Developer & Cybersecurity Toolkit

Security & Reverse Engineering Utilities

A curated suite of client-side security tools for reverse engineering bundles, analyzing cryptographic tokens, hardening HTTP headers, and inspecting web infrastructure. Press Ctrl + K to search instantly.

100% Client-Side Zero Data Transmission Free & Open Source
Showing 23 of 23 tools
SARIF v2.1
Security

SARIF Security Report Visualizer

Ingest, inspect, and analyze OASIS SARIF v2.1.0 vulnerability reports from CodeQL, Semgrep, Trivy, Snyk, and ESLint.

CodeQL & Semgrep Ingestion
Taint Dataflow & Snippet Context
Executive Markdown & CSV Export
Launch Tool
AST Tree
Reverse Engineering

JSON Formatter, Validator & Tree Explorer

Format messy JSON schemas, unescape slashes (\/), inspect collapsible AST tree nodes, auto-repair trailing commas, and minify in real-time.

Custom Indentation & Auto-Repair
Unescape Slashes (\/)
Interactive Collapsible Tree Viewer
Launch Tool
GFM & Alerts
Security

Markdown (.md) Reader & Security Studio

Render and audit Markdown (.md) documents with GFM tables, security callout alerts, XSS hygiene scanning, and live split editing.

Split & Zen Reader Views
XSS & Security Hygiene Scan
Dynamic Table of Contents & HTML Export
Launch Tool
AST v2.4
Reverse Engineering

JS to JSON Decompiler & Search

Decompile minified JS, Turbopack chunks, and Webpack modules into searchable JSON. Extract URLs, API endpoints, tokens, and functions.

Turbopack & Webpack Chunking
Automated Secret & URL Recon
Regex Search & JSON Export
Launch Tool
Auth Audit
Security

JWT & Token Security Inspector

Decode and inspect JSON Web Tokens (JWT). Audit claims, check token expiry, and evaluate algorithm security vulnerabilities.

Header & Payload Claim Parsing
Expiration & Timestamp Checks
Security Vulnerability Scan
Launch Tool
WebCrypto
Cryptography

Cryptographic Hash & Checksum

Compute SHA-256, SHA-512, SHA-1, and HMAC-SHA256 digests instantly for plain text or uploaded files using the WebCrypto API.

Hardware Accelerated SHA-256/512
File Checksum Generation
HMAC Signature Verification
Launch Tool
A+ OWASP
Hardening

HTTP Security Headers & CSP Hardener

Generate A+ grade HTTP security headers, Content Security Policies (CSP), and HSTS configurations for Nginx, Next.js, and Cloudflare.

Content Security Policy (CSP)
HSTS Preload Configuration
Nginx & Next.js Snippet Export
Launch Tool
API Studio
Security

cURL Runner & API Code Studio

Parse cURL commands, test HTTP endpoints with live execution, and convert cURL to JavaScript Fetch, Python, Go, and PHP.

Multi-Language Code Generation
Live Request Execution
Direct AI Studio Cloud Link
Launch Tool
DNS Recon
Security

Email Spoofing & DNS Security Auditor

Audit domain DNS records for anti-phishing protection, SPF fail rules, DMARC enforcement, and MX mail gateways.

SPF & DMARC Enforcement Scan
Anti-Phishing Scoring (A+ to F)
MX Exchange Gateways
Launch Tool
Phishing Recon
Security

Email Header & Hop Trace Analyzer

Inspect raw RFC 822 email headers, extract originating sender server IPs, analyze mail relay hop latency, and detect phishing indicators.

Originating Server IP Extraction
Visual Hop Relay Latency
Spoofing & Return-Path Audit
Launch Tool
API Audit
Security

CORS Misconfiguration Inspector

Audit API cross-origin security. Test for Origin reflection vulnerabilities, arbitrary origin trust, and credential exposure.

Origin Reflection Testing
Wildcard Credential Leaks
Simulated Preflight Analysis
Launch Tool
CyberChef
Reverse Engineering

Multi-Format Encoder / Decoder

Transform obfuscated payloads, strings, and hashes across Base64, Hexadecimal, URL Encoding, HTML Entities, Binary, and ROT13.

6 Bi-Directional Formats
1-Click Input/Output Swap
Zero-Latency Client Conversion
Launch Tool
AEAD WebCrypto
Cryptography

AES-GCM Authenticated Decryptor & Encryptor

Encrypt and decrypt confidential payloads using AES-128-GCM and AES-256-GCM with 128-bit authentication tag tamper verification.

128-bit / 256-bit AES-GCM
100k-iteration PBKDF2 Derivation
128-bit Auth Tag Tamper Detection
Launch Tool
WP Salts
Cryptography

Password & Salt Security Generator

Generate CSPRNG passwords, API secret keys, and WordPress salts (wp-config.php AUTH_KEY, SECURE_AUTH_KEY) with customizable entropy.

WordPress Salts (wp-config.php)
CSPRNG Entropy Meter
Batch Key & .env Generation
Launch Tool
DOM Sanitizer
Hardening

HTML Beautifier, Cleaner & Live Viewer

Format unreadable markup, sanitize DOM clutter (scripts, tracking attributes), search tags in real-time, and view isolated live previews.

Custom Indentation & Minify
Script, Style & Attribute Purge
Live Sandboxed Iframe Preview
Launch Tool
Test Studio
Security

API Payload Tester & Script Studio

Test backend proxies, execute payload assertions with JavaScript test scripts, audit SSRF boundaries, and inspect live responses.

Gemini / AI Proxy Testing
JavaScript Assertion Runner
SSRF & Auth Boundary Presets
Launch Tool
OSINT & Geo
Security

Real IP & Origin Recon Finder

Unmask origin server IPs hidden behind Cloudflare, CDNs, and WAFs. Probe unproxied subdomains, MX mail gateways, and inspect client public IP geolocation.

CDN/Cloudflare Bypass Recon
Subdomain & MX Leak Probing
Client Public IP & Geolocation
Launch Tool
X.509 & TLS
Security

SSL/TLS Certificate & Cipher Inspector

Verify HTTPS expiration dates, Root CA trust chains, Subject Alternative Names (SANs), TLS 1.3 handshake, and cipher suites.

Expiration & Countdown Alerts
SAN Subdomain Extraction
TLS 1.3 & Cipher Suite Inspection
Launch Tool
IPv4 / VLSM
Hardening

Subnet & CIDR Network Calculator

Calculate IPv4/IPv6 subnets, usable host ranges, broadcast addresses, visual 32-bit binary breakdown, and VLSM network division tables.

Visual 32-Bit Binary Breakdown
VLSM Subnet Division Tables
Interactive CIDR Cheat Sheet
Launch Tool
PKI & X.509
Cryptography

X.509 PEM Certificate & Key Inspector

Parse and validate .pem, .crt, .csr, and .pub files in-browser. Inspect Subject, Issuer, expiration, SANs, and RSA/ECC public keys.

PEM / CRT / CSR / Key Parser
SANs & Extension Extraction
Public Key & Curve Audit
Launch Tool
CWE-1333
Security

ReDoS Vulnerability & Backtracking Analyzer

Detect catastrophic backtracking in regular expressions. Identify nested quantifiers, exponential time complexity, and benchmark CPU starvation.

Catastrophic Backtracking Scan
Safe Stress Timing Benchmark
Safe Pattern Remediation
Launch Tool
OWASP API4
Security

API Rate Limit & Header Analyzer

Audit API rate limiting headers, request throttling quotas, IETF draft RateLimit fields, and DoS mitigation postures across web servers.

IETF & X-RateLimit Dissection
Retry-After & Backoff Detection
Edge WAF & Gateway Fingerprinting
Launch Tool
CLI Reference
Hardening

Security CLI Manual & Cheat Sheet

Interactive command guide for Nmap, OpenSSL, Dig, Tcpdump, and cURL with flag breakdowns and defensive hardening advice.

Nmap & OpenSSL Syntax
Flag & Parameter Dissection
Defensive Hardening Advice
Launch Tool

Need Customized Infrastructure Hardening?

SecureStack provides full enterprise hardening, Cloudflare WAF configuration, malware eradication, and automated backup orchestration for production websites.