Recon, DNS, headers, and encoding — browser tools stay local; network tools call our API.
Encode or decode JSON Web Tokens in your browser. Inspect header, payload, and expiry — optional HS256 signing, nothing sent to a server.
Open →
Check if your internal package names exist on the public npm registry. Detect dependency confusion attack vectors.
Open →
Audit the HTTP security headers of any website. Score CSP, HSTS, X-Frame-Options, and more.
Open →
Inspect the SSL/TLS certificate for any domain. Check validity, expiry, issuer, and certificate chain.
Open →
Check if a website has a valid security.txt file and verify its format per RFC 9116.
Open →
Analyze the TLS configuration of any HTTPS server. Check protocol versions, cipher suites, and known vulnerabilities.
Open →
Detect the CDN or Web Application Firewall protecting any website. Identify Cloudflare, Akamai, AWS, and more.
Open →
Look up geolocation, ISP, and ASN for any IPv4 or IPv6 address.
Open →
Check a domain's DMARC policy, SPF record, and DKIM configuration. Protect your domain against email spoofing.
Open →
Look up CNAME records for any domain and trace the full chain of aliases.
Open →
Test the Cross-Origin Resource Sharing policy of any API or endpoint. Detect misconfigured CORS that could expose data.
Open →
Look up domain registration details, registrar, creation/expiry dates, and nameservers.
Open →
Query all DNS record types (A, AAAA, MX, TXT, NS, CNAME, SOA) for any domain.
Open →
Discover publicly known subdomains for any domain using certificate transparency logs and passive DNS.
Open →
Trace the full redirect chain for any URL. Detect redirect loops, mixed-content downgrades, and unnecessary hops.
Open →
• PandaONE platform
Continuous AI-driven testing on every commit — validated findings, proof packs, and PR fixes.
Get started