Paste a URL. See what it says about you.
Every scanner below runs on a URL alone — no install, no repository access, no card. Results in about a minute. The SEO and AEO scanners print their whole report on the page with no account at all; the security and backend scanners need a free account, because their findings are a map of how to break into your site. Each tile says which it is. The course needs neither a URL nor an account.
All free tools
Learn the words developers use
Short lessons on how software is built, shipped and broken into, with a quiz after every one. No code to write, no account needed.
Website security scanner
Headers, TLS, cookies, exposed files, injection probes and the rest of the OWASP surface, from one URL.
SEO scanner
Crawling and indexing, on-page metadata, content, internal links and the speed signals search engines read.
AEO scanner
Whether ChatGPT, Claude, Perplexity, Google AI and Copilot can reach, read and cite the site at all.
Exposed API key scanner
Finds live keys shipped to the browser — Stripe, OpenAI, Supabase, Firebase and forty more providers.
Supabase RLS checker
Answers the one question that matters about a Supabase project: can a stranger read your tables?
Lovable app scanner
The same security pass, aimed at what Lovable ships by default. No repository access needed.
Vibe-coded app scanner
For an app an AI wrote most of: the mistakes those tools make repeatedly, checked in one pass.
Watch it instead of remembering to check
A free account keeps the results, tracks what changed between scans, and tells you when something breaks.