ZenovayTools

Security & Privacy Tools

Generate strong passwords, check password strength, and create HMAC signatures — all client-side.

Password Generator

Generate strong, random passwords with customizable length, characters, and complexity.

Security & Privacy

Password Strength Checker

Check how strong your password is. Get an estimated crack time and improvement suggestions.

Security & Privacy

HMAC Generator

Generate HMAC signatures using SHA-256, SHA-384, or SHA-512 with the Web Crypto API.

Security & Privacy

AES Encryption/Decryption

Encrypt and decrypt text using AES-GCM with PBKDF2 key derivation. Runs entirely in your browser.

Security & Privacy

CSP Header Generator

Generate Content-Security-Policy headers with a visual editor. Pick directives, use presets, and copy the result.

Security & Privacy

SRI Hash Generator

Generate Subresource Integrity (SRI) hashes for scripts and stylesheets. SHA-256, SHA-384, and SHA-512.

Security & Privacy

Email Header Parser

Parse raw email headers to see delivery path, SPF/DKIM/DMARC results, and hop-by-hop timestamps.

Security & Privacy

Email Deliverability Checker

Check SPF, DKIM, DMARC, and MX records for any domain. Diagnose email deliverability issues and improve inbox rates.

Security & Privacy

WordPress Security Checker

Check any WordPress site for common security issues: exposed files, outdated version signals, login page exposure, XML-RPC, and user enumeration.

Security & Privacy

Security Headers Checker

Audit all 8 modern HTTP security headers — HSTS, CSP, Permissions-Policy, Referrer-Policy, X-Frame-Options, and more. Grade A-F with privacy data-flow implications.

Security & Privacy

CSP Analyzer

Deep Content Security Policy analysis — decodes all directives, detects unsafe-inline/unsafe-eval, identifies tracker origins whitelisted in script-src, and grades CSP strength A-F with a privacy angle.

Security & Privacy

SSL/TLS Checker

Checks HTTPS configuration, HSTS header and preload status, mixed-content risks, HTTP→HTTPS redirect chain, and certificate transparency. Fast alternative to SSL Labs for quick site audits.

Security & Privacy

Password Breach Checker

Checks if a password has been exposed in known data breaches using the k-anonymity HaveIBeenPwned API. Your password is hashed in-browser and never sent to any server.

Security & Privacy

Mixed Content Checker

Scans HTTPS pages for HTTP sub-resources (blocking: scripts/stylesheets/iframes; passive: images/media). Detects CSP upgrade-insecure-requests. Grade A-F.

Security & Privacy

Server Info Disclosure

Detects HTTP headers that leak server/technology versions: Server, X-Powered-By, X-AspNet-Version, X-Generator, X-Runtime, X-Varnish. Severity-rated findings. Grade A-F.

Security & Privacy

HTTP Method Checker

Tests which HTTP methods are enabled on a URL (GET, HEAD, POST, PUT, DELETE, PATCH, TRACE). Flags dangerous methods like TRACE (XST) and unnecessary PUT/DELETE. Grade A-F.

Security & Privacy

CAA Record Checker

Checks Certification Authority Authorization (CAA) DNS records: which CAs can issue certificates, wildcard policy, iodef violation reporting. Flags missing CAA as high risk — any CA can issue certs without authorization.

Security & Privacy

Exposed Files Checker

Checks 25+ sensitive file paths: .env, .git/config, wp-config.php, phpinfo.php, .htpasswd, adminer.php, backup.sql, .ssh/id_rsa, composer.json, and more. Severity critical/high/medium/low. Grade A-F.

Security & Privacy

DMARC Record Analyzer

Analyzes DMARC policy: p=reject/quarantine/none, rua/ruf reporting addresses, pct enforcement %, adkim/aspf alignment, subdomain policy (sp=). Checks for monitoring-only vs full-enforcement policy. Grade A-F.

Security & Privacy

DKIM Record Checker

Checks DKIM selectors for your domain by testing 20 common selectors (google, selector1, mail, k1, sendgrid, etc.). Shows key type, estimated key length, hash algorithms. Flags 1024-bit weak keys and revoked keys.

Security & Privacy

TLS Certificate Checker

Queries Certificate Transparency logs (crt.sh) to show your TLS certificate expiry date, days remaining, issuer, Subject Alternative Names (SANs), and wildcard status. Checks for multiple active certs.

Security & Privacy

SPF Record Analyzer

Deep SPF record analysis: parses all mechanisms (include, ip4, ip6, a, mx, ptr), follows the include chain, counts DNS lookups against the RFC 7208 10-lookup limit, checks -all hardfail vs ~all softfail. Grade A-F.

Security & Privacy

URL Reputation Checker

Check if a URL or domain is known malware or phishing infrastructure using the URLhaus abuse.ch database. Provides threat classification, malware type, tags, and reporter information for flagged URLs.

Security & Privacy

BIMI Record Checker

Check your domain's BIMI (Brand Indicators for Message Identification) DNS record. Verifies the BIMI TXT record format, SVG logo URL reachability, VMC (Verified Mark Certificate), and DMARC policy prerequisite (p=quarantine or reject).

Security & Privacy

Subdomain Finder

Find all subdomains of a domain using Certificate Transparency logs (crt.sh). Discovers subdomains across all historical SSL/TLS certificates. Great for attack surface mapping and security audits.

Security & Privacy

DNSSEC Checker

Check if a domain has DNSSEC enabled and properly validated. Verifies the AD (Authenticated Data) flag, DNSKEY and DS records, and algorithm used. Detects broken or missing DNSSEC chains.

Security & Privacy

MX Record Checker

Check your domain's MX (Mail Exchange) records: priority ordering, mail server hostnames, A/AAAA resolution, and PTR (reverse DNS) records. Diagnoses common email delivery configuration issues.

Security & Privacy

IP Blacklist Checker

Check if an IP address or domain is listed on 15+ spam and malware blacklists including Spamhaus ZEN, SpamCop, Barracuda, SORBS, ABUSEAT CBL, DroneBL, and more. Enter domain or IP.

Security & Privacy

TLSA / DANE Checker

Check TLSA (DANE) DNS records for your domain. Validates _443._tcp and _25._tcp DANE records, parses usage/selector/matching-type fields, and verifies DNSSEC is required for DANE to be secure. Get a full DANE readiness assessment.

Security & Privacy

HSTS Preload Checker

Check if your domain is on the HSTS preload list and validate your Strict-Transport-Security header. Verifies max-age, includeSubDomains, and preload flags required for Chrome/Firefox preloading. Get eligibility status and configuration score.

Security & Privacy

Cookie Security Analyzer

Analyze cookies returned by any URL for security attributes. Checks HttpOnly, Secure, SameSite (Strict/Lax/None), Domain scope, expiry, and flags insecure configurations. Get a per-cookie security score and recommendations.

Security & Privacy

Security.txt Checker

Validate your security.txt file against RFC 9116. Checks required fields (Contact, Expires), optional fields (Encryption, Policy, Canonical), expiry status, and HTTPS hosting. Get a health score and actionable recommendations.

Security & Privacy

Subdomain Takeover Checker

Check if any of your subdomains have dangling CNAME records pointing to unclaimed third-party services (GitHub Pages, Heroku, Shopify, Azure, AWS S3, Fastly, etc.). Detects potential subdomain takeover vulnerabilities before attackers exploit them.

Security & Privacy

Cross-Origin Policy Checker

Check Cross-Origin-Opener-Policy (COOP), Cross-Origin-Embedder-Policy (COEP), and Cross-Origin-Resource-Policy (CORP) headers. These headers enable browser isolation features required for SharedArrayBuffer and high-resolution timers. Get a security score and setup guidance.

Security & Privacy

TOTP Generator

Generate time-based one-time passwords (TOTP) for two-factor authentication. Enter a secret key and get the current 6-digit code with countdown timer.

Security & Privacy

Htpasswd Generator

Generate Apache .htpasswd entries with bcrypt, MD5, or SHA1 hashing. Create password-protected directories for Apache and Nginx servers.

Security & Privacy

Password Strength Checker

Check password strength with detailed scoring. Shows entropy, estimated crack time, and criteria breakdown. Includes a secure password generator.

Security & Privacy

JWT Generator/Decoder

Generate and decode JSON Web Tokens. Encode with HMAC-SHA256 via Web Crypto API. Decode to see header, payload, and expiration status.

Security & Privacy

CSP Header Generator

Generate Content Security Policy headers visually. Configure directives with predefined sources, custom URLs, and presets.

Security & Privacy

SRI Hash Generator

Generate Subresource Integrity hashes for scripts and stylesheets. SHA-256, SHA-384, and SHA-512 via Web Crypto API.

Security & Privacy

IP Subnet Calculator

Calculate IPv4 subnet details from an IP address and CIDR prefix or subnet mask. See network address, broadcast, host range, wildcard mask, and binary representations.

Security & Privacy

Caesar Cipher

Encode and decode text using the Caesar cipher (ROT shift cipher). Supports custom shift values and brute-force all 25 possible decryptions at once.

Security & Privacy

Password Strength Meter

Analyze password strength in real time. Check entropy, crack time estimates, character set diversity, and get actionable suggestions to make passwords stronger.

Security & Privacy

Vigenère Cipher

Encode and decode text using the Vigenère polyalphabetic cipher. Enter a keyword to create a key-based substitution cipher stronger than Caesar.

Security & Privacy