The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the EverThread listing page.
A website security check that explains itself in plain English. Free, no key, observation only.
--json for machines, --fail-on urgent (or attention) to fail a CI step.everthread explain tls.expiring and everthread findings for the explanations behind every finding.Tools: check_site, explain_finding, list_findings. Works with Claude Code, Claude Desktop, Cursor, and anything else that speaks MCP.
It loads the home page the way a browser does and reads the certificate, security headers, scripts, forms, frames, redirects, a fixed handful of well-known files, and the page text. It never logs in, probes for hidden paths, or runs exploit tooling. Public results withhold the exact address of an exposed file; the site owner sees it after signing up. Only check sites you own or have permission to check.
Docs: https://everthread.live/api · Every finding explained: https://everthread.live/fix/