Resolve packages from a supplied dependency manifest, query the public OSV.dev advisory database, and return a ranked, import-checked fix list plus one pass/fail gate.
Audit which AI crawlers can access a site via robots.txt, llms.txt, and sitemap signals for GPTBot, ClaudeBot, PerplexityBot, and more.
Check whether AI crawler user agents can read public pages. Audit robots.txt, HTTP status, extracted text, required markers, and cloaking for each URL and bot.
Watches a list of Artifact Hub packages and reports each new chart version, application-version change, and change in the Artifact Hub security report summary, against a stored baseline. Each change record also gives the signature and deprecation state. P
Sends a real OPTIONS preflight and a real cross-origin GET from each origin that you name, against each API path that you name. Reports which origins the API accepts, which accept credentials, and every violation class: wildcard with credentials, origin r
Proves that a deploy serves the delivery contract that you agreed. For every URL that you name, the Actor sends header-only transactions: one request for each required compression algorithm, an HTTP-scheme probe and a trailing-slash variant, so four trans
Find the renewal that did not reach every server. For each hostname the Actor resolves every A and AAAA address, opens a TLS handshake to each address with the hostname as SNI, and compares the certificate that each address serves with the newest certific
Pulls the manifest of every pinned image reference over HTTPS and reports whether the pull works now, why it would fail, which platforms the manifest holds, the TLS name-match verdict, and how much anonymous rate budget the registry has left. HTTP only, n
Prove Gmail, Yahoo and Outlook bulk-sender conformance from a message they received. Give it raw .eml messages. It reads the receiver Authentication-Results, verifies each DKIM signature, checks SPF and DKIM alignment, the DMARC record, one-click unsubscr
Reads the public dependency dashboard issue of each repository, and reports the declared repository problems, the size of each backlog section, and the change since the last run. One row for each repository, one row for each new problem and each backlog g
Check each pinned dependency version against a release-age cooldown policy. Report which pins are still inside the window, and the date on which each one becomes admissible.
Reads the script bundles that your deployed pages load from their own origin and probes a fixed set of debug and schema paths. Reports each leaked key and each exposed endpoint with a redacted match, and gives one gate_pass verdict for your build step. HT
Polls public DNS-over-HTTPS resolvers until a record matches the expected value at every resolver, then sends one webhook and writes one sealed receipt. Built for the moment of a cutover, so the next step can start. HTTP only, no browser, no proxy, no dat
Checks 1 to 500 domains through public RDAP. Reports expiry, missing locks, risk status, and changes since the last run.
Check email HTML against 12 client profiles before you send it. Finds Outlook and Gmail breakages, dead or insecure assets, and Gmail clip-limit risk, with no browser and no render farm.
Checks that each site advertises its RSS, Atom, or JSON feed, that the feed resolves and is served correctly, and that it points back to the site.
Reads the workflow files of a public repository set and reports every `uses:` reference: mutable tag or branch against commit sha pin, archived, renamed or missing action repositories, the last release date and a risk class. One dataset row for each refer
Checks GitHub Pages sites on custom domains: DNS records for the apex and www, HTTPS status of each required path, the HTTP-to-HTTPS redirect, the certificate host name, dangling-domain risk, and the Pages API state when a token is given. Gives PASS, WARN
Validate hreflang annotations after a domain or site migration: locale syntax, duplicates, target health, canonicals, x-default, self-references, reciprocal return links, and old-domain references.
Submits published URLs to IndexNow endpoints (Bing, Yandex) with a preflight check and a receipt ledger. HTTP only, no login, no paid API.
Compare the current and the proposed version of a dependency, and report every install-time script that the new version adds, removes or changes, with the flagged lines and a clean, review or block verdict.
Turn JSON or CSV event rows into a subscribable ICS feed with stable UIDs and SEQUENCE.
Check a domain-migration redirect map: for each old-to-new URL pair, follow the live redirect chain and verify it lands on the expected target, within bounded hops.
Give it your domains. It reads _mta-sts and _smtp._tls TXT, the live MX set and the MTA-STS policy file, compares each one with the snapshot of the last run, parses your TLS-RPT report files, and tells you if the domain can move to enforce mode. It finds