Free tools. No account, no upload.
Three tools below run entirely in your browser — nothing you type is sent to a server, and there's nothing to sign up for. More are in development; those are marked so you know what's real.
Runs locally, in this tab.
These three need no backend, so there's no rate limit, no queue, and no copy of your data anywhere.
These need a server, so they're not ready.
Listed so you know what's coming. Nothing below works yet — when one ships it moves into the section above.
Subdomain Finder
Enumerate subdomains of a domain from public certificate transparency logs.
HTTP Headers Check
Grade a site's security headers and cookie flags, with the exact value to add for each miss.
SSL / TLS Inspector
Certificate chain, expiry, protocol versions and cipher suites.
Port Scanner
Check which common ports respond on a host you own.
DNS Lookup
A, MX, TXT, NS and CNAME records with SPF and DMARC parsed.
CVE Lookup
Search a package and version against OSV and NVD, with the fixed version.
Secret Detector
Check a file or config blob for keys and tokens before you commit.
Snippet Scanner
Paste one file and get a Spartyx opinion without connecting a repo.
When the network tools land, scope matters
Port scanning, subdomain enumeration and TLS probing against systems you don't own or have written permission to test may be illegal where you live. When these ship they'll be limited to targets you can prove you control.
Need more than a single check?
Spartyx scans a whole repository — cross-file taint tracking, dependency CVEs and a PDF report. Free during beta.