Learn from real incidents. Defend your own site.
Not how to attack — how to defend, drawn from breaches that actually happened. Practical defense you can act on today, even without a security background.
- >.env exposure[ Defended ]
- >TLS / cert expiry[ Watch ]
- >Dependency CVEs[ Critical ]
- >Security headers[ Defended ]
- >Secret in repo[ Defended ]
Where to start
Pick an entry point by goal. All free, no signup.
Notable incidents & vulnerabilities
Capital One, Log4Shell, MOVEit and more — public breaches and vulnerabilities, turned into how you defend.
What this site stands for
A security product has to keep its own house in order.
We don't hold secrets
We never store your real API keys — only metadata. The safest secret is the one we can't leak.
Scan only what you own
Diagnostics run on verified domains only. Internal IPs and metadata endpoints are blocked — SSRF defense is built in.
Minimal blast radius
Isolation so one breach can't cascade. This site itself runs on a dedicated, isolated host.
We test on ourselves
This site watches its own dependencies for CVEs. The incident that started this never gets missed by a human again.