Security tools
Check password strength, build Content-Security-Policy headers, audit security headers, inspect JWT claims, generate htpasswd entries and scan text for leaked secrets.
16 tools in this category · 4 sub-categories
Audit
Certificates & Keys
HTTP Headers
CSP Builder
Build a Content-Security-Policy header from per-directive sources.
Security Headers Auditor
Grade HTTP response headers against security best practices.
CORS Config Generator
Generate CORS headers/config for Nginx, Apache, Express, or Workers.
Robots.txt Security Checker
Scan robots.txt for accidental disclosure of sensitive paths.
Permissions-Policy Header Generator
Build a Permissions-Policy header controlling camera, geolocation and more.
Referrer Policy Generator
Pick a Referrer-Policy value and get header/meta/server snippets.
X-Frame-Options / Clickjacking Checker
Check if X-Frame-Options and CSP frame-ancestors block framing.
Passwords & Auth
Password Strength Checker
Estimate password entropy, crack time, and get actionable advice.
JWT Inspector
Decode a JWT and audit its claims for common issues.
Htpasswd Generator
Generate .htpasswd lines using SHA-1 or plain text.
TOTP Generator
Generate time-based one-time passcodes from a Base32 secret.
Password Policy Generator
Generate password policy rules, regex and copy for NIST or PCI presets.