Run instant, passive security checks on any website, domain, or password. No accounts, no upsells, no data hoarding — built by the pentesters at Lorikeet Security.
Each tool runs the same checks our pentesters use on day-one engagements. Pick one and get a result in under thirty seconds.
Headers, TLS, cookie flags, server fingerprints, redirects, and common misconfigurations.
Certificate chain, expiry windows, protocol support (TLS 1.0–1.3), and cipher suites.
A, AAAA, MX, NS, TXT, CNAME, SOA, CAA, and PTR records resolved instantly with TTLs.
SPF, DKIM, DMARC, MTA-STS, and BIMI configuration. Surface impersonation and spoofing risks.
Entropy analysis and crack-time estimates. Runs 100% in your browser — never sent anywhere.
Subdomain enumeration, port reachability, and a JWT decoder are next. Got a request?




A free scan tells you whether the front door is locked. Real attackers care about the rest of the house.
Free scans catch basic misconfigurations. A Lorikeet Security pentest uncovers business logic flaws, auth bypasses, injection vectors, and the hundreds of attack paths automated tools miss.
Hi, I'm Lory! Need help finding the right service? Click to chat!