Security & Privacy
Twenty analysers and generators for the defensive side of the job: checking a policy you wrote, reading a token you were handed, judging how strong a secret really is. Everything runs in your browser, and the ones that quote a standard say which standard and which version.
20 tools in Security & Privacy
- Checksum VerifierHash a downloaded file in your browser and compare it against the published digest, with the comparison done character by character.
- Cookie Attribute AnalyserPaste a Set-Cookie line and see which protections it is missing, and what SameSite of Lax genuinely permits that None does not.
- CORS Policy ExplainerWork out whether a given cross-origin request would actually be allowed, and why a wildcard origin silently stops working with credentials.
- Content Security Policy AnalyserPaste a Content-Security-Policy header and see which directives are doing nothing, which wildcards reopen what the rest of it closed.
- CVSS CalculatorBuild a CVSS v3.1 vector from the metrics and get the base score with the arithmetic shown, so a disputed rating can be traced to a chosen value.
- DMARC & SPF Record ExplainerRead an email authentication record back in plain words, including what a policy of none actually enforces and how many lookups SPF allows.
- Shannon Entropy CalculatorMeasure the information density of a string in bits per character — the standard way to tell an encoded blob from ordinary prose in a log.
- Hash IdentifierPaste a digest and see which algorithms produce that length and alphabet, with the ambiguous cases listed rather than a single confident guess.
- Password Hashing Cost CalculatorTime PBKDF2 in your own browser and read off the iteration count that costs an attacker most while still letting a login finish promptly.
- HMAC GeneratorSign a message with a shared key using HMAC over SHA-256 or SHA-512, for checking a webhook signature your own code is meant to produce.
- Homoglyph & Lookalike DetectorFind the Cyrillic and Greek characters hiding in a domain or filename that render identically to Latin ones, the trick behind lookalike addresses.
- JWT Security InspectorReads a token for the weaknesses rather than the contents: an unsigned algorithm, no expiry at all, a lifetime measured in years, secrets in the payload.
- Passphrase GeneratorWord-based passphrases with the entropy stated in bits, so you can see why four random words beat a mangled dictionary word you cannot recall.
- Password Strength AnalyserHow long a password would really survive an offline attack, with the dictionary words, keyboard runs and dates that shorten it named individually.
- Well-Known Ports ReferenceWhich service answers on a given port, which are assigned versus merely customary, and which ones have no business facing the internet.
- Secret Key GeneratorRandom API keys and signing secrets at whatever bit length you need, emitted as hex, base32, base64 and base64url so it drops into what the library expects.
- Security Headers AnalyserPaste your response headers and get them judged offline: what is present, what is missing, and which combinations cancel each other out.
- security.txt GeneratorBuild the RFC 9116 file that tells a researcher where to report a flaw, with the required expiry field and the mistakes that void it.
- TOTP Code GeneratorGenerate the six digits a shared secret should currently produce, for checking that an authenticator you just enrolled is actually in step.
- URL Safety InspectorPull a link apart before you follow it: punycode in the host, credentials before the at sign, a real destination buried in a redirect parameter.
Analysers, generators, and reference
The category splits three ways, and knowing which third you are in tells you what kind of answer to expect. An analyser reads something you already have and tells you what it means. A generator produces something you do not have yet, and is only as good as its source of randomness. A reference answers a lookup and holds no opinion at all.
- Analysers: the content security policy checker, the security headers report, the cookie attribute reader, the JWT security inspector, the DMARC and SPF explainer, the CORS policy explainer, the URL safety inspector, the hash identifier and the homoglyph detector.
- Generators: passwords, passphrases, secret keys, HMACs, TOTP codes and a security.txt file.
- Reference and scoring: the well-known ports table, the CVSS calculator, the Shannon entropy calculator and the password hashing cost calculator.
Where the rules in these tools come from
None of the judgements here are house opinions dressed up as standards. Where a tool applies a rule, the rule has a document behind it, and the tool names it on the page rather than leaving you to assume there was one.
The CVSS calculator implements the FIRST.org Common Vulnerability Scoring System v3.1, metric group by metric group, so a vector string produced here is the same vector string a vulnerability database would produce. The TOTP generator implements RFC 6238 and is checked against the test vectors published in RFC 6238 and RFC 4226 — including the requirement that a shared secret be at least 128 bits, which the tool checks your secret against and says so. The security.txt generator validates against RFC 9116, which defines two required fields and seven optional ones. The well-known ports reference is a subset of IANA’s own Service Name and Transport Protocol Port Number Registry, with the service names, descriptions, transports and referenced RFCs copied verbatim from it.
The homoglyph detector is the most heavily sourced tool on the site. It is built on the Unicode Consortium’s confusables.txt from Unicode Security Mechanisms (UTS #39) version 17.0.0, on UnicodeData.txt for the characters that render as nothing, and on the Unicode blocks file to name which script a character belongs to. Each of those files has a version and a date, and the tool’s own page carries them.
What a subset is, and why saying so matters
Two tools here deliberately hold less data than their source, and both say which filter was applied. The ports table keeps 116 entries out of a registry of more than 14,500, chosen for the ones that actually appear in firewall rules, scan output and incident tickets. The confusables data keeps 691 of the mappings in the Unicode file — those from a single non-ASCII code point to a single printable ASCII one — and deliberately excludes the styled presentation variants, because a mathematical or circled letter is a different trick from a lookalike.
A subset with its rule published is a usable tool. A subset presented as the whole registry is a tool that will tell you a port is unassigned when it is not, and that is the failure mode worth naming out loud.
Randomness, and the one shortcut that ruins a generator
Every generator here draws from the browser’s cryptographic random source rather than from the ordinary pseudo-random function, and that distinction is the entire security of the output. The ordinary generator is fast, seeded and predictable, and a key produced from it looks exactly as random as a real one right up to the moment somebody reproduces it.
The secret key generator shows the arithmetic on screen for the same reason: so many bits, divided by eight, is so many bytes, taken from the cryptographic source. A generator that will not tell you where its bytes came from is asking for trust it has not earned.
What none of these tools can do
They cannot see your server. The headers analyser, the CSP checker and the cookie reader all work on text you paste in, which means they assess what you say your configuration is rather than what is actually being served — useful for reviewing a policy before you ship it, and no substitute for fetching the real response afterwards.
They also cannot tell you whether a finding matters in your environment. A CVSS base score is a property of a vulnerability, not of your deployment; a missing header on a page with no session on it is not the same finding as the same header missing from an authenticated area. The scoring tools give you the number the standard defines and stop there, which is the correct place for a calculator to stop.
Three questions before you trust any of this
Should I paste a real secret or a real token in here?
Nothing you type reaches a server — these are all client-side — so the exposure is your own screen and your own clipboard rather than a third party. The professional habit still applies: anything you have displayed should be rotated if it grants access to something that matters, regardless of which tool displayed it.
Is a passphrase really stronger than a password?
It depends entirely on how it was chosen. A passphrase of words picked uniformly at random from a large word list has a calculable strength, and a long one beats a short random string comfortably. A phrase you thought of yourself is a different object with no such guarantee, because your choice is not uniform and the attacker knows the same language you do.
Why does the CVSS score here differ from the vendor’s?
Almost always because a metric was set differently — attack vector, privileges required and user interaction are the three that move a score most, and reasonable people reading the same advisory pick differently. Compare the vector strings rather than the numbers: the vector shows exactly which metric you disagree on, which the score alone never can.