App category
Security and privacy
Inspect security and privacy evidence that can be checked from public configuration, published files, and supplied artifacts. These apps cover certificates, headers, authentication discovery, exposed personal data, advisories, SBOMs, and JavaScript dependencies without claiming a full penetration test.
Choose an app when
- Use SSL Certificate Check for the certificate and accepted TLS versions, Security Headers Check for browser protection headers, and Auth Discovery Check for OIDC or OAuth metadata and endpoints.
- Use Tracker Checkup to observe trackers, cookies, pixels, fingerprinting, and listeners during one browser visit.
- Use JS Vulnerability Check for libraries served by a page, SBOM Check for supplied software bills of materials, CSAF Advisory Check for CSAF documents, and STIX Bundle Check for STIX data or a TAXII collection.
Auth Discovery Check
2 tools
Check an OIDC/OAuth issuer's discovery documents in chat
CSAF Advisory Check
3 tools
Check a CSAF 2.0 security advisory before you publish it
JS Vulnerability Check
1 tool
A Retire.js scan of the external scripts present in a page's served HTML, matched against the public database of known JavaScript library vulnerabilities
SBOM Check
2 tools
Check an SBOM document before you ship it
Security Headers Check
1 tool
Reads the eight industry-standard browser protection headers straight off the live response: each one set or missing, with the value your server actually sent and a weighted header score
Tracker Checkup
2 tools
Loads a public page in a fresh instrumented Chrome profile and reports what actually ran: EasyPrivacy filter-rule tracker matches with the matching rule, cookies, ad and analytics pixels, canvas-fingerprinting and keyboard-listener hooks, session-recording services, and requests observed before the consent-interface check
SSL Certificate Check
1 tool
An openssl handshake to the URL's explicit port or 443 by default: the TLS versions a server offers, and the certificate it serves
STIX Bundle Check
2 tools
Check a hosted STIX 2.1 threat-intel bundle against the OASIS validator, with exact object, reference, and pattern evidence