Toolkit

Four tools that answer one question each. Nothing is stored, and two of them never send anything at all.

Should I patch this?

Enter a CVE and get the same verdict the site publishes, with the evidence.
Looks up CISA KEV, NVD and EPSS through this site, so no third party sees what you searched.

Dependency check

Paste a package.json or requirements.txt and see which pinned versions have known vulnerabilities.
Only package names and versions leave your browser. Data from the OSV open vulnerability database.

Email header analyzer

Paste the raw headers of a suspicious email. In Gmail: ⋮ → Show original.
Runs entirely in your browser. Nothing is uploaded.

Passphrase strength

How long would a cracking rig need? Type to see it change.
Runs entirely in your browser. Never type a password you actually use into any website.