Instant security checks.
No login. No signup.
Each tool runs a specific security check in seconds. Use them individually or run everything at once with the full PatchVex Web Scanner.
Run a full scan instead →Available now
Security Headers Checker
Check which security headers a URL returns: CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, and more.
Open tool →TLS Checker
Verify TLS version, cipher suite quality, certificate validity, and HSTS configuration for any hostname.
Open tool →CORS Validator
Test how a URL responds to cross-origin requests and identify misconfigured Access-Control headers.
Open tool →CSP Analyzer
Parse and validate a Content-Security-Policy string. Identifies missing directives, unsafe sources, and potential bypasses.
Open tool →Cookie Analyzer
Analyze cookie attributes — HttpOnly, Secure, SameSite, Path, and Domain — for any URL.
Open tool →JWT Decoder
Decode and inspect JWT header, payload, and signature. Identifies weak algorithms and missing claims.
Open tool →Coming soon
Open Redirect Checker
Test URLs for open redirect vulnerabilities that attackers can use for phishing.
Referrer Policy Checker
Verify the Referrer-Policy header value and understand what information leaks to third parties.
Security.txt Validator
Check whether a domain has a valid /.well-known/security.txt file per RFC 9116.