Confirm authorisation
Only test sites you own or are contracted to assess. Keep written scope for client work.
A free, browser-based toolkit for hardening your own websites the way an attacker would probe them — find exposed files, weak headers, spoofable email, expiring certificates and disclosure leaks, then fix them with a prioritised report.
Authorised use only. Scan sites you own or have written permission to test.
We send a one-time code to your email. Verified users get 3 free scans per day, then upgrade to Growth Lab Pro for unlimited access.
Scan your site for exposed .env, .git, backups, phpinfo, server-status and directory listings.
Grade HSTS, CSP, COOP, CORP, frame and MIME protection, cookie flags and disclosure.
Check MX, SPF, DMARC and CAA to stop spoofing and improve deliverability.
Read certificate issuer, validity window and days remaining to expiry.
Check responsible-disclosure and crawler-discovery files.
Test passphrase strength, decode JWTs, hash text and build a hardened CSP — all locally.
Members-only portal: download the best free pen-testing tools with official links and step-by-step usage guides.
Only test sites you own or are contracted to assess. Keep written scope for client work.
Run the exposure scan and TLS, DNS and header checks to see what's reachable and what leaks.
Close exposed files first, then fix headers, cookie flags and email spoofing. Use the report's ranked list.
Re-scan after each fix. Growth Lab Pro adds continuous monitoring so regressions email you automatically.
Free accounts get 3 scans a day. Go Pro for unlimited scans across every tool, white-label PDF reports with your own logo, the AI content assistant, rank tracking and continuous monitoring — €25/month or €200/year. Cancel anytime.