Generate and test passwords and keys, hash and encrypt data, and check a website’s security setup.
Create secure passwords
Score a password out of 100 by length, character variety, repeats and sequences.
Generate high-entropy random keys for APP_KEY, JWT secrets, and secure application credentials.
Generate random version 4 UUIDs, up to 100 at a time.
Generate different hashes.
Calculate MD5 Hashes
Calculate SHA Hashes
Generate bcrypt password hashes with an adjustable cost factor, or check whether text matches an existing bcrypt hash, all in your browser.
Encrypt and decrypt text with AES-256-GCM and a passphrase, entirely in your browser.
Check whether a site's SSL/TLS certificate is valid, who issued it and when it expires.
Check which common security headers a website sends.
Audit security headers, detect WAF, and visualize protection.
Check whether a domain is flagged for malware or phishing.
Create secure Content Security Policy (CSP) headers for your website.
Create a security.txt file to help researchers report vulnerabilities.
Search and analyze Common Vulnerabilities and Exposures (CVE) details.
See what any website can read about your browser — user agent, screen, GPU, fonts, canvas — without asking.
Check a card number with the Luhn algorithm and identify the likely brand. Format check only.
Parse raw email headers into key fields and a list of Received hops.
Identify domain homograph attacks using Punycode and Unicode characters.
Build Google search queries with advanced operators for research and authorized testing.
Generate an OpenSSH client Host block for your ~/.ssh/config.
We'd like to use cookies for anonymous usage statistics (Google Analytics) so we can improve the tools. Tools themselves don't need them, and your files and inputs are never part of this. See the privacy policy.