PwnDeck Scanner — Website Security & Privacy
Overview
Instant security & privacy audit for any site: headers, cookies, trackers, tech stack, vulnerable JS libraries.
----------- | English | ----------- PwnDeck Scanner runs a one-click security and privacy audit on whichever page you're visiting — no servers, no accounts, no tracking. Everything happens locally in your browser. Interface available in English and Spanish. ✅ WHAT IT CHECKS • Security headers — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COEP/COOP/CORP, X-XSS-Protection. Get a 1.0–10.0 rating with concrete fix suggestions. • Cookies — every cookie's Secure / HttpOnly / SameSite flags, size, first vs third-party, and known tracker classification. • SSL/TLS — HTTPS, HTTP/2 & HTTP/3 protocol, mixed content and server (full certificate analysis in the web report). • Technology stack — detects 200+ technologies across JavaScript frameworks, CMS platforms, e-commerce systems, analytics, CDNs, payment processors, icon libraries and authentication providers, with versions extracted when available. • Vulnerable JavaScript libraries — cross-checks the detected libraries against an offline vulnerability catalog and live OSV.dev queries to flag versions with known CVEs. • Third parties — every external script, iframe, image domain, and known tracker, with a privacy score. • Page hygiene — mixed content, insecure form submissions, password fields on HTTP, reverse tabnabbing risks, missing Subresource Integrity (SRI). • Exposed files — flags publicly readable robots.txt, sitemap and security.txt, and sensitive leaks like .env or .git/config. 🔒 PRIVACY-FIRST Everything runs in your browser — no account, no sign-up. Two requests go to our own services: the page's address to pwndeck.com (to compute a unified score so the extension and the web report match) and the names of detected libraries to osv.dev, the public CVE database. The extension also reads the visited page's response headers and checks it for well-known or exposed files — requests to the very site you're already on. No page content is ever uploaded. No analytics, no telemetry, no tracking, and no remote code execution. 👨💻 BUILT FOR Developers shipping production websites, pentesters reviewing client sites, security teams doing quick audits, students learning web security. 🌐 ALSO ON The web version with 150+ free tools (hash generators, encoders, network analyzers, JWT decoder, SSL checker, and more) is at https://pwndeck.com. ----------- | Español | ----------- PwnDeck Scanner ejecuta una auditoría de seguridad y privacidad con un solo clic sobre la página que estés visitando — sin servidores, sin cuentas, sin tracking. Todo ocurre localmente en tu navegador. Interfaz disponible en inglés y español. ✅ QUÉ ANALIZA • Cabeceras de seguridad — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COEP/COOP/CORP, X-XSS-Protection. Obtienes una nota del 1.0 al 10.0 con sugerencias concretas para corregir cada problema. • Cookies — flags Secure / HttpOnly / SameSite de cada cookie, tamaño, primera vs. terceras partes, y clasificación de trackers conocidos. • SSL/TLS — HTTPS, protocolo HTTP/2 y HTTP/3, contenido mixto y servidor (análisis completo del certificado en el informe web). • Stack tecnológico — detecta más de 200 tecnologías: frameworks JavaScript, CMS, plataformas de e-commerce, analítica, CDNs, pasarelas de pago, librerías de iconos y proveedores de autenticación. Versiones extraídas cuando están disponibles. • Librerías JavaScript vulnerables — contrasta las librerías detectadas con un catálogo de vulnerabilidades offline y consultas en vivo a OSV.dev para marcar versiones con CVEs conocidas. • Terceras partes — cada script externo, iframe, dominio de imagen y tracker conocido, con su puntuación de privacidad. • Higiene de página — contenido mixto, formularios inseguros, campos de contraseña sobre HTTP, riesgos de reverse tabnabbing, ausencia de Subresource Integrity (SRI). • Archivos expuestos — detecta robots.txt, sitemap y security.txt accesibles, y fugas sensibles como .env o .git/config. 🔒 PRIVACIDAD ANTE TODO Todo se ejecuta en tu navegador, sin cuenta ni registro. Dos peticiones van a nuestros servicios: la dirección de la página a pwndeck.com (para calcular una puntuación unificada que coincida con el informe web) y los nombres de las librerías detectadas a osv.dev, la base pública de CVEs. La extensión también lee las cabeceras de respuesta de la página visitada y comprueba si expone archivos conocidos — peticiones al propio sitio que ya estás visitando. Nunca se sube el contenido de la página. Sin analítica, sin telemetría, sin tracking y sin ejecución de código remoto. 👨💻 PENSADO PARA Desarrolladores que despliegan webs en producción, pentesters revisando sitios de clientes, equipos de seguridad haciendo auditorías rápidas y estudiantes aprendiendo seguridad web. 🌐 TAMBIÉN EN La versión web con más de 150 herramientas gratuitas (generadores de hash, codificadores, analizadores de red, decodificador JWT, checker SSL y más) está en https://pwndeck.com.
5 out of 52 ratings
Details
- Version1.6.9
- UpdatedJuly 7, 2026
- Size286KiB
- Languages2 languages
- DeveloperWebsite
Email
javiiciber@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
PwnDeck Scanner — Website Security & Privacy has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
PwnDeck Scanner — Website Security & Privacy handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser