Free Security & Developer Tools
15 focused utilities for developers shipping AI-built apps. Verify one thing fast, then run a full SimplyScan for the whole picture.
- Free SSL Certificate Checker · Instantly verify a site's SSL certificate · issuer, expiration date, TLS version, and hostname match.
- Free Email Security Checker (SPF, DKIM, DMARC) · Check your domain's email authentication · SPF, DKIM, and DMARC · and see if you're vulnerable to spoofing.
- Free Security Headers Checker · Get an A-F grade on your site's HTTP security headers, including CSP, HSTS, and cross-origin isolation policies.
- Free Exposed Files Scanner · Check whether your site accidentally exposes .env, .git/config, backup archives, or other high-risk files.
- Free AI Visibility Checker (AEO) · See whether ChatGPT, Claude, Perplexity, Gemini and other AI engines can crawl and cite your site · and how to fix it if they can't.
- Free SEO Checker · Get an instant on-page SEO grade · title, meta description, indexability, structured data, Open Graph, image alt text and more.
- Free JWT Debugger & Decoder · Paste a JSON Web Token to decode its header and payload · and get flagged for alg:none, weak algorithms, missing expiry, and sensitive claims.
- Free Content Security Policy (CSP) Evaluator · Paste a Content-Security-Policy and get an A-F grade · with specific fixes for unsafe-inline, unsafe-eval, wildcards, and missing directives.
- Free Password Strength Checker · Test any password's strength · entropy, estimated crack time, and detection of common patterns and dictionary words.
- Free Hash Generator (MD5, SHA-1, SHA-256, SHA-512) · Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes from any text · instantly and entirely in your browser.
- Free Base64 Encoder & Decoder · Encode text to Base64 or decode it back · with full UTF-8 support. Handy for inspecting tokens, data URIs, and encoded config.
- Free SRI Hash Generator (Subresource Integrity) · Generate a Subresource Integrity hash for any script or stylesheet · paste the content or upload the file · so a compromised CDN can't tamper with it.
- Free DNS Security Checker (DNSSEC & CAA) · Check whether a domain is protected by DNSSEC and restricts certificate issuance with CAA records · two defenses against DNS hijacking and rogue certificates.
- Free security.txt Validator · Check whether a site publishes a valid security.txt · the RFC 9116 file that tells researchers how to responsibly report vulnerabilities.
- Free CORS Misconfiguration Tester · Test any URL for dangerous CORS misconfigurations · origin reflection, wildcard-with-credentials, and null-origin acceptance that can leak authenticated data.
Run a full security scan →