Free Security Tools

Six focused security tools for developers. No account required. No data stored. Inspired by Anthropic's Project Glasswing.

πŸ›‘οΈ
Free

Security Headers Checker

Audit any website's HTTP security headers against OWASP and Mozilla Observatory recommendations. Get a per-header grade and specific fix instructions.

  • βœ“Content-Security-Policy (CSP)
  • βœ“HTTP Strict Transport Security (HSTS)
  • βœ“X-Frame-Options, X-Content-Type-Options
  • βœ“Referrer-Policy, Permissions-Policy
HTTPHeadersOWASP
πŸ”‘
Free

JWT Decoder & Debugger

Decode JWT tokens in real time directly in your browser. Flags dangerous algorithms (alg:none), expired tokens, missing claims, and other security misconfigurations.

  • βœ“Decode header and payload instantly
  • βœ“Detect alg:none and weak algorithms
  • βœ“Check expiry and issued-at timestamps
  • βœ“Flag missing security claims
AuthenticationJWTOAuth
πŸ”
Free

Secret Scanner

Paste code, config files, or environment files to detect accidentally committed secrets. Covers API keys, tokens, certificates, passwords, and more.

  • βœ“AWS, GCP, Azure credentials
  • βœ“GitHub, GitLab, NPM tokens
  • βœ“Stripe, Twilio, SendGrid keys
  • βœ“Private keys and certificates
SecretsCredentialsCI/CD
πŸ“¦
Free

Dependency Vulnerability Checker

Paste your package.json, requirements.txt, or Gemfile to check for known CVEs in your dependencies. See severity ratings and recommended upgrade paths.

  • βœ“npm / yarn (package.json)
  • βœ“Python (requirements.txt)
  • βœ“CVE severity (critical/high/medium/low)
  • βœ“Recommended fix versions
DependenciesCVESupply Chain
βœ…
Free

OWASP Top 10 Checklist

Interactive OWASP Top 10 checklist tailored to your application stack. Track what you've covered, what needs attention, and get guidance on each category.

  • βœ“All OWASP Top 10 2021 categories
  • βœ“Stack-specific guidance
  • βœ“Exportable audit report
  • βœ“Links to OWASP resources
OWASPChecklistAudit

Coming Soon

πŸ€–
Coming Soon

AI Security Code Review

Submit a code snippet for AI-powered security analysis. Inspired by Anthropic's Project Glasswing, this tool finds injection risks, auth flaws, and insecure patterns.

AICode ReviewGlasswing

All tools are free. No account needed.

Inspired by Anthropic's Project Glasswing initiative. Learn about Claude Mythos β†’

Free Security Tools β€” Glasswing Security