes known CVE examples, vector string parsing, and severity breakdown. 100% client-side.

    • CVSS v3.1 standard
    • Vector string parser
    • Known CVE examples
    • Severity breakdown

    IDN Homograph Detector

    Detect internationalized domain name (IDN) homograph attacks. Analyze domains for confusable Unicode characters, punycode encoding, mixed scripts, and visual spoofing risks. 100% client-side.

    • Confusable char detection
    • Punycode decode
    • Mixed script analysis
    • Brand impersonation check

    ReDoS Checker

    Test regular expressions for ReDoS (Regular Expression Denial of Service) vulnerabilities. Detects catastrophic backtracking, nested quantifiers, and exponential complexity with timing analysis. 100% client-side.

    • Pattern analysis
    • Timing test
    • Severity grading
    • Fix suggestions

    Hash Generator & Verifier

    Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes for text or files. Verify file integrity by comparing hashes. 100% client-side — nothing leaves your browser.

    • 5 hash algorithms
    • File hashing
    • Hash verification
    • Security ratings

    TLS Configuration Generator

    Generate secure TLS/SSL configurations for Nginx, Apache, HAProxy, and Caddy. Based on Mozilla's recommended settings with Modern, Intermediate, and Legacy presets.

    • 4 web servers
    • 3 security levels
    • HSTS & OCSP options
    • Copy-paste ready

    Encoder / Decoder

    Encode and decode text with Base64, URL encoding, HTML entities, hex, binary, Unicode escapes, ROT13, and Punycode. Essential for security analysis and debugging. 100% client-side.

    • 8 encoding formats
    • Instant encode/decode
    • Size analysis
    • 100% client-side

    PEM Certificate Decoder

    Paste a PEM-encoded X.509 certificate and decode all fields: subject, issuer, SANs, validity, key type, extensions, and security grade. 100% client-side.

    • ASN.1 DER parser
    • SAN extraction
    • Security grading
    • SHA-256 fingerprint

    CSR Decoder & Inspector

    Paste a PEM-encoded Certificate Signing Request (PKCS#10) to decode subject, key algorithm, SANs, extensions, and get a security grade. 100% client-side.

    • Subject & DN parsing
    • Key algorithm & size
    • SAN extraction
    • Security grading

    TLS Certificate Chain Viewer

    Inspect the complete certificate trust path for any domain — leaf, intermediate CAs, and root CA with key details, validity, fingerprints, and chain grade.

    • Full chain display
    • Trust path visualization
    • Key & signature details
    • Expiry tracking

    WAF Detector

    Detect Web Application Firewalls protecting any domain. Identifies 16+ WAF and CDN providers through header analysis, response inspection, and DNS fingerprinting.

    • 16+ WAF signatures
    • Header analysis
    • DNS fingerprinting
    • Trigger detection

    Blacklist & Reputation Check

    Check if your domain or IP is on major DNS blacklists, spam databases, and security blocklists. Protect your email deliverability and online reputation.

    • 16+ blacklists
    • IP & domain checks
    • Reputation score
    • Delisting guidance

    CSP Evaluator

    Deep analysis of Content-Security-Policy headers. Detect unsafe directives, known bypass endpoints, missing protections, and get actionable XSS prevention guidance.

    • Directive analysis
    • Bypass detection
    • Nonce/hash check
    • Graded scoring

    CSP Header Builder

    Interactively build Content-Security-Policy headers with drag-and-drop directives, real-time grading, preset templates, and export for Nginx/Apache/Express.

    • Interactive builder
    • Preset templates
    • Security grading
    • Multi-format export

    IP Geolocation & ASN Lookup

    Map any IP address or domain to its geographic location, ISP, and autonomous system. Detect proxies, VPNs, hosting providers, and mobile carriers.

    • City-level location
    • ASN & ISP info
    • Proxy/VPN detection
    • Reverse DNS

    Security.txt Generator

    Create a properly formatted RFC 9116 security.txt file for your domain. Fill in fields, validate in real-time, and download or copy the result.

    • RFC 9116 compliant
    • Real-time validation
    • Copy & download
    • Deployment guide

    Phishing URL Analyzer

    Paste any suspicious URL to analyze it for phishing indicators. Detects brand impersonation, homoglyph attacks, suspicious TLDs, URL shorteners, and 12+ signals.

    • 12+ phishing signals
    • Brand impersonation
    • Homoglyph detection
    • Risk scoring

    DNS Lookup

    Query any DNS record type for a domain. Check A, AAAA, MX, NS, TXT, CNAME, SOA, and more with detailed results.

    • All record types
    • Quick lookup
    • Detailed results
    • TTL info

    HTTP Method Tester

    Discover which HTTP methods a server accepts and flag dangerous ones like TRACE (XST), PUT, DELETE, and CONNECT.

    • 9 methods tested
    • XST detection
    • Risk grading
    • Fix recommendations

    Disposable Email Detector

    Detect throwaway, temporary, and disposable email addresses. Protect against fraud, fake signups, and list hygiene issues with bulk checking support.

    • 500+ disposable domains
    • Bulk check
    • Pattern analysis
    • CSV export

    Need Continuous Monitoring?

    Sign up for WebGuarder to get automated scanning, scheduled reports, alerting, team collaboration, and 13+ security scanners for your entire infrastructure.

    Start Free Trial
    WebGuarder
    Privacy PolicyTerms of Service

    © 2026 WebGuarder. All rights reserved.