Privacy tools
Security checks that stay on your device. No passwords or secrets are uploaded.
These tools evaluate and generate credentials without sending anything to a server. The password strength meter calculates entropy in bits, estimates crack time at three attack speeds, and flags matches against a common-password list — all done client-side so the password you are testing never leaves the browser. The cryptographically secure password generator uses the Web Crypto API to produce random characters from a configurable character set with no server involvement.
The Diceware passphrase generator uses the EFF long wordlist and the Web Crypto API to pick words, producing passphrases that are both high-entropy and memorable. The HTTP header security analyzer grades six security response headers — including Content-Security-Policy, Strict-Transport-Security, and X-Content-Type-Options — from A to F based on presence and configuration. The browser cookie parser decodes Set-Cookie headers and flags attributes like HttpOnly, Secure, and SameSite so you can audit cookies without a proxy tool.
Password strength meter
Live entropy bar, three crack-time speeds, common-password list, pattern warnings, no storage.
HTTP header security analyzer
Six security headers graded A to F, per-header pass/warn/fail, missing list, CSP template copy.
Password generator
Cryptographically secure random passwords with charset options, entropy meter, and crack-time estimate.
Diceware passphrase generator
EFF wordlist passphrases with crypto random picks, dice roll display, entropy, and crack time.
How to Decode Browser Cookies (HTTP Cookie Parser)
Parse Set-Cookie headers, decode values, and flag HttpOnly, Secure, SameSite, and expiry issues.