SSL/TLS certificate — issuer, expiry, cipher strength, SANs, TLS version
Checks SPF, DKIM, and DMARC DNS records — returns a security_score, rating, and actionable recommendations for missing or weak configurations
Web server, CMS, JS frameworks, CDN, and analytics
Query crt.sh Certificate Transparency logs for a domain and extract certificate, subdomain, and wildcard information
Autonomous System Number (ASN) and network ownership lookup via Team Cymru WHOIS — identifies ASN, BGP prefix, organization, registry, country, and allocation date for domains or IP addresses (no API key required)
Check if an IP is flagged as malicious via AbuseIPDB (api key requied)
Analyzes HTTP security headers — checks HSTS, CSP, X-Frame-Options, and more with severity ratings and misconfiguration details
Runs all core tools in parallel and returns combined result
Search NVD for known CVEs by software name and version (no API key required)
Checks for publicly accessible AWS S3, Azure Blob Storage, and Google Cloud Storage buckets using common bucket naming patterns derived from the target domain
Traces the full HTTP redirect chain hop by hop — flags TLS downgrades, private-IP leaks, redirect loops, cross-domain hops, and overly long chains
Fetch and parse robots.txt to reveal hidden directories and sitemaps
+2 more tools listed on main page