Free Tools

Free Security Tools

Quick security checks for developers. No signup required, no data stored.

Whether you're building with AI coding tools or shipping a production app, these free utilities help you verify your security configuration before vulnerabilities become problems.

JWT Debugger

Decode JWTs and catch security issues: alg:none, long-lived tokens, sensitive claims. 100% client-side signature verification.

CORS Tester

Test any URL for CORS misconfigurations. Detects Origin reflection, null origin acceptance, and preflight failures.

CSP Evaluator

Audit your Content Security Policy. Paste a CSP or fetch from URL. Graded A-F with specific fixes for unsafe-inline, wildcard sources, and more.

Secret Scanner

Scan .env files, code, or config for exposed API keys. 30+ patterns including AWS, OpenAI, Stripe, GitHub, Firebase Admin, and private keys.

SSL Certificate Checker

Check SSL certificate validity, expiry date, and TLS configuration. Get an instant security grade.

Email Security Checker

Check SPF, DMARC, and MX records for any domain. Protect against email spoofing and phishing.

Password Strength Checker

Test password strength with detailed analysis. 100% client-side - your password never leaves your browser.

Data Breach Checker

Check if your email has been exposed in a data breach. Powered by Have I Been Pwned.

DNS Security Checker

Check DNSSEC configuration and CAA records. Prevent DNS hijacking and unauthorized certificates.

security.txt Validator

Check if a website has a valid security.txt for responsible vulnerability disclosure.

SRI Hash Generator

Generate Subresource Integrity hashes for scripts and stylesheets. Protect against CDN compromises.

Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes instantly. 100% client-side.

Base64 Encoder/Decoder

Encode and decode Base64 strings. Useful for debugging tokens and inspecting encoded data.

How to Use These Tools

1

Enter Your Domain or Data

Each tool requires minimal input - just a domain name, email address, or password to check.

2

Get Instant Results

Results appear in seconds. No waiting for emails, no creating accounts, no complex setup required.

3

Take Action

Each tool provides actionable recommendations. Fix issues before they become security incidents.

Need a Full Security Scan?

These tools check individual aspects of security. VAS scans your entire application for vulnerabilities including exposed API keys, database misconfigurations, authentication issues, missing security headers, and more.

A comprehensive scan takes about 20 minutes and provides a detailed report with prioritized fixes and code examples tailored to your tech stack.

Run Full Security Scan