Free Handy Tools

Security & Privacy

Twenty analysers and generators for the defensive side of the job: checking a policy you wrote, reading a token you were handed, judging how strong a secret really is. Everything runs in your browser, and the ones that quote a standard say which standard and which version.

20 tools in Security & Privacy

Analysers, generators, and reference

The category splits three ways, and knowing which third you are in tells you what kind of answer to expect. An analyser reads something you already have and tells you what it means. A generator produces something you do not have yet, and is only as good as its source of randomness. A reference answers a lookup and holds no opinion at all.

  • Analysers: the content security policy checker, the security headers report, the cookie attribute reader, the JWT security inspector, the DMARC and SPF explainer, the CORS policy explainer, the URL safety inspector, the hash identifier and the homoglyph detector.
  • Generators: passwords, passphrases, secret keys, HMACs, TOTP codes and a security.txt file.
  • Reference and scoring: the well-known ports table, the CVSS calculator, the Shannon entropy calculator and the password hashing cost calculator.

Where the rules in these tools come from

None of the judgements here are house opinions dressed up as standards. Where a tool applies a rule, the rule has a document behind it, and the tool names it on the page rather than leaving you to assume there was one.

The CVSS calculator implements the FIRST.org Common Vulnerability Scoring System v3.1, metric group by metric group, so a vector string produced here is the same vector string a vulnerability database would produce. The TOTP generator implements RFC 6238 and is checked against the test vectors published in RFC 6238 and RFC 4226 — including the requirement that a shared secret be at least 128 bits, which the tool checks your secret against and says so. The security.txt generator validates against RFC 9116, which defines two required fields and seven optional ones. The well-known ports reference is a subset of IANA’s own Service Name and Transport Protocol Port Number Registry, with the service names, descriptions, transports and referenced RFCs copied verbatim from it.

The homoglyph detector is the most heavily sourced tool on the site. It is built on the Unicode Consortium’s confusables.txt from Unicode Security Mechanisms (UTS #39) version 17.0.0, on UnicodeData.txt for the characters that render as nothing, and on the Unicode blocks file to name which script a character belongs to. Each of those files has a version and a date, and the tool’s own page carries them.

What a subset is, and why saying so matters

Two tools here deliberately hold less data than their source, and both say which filter was applied. The ports table keeps 116 entries out of a registry of more than 14,500, chosen for the ones that actually appear in firewall rules, scan output and incident tickets. The confusables data keeps 691 of the mappings in the Unicode file — those from a single non-ASCII code point to a single printable ASCII one — and deliberately excludes the styled presentation variants, because a mathematical or circled letter is a different trick from a lookalike.

A subset with its rule published is a usable tool. A subset presented as the whole registry is a tool that will tell you a port is unassigned when it is not, and that is the failure mode worth naming out loud.

Randomness, and the one shortcut that ruins a generator

Every generator here draws from the browser’s cryptographic random source rather than from the ordinary pseudo-random function, and that distinction is the entire security of the output. The ordinary generator is fast, seeded and predictable, and a key produced from it looks exactly as random as a real one right up to the moment somebody reproduces it.

The secret key generator shows the arithmetic on screen for the same reason: so many bits, divided by eight, is so many bytes, taken from the cryptographic source. A generator that will not tell you where its bytes came from is asking for trust it has not earned.

What none of these tools can do

They cannot see your server. The headers analyser, the CSP checker and the cookie reader all work on text you paste in, which means they assess what you say your configuration is rather than what is actually being served — useful for reviewing a policy before you ship it, and no substitute for fetching the real response afterwards.

They also cannot tell you whether a finding matters in your environment. A CVSS base score is a property of a vulnerability, not of your deployment; a missing header on a page with no session on it is not the same finding as the same header missing from an authenticated area. The scoring tools give you the number the standard defines and stop there, which is the correct place for a calculator to stop.

Three questions before you trust any of this

Should I paste a real secret or a real token in here?

Nothing you type reaches a server — these are all client-side — so the exposure is your own screen and your own clipboard rather than a third party. The professional habit still applies: anything you have displayed should be rotated if it grants access to something that matters, regardless of which tool displayed it.

Is a passphrase really stronger than a password?

It depends entirely on how it was chosen. A passphrase of words picked uniformly at random from a large word list has a calculable strength, and a long one beats a short random string comfortably. A phrase you thought of yourself is a different object with no such guarantee, because your choice is not uniform and the attacker knows the same language you do.

Why does the CVSS score here differ from the vendor’s?

Almost always because a metric was set differently — attack vector, privileges required and user interaction are the three that move a score most, and reasonable people reading the same advisory pick differently. Compare the vector strings rather than the numbers: the vector shows exactly which metric you disagree on, which the score alone never can.