Free Tools

Focused tools, coming soon.
The full scan is instant today.

Single-purpose tools for each check below are on the roadmap. In the meantime, the full PatchVex Web Scanner already covers all of them in one instant, free scan.

Run a full scan instead →

Coming soon

Coming Soon

Security Headers Checker

Check which security headers a URL returns: CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, and more.

HeadersCSPHSTS
Coming Soon

TLS Checker

Verify TLS version, cipher suite quality, certificate validity, and HSTS configuration for any hostname.

TLSHTTPSCertificates
Coming Soon

CORS Validator

Test how a URL responds to cross-origin requests and identify misconfigured Access-Control headers.

CORSAPIHeaders
Coming Soon

CSP Analyzer

Parse and validate a Content-Security-Policy string. Identifies missing directives, unsafe sources, and potential bypasses.

CSPXSSHeaders
Coming Soon

Cookie Analyzer

Analyze cookie attributes — HttpOnly, Secure, SameSite, Path, and Domain — for any URL.

CookiesAuthSession
Coming Soon

JWT Decoder

Decode and inspect JWT header, payload, and signature. Identifies weak algorithms and missing claims.

JWTAuthTokens
Coming Soon

Open Redirect Checker

Test URLs for open redirect vulnerabilities that attackers can use for phishing.

RedirectsPhishing
Coming Soon

Referrer Policy Checker

Verify the Referrer-Policy header value and understand what information leaks to third parties.

PrivacyHeaders
Coming Soon

Security.txt Validator

Check whether a domain has a valid /.well-known/security.txt file per RFC 9116.

DisclosureRFC 9116