nowfound

Alternatives

Products that do what Tblue – 614 passive security scanners for any website, runs locally does

Passive blue-team security scanner — 582 read-only modules, plus 32 opt-in probes. Runs on your machine. No accounts. No telemetry. - taylannuhogluofficial-png/Tblue

  1. 1

    SaaS pen-testing that surpasses the level of ethical hackers

    2022

  2. 2

    Secure code in less than 5 minutes for free

    2022

  3. 3

    A real-time website scanner to see what trackers are lurking

    2020

  4. 4MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com

  5. 5C3
  6. 6ST
  7. 7KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com

  8. 8

    AI all-in-one security scanner for Web, API, and OSINT.

    Jul 2026 · github.com

  9. 9

    Web Security Risk & AI authorship scanner

    28d ago · vulnexa.com

  10. 10

    Scan any website for leaked secrets in seconds

    Feb 2026 · nullgaze-ohm8.vercel.app

  11. 11

    Complete security scanner web app

    2025

  12. 12
    GitHub2

    All-in-one security scanning toolkit for penetration testers

    Dec 2025 · github.com

  13. 13WS

    http://webscanner.tk/quickscan/ Hi! I made this project over the couse of a week to help teach myself more about Django and web app development. I am studying computer security in school and web security is one of my passions. It is a tool that helps web developers ensure that they have implemented helpful security mechanisms like HTTPOnly flags, X-Frame-Options, etc. There are hundreds of tools that offer to scan websites for things like cross-site scripting, mySQL injection, etc. This tool simply looks for information that is available via one or two GET requests (the headers, protocols,…

    2013

  14. 14

    Free website security scanner 20+ checks, instant PDF report

    May 2026 · pulseshield.co.uk

  15. 15SS
  16. 16

    Find GDPR risks on your live site before regulators do

    Feb 2026 · securespells.com

  17. 17

    Whack the moles your current scanner can't see.

    Aug 2026 · whack.sh

  18. 18

    Free security scan that tells you exactly how to fix it

    Jun 2026

  19. 19IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  20. 20

    100% Offline SAST, Finds What Semgrep & CodeQL Miss

    Jul 2026

  21. 21TO

    I'm an infrastructure architect who started using AI assistants to write code 3 months ago. After building several systems with Claude, I noticed a pattern: the code always had security issues I could spot from my ops background, but I couldn't fix them myself since I can't actually write code. Why I built this: I needed a way to verify AI-generated code was production-safe. Existing tools either required cloud uploads (privacy concern) or produced output too large for AI context windows. TheAuditor solves both problems - it runs completely offline and chunks findings into 65KB segments that…

    Sep 2025 · github.com

  22. 22

    Free vibe coding security checklist and passive scanner

    Jul 2026 · checkmyvibeapp.com

  23. 23

    Next-Gen WordPress security scanner. Scan DEEP. Scan FREE

    Dec 2025 · wpcheckr.com

  24. 24

    Scan any website for security issues in 10 seconds. Free.

    Feb 2026 · guardscan.dev

Ranked by how close each launch is in meaning, then by votes. Refine with a description →