Fast, free tools for defenders.
No signup. No tracking dashboards. Client-side tools never send your data anywhere — paste, check, done.
Security Headers Checker
Grade any site's HTTP security headers — CSP, HSTS, frame protection — with plain-English fixes.
DNS Lookup
Query A, MX, TXT, SPF, DMARC and more over DNS-over-HTTPS. Includes one-click email-auth checks.
SPF & DMARC Checker
Is your domain spoofable? SPF, DMARC and DKIM checked against the RFCs, with plain-English fixes.
CVE Lookup
CVE details straight from NVD: CVSS score and vector, CISA KEV status, weaknesses, references.
JWT Decoder
Decode JSON Web Tokens locally. Header, claims, expiry sanity checks. The token never leaves your machine.
Decoder Toolbox
Base64, URL, hex, SHA hashes, epoch timestamps — the everyday conversions, all client-side.
Email Header Analyzer
Paste raw email headers: hop-by-hop path, SPF/DKIM/DMARC results, spoofing red flags.
Security Headers Generator
Pick your headers, copy exact config for nginx, Apache, Caddy, Cloudflare, IIS, and Express.
CVSS 3.1 Calculator
Score vulnerabilities to the FIRST spec: base and temporal metrics, vector string both ways.
Password Strength Checker
Live entropy estimate, pattern warnings, and time-to-crack — the password never leaves your browser.
Passphrase Generator
Strong passphrases or random passwords from the browser's crypto RNG, with a live entropy readout.
Password Entropy Calculator
Bits of entropy from length and character set, with the formula shown and a strength rating.
Brute-Force Time Estimator
Crack time from length and charset across attacker models, from throttled logins to GPU clusters.
Why these tools exist
Every tool here does one job, fast, and explains its output. Checks report only what was actually observed — no invented findings, no fake authority. Read how each check works.
weekly kev brief
Patch what's actually being exploited.
One email a week: the vulnerabilities under active attack, prioritized — no noise.
Free. No spam. Unsubscribe anytime. Delivered by Beehiiv.