Security & Reverse Engineering Utilities
A curated suite of client-side security tools for reverse engineering bundles, analyzing cryptographic tokens, hardening HTTP headers, and inspecting web infrastructure. Press Ctrl + K to search instantly.
SARIF Security Report Visualizer
Ingest, inspect, and analyze OASIS SARIF v2.1.0 vulnerability reports from CodeQL, Semgrep, Trivy, Snyk, and ESLint.
JSON Formatter, Validator & Tree Explorer
Format messy JSON schemas, unescape slashes (\/), inspect collapsible AST tree nodes, auto-repair trailing commas, and minify in real-time.
Markdown (.md) Reader & Security Studio
Render and audit Markdown (.md) documents with GFM tables, security callout alerts, XSS hygiene scanning, and live split editing.
JS to JSON Decompiler & Search
Decompile minified JS, Turbopack chunks, and Webpack modules into searchable JSON. Extract URLs, API endpoints, tokens, and functions.
JWT & Token Security Inspector
Decode and inspect JSON Web Tokens (JWT). Audit claims, check token expiry, and evaluate algorithm security vulnerabilities.
Cryptographic Hash & Checksum
Compute SHA-256, SHA-512, SHA-1, and HMAC-SHA256 digests instantly for plain text or uploaded files using the WebCrypto API.
HTTP Security Headers & CSP Hardener
Generate A+ grade HTTP security headers, Content Security Policies (CSP), and HSTS configurations for Nginx, Next.js, and Cloudflare.
cURL Runner & API Code Studio
Parse cURL commands, test HTTP endpoints with live execution, and convert cURL to JavaScript Fetch, Python, Go, and PHP.
Email Spoofing & DNS Security Auditor
Audit domain DNS records for anti-phishing protection, SPF fail rules, DMARC enforcement, and MX mail gateways.
Email Header & Hop Trace Analyzer
Inspect raw RFC 822 email headers, extract originating sender server IPs, analyze mail relay hop latency, and detect phishing indicators.
CORS Misconfiguration Inspector
Audit API cross-origin security. Test for Origin reflection vulnerabilities, arbitrary origin trust, and credential exposure.
Multi-Format Encoder / Decoder
Transform obfuscated payloads, strings, and hashes across Base64, Hexadecimal, URL Encoding, HTML Entities, Binary, and ROT13.
AES-GCM Authenticated Decryptor & Encryptor
Encrypt and decrypt confidential payloads using AES-128-GCM and AES-256-GCM with 128-bit authentication tag tamper verification.
Password & Salt Security Generator
Generate CSPRNG passwords, API secret keys, and WordPress salts (wp-config.php AUTH_KEY, SECURE_AUTH_KEY) with customizable entropy.
HTML Beautifier, Cleaner & Live Viewer
Format unreadable markup, sanitize DOM clutter (scripts, tracking attributes), search tags in real-time, and view isolated live previews.
API Payload Tester & Script Studio
Test backend proxies, execute payload assertions with JavaScript test scripts, audit SSRF boundaries, and inspect live responses.
Real IP & Origin Recon Finder
Unmask origin server IPs hidden behind Cloudflare, CDNs, and WAFs. Probe unproxied subdomains, MX mail gateways, and inspect client public IP geolocation.
SSL/TLS Certificate & Cipher Inspector
Verify HTTPS expiration dates, Root CA trust chains, Subject Alternative Names (SANs), TLS 1.3 handshake, and cipher suites.
Subnet & CIDR Network Calculator
Calculate IPv4/IPv6 subnets, usable host ranges, broadcast addresses, visual 32-bit binary breakdown, and VLSM network division tables.
X.509 PEM Certificate & Key Inspector
Parse and validate .pem, .crt, .csr, and .pub files in-browser. Inspect Subject, Issuer, expiration, SANs, and RSA/ECC public keys.
ReDoS Vulnerability & Backtracking Analyzer
Detect catastrophic backtracking in regular expressions. Identify nested quantifiers, exponential time complexity, and benchmark CPU starvation.
API Rate Limit & Header Analyzer
Audit API rate limiting headers, request throttling quotas, IETF draft RateLimit fields, and DoS mitigation postures across web servers.
Security CLI Manual & Cheat Sheet
Interactive command guide for Nmap, OpenSSL, Dig, Tcpdump, and cURL with flag breakdowns and defensive hardening advice.
Need Customized Infrastructure Hardening?
SecureStack provides full enterprise hardening, Cloudflare WAF configuration, malware eradication, and automated backup orchestration for production websites.