Robert Majhen’s lab
Free security-check tools.
To find out what your site shows in public, or whether a message you received is a fraud, you should not have to pay an expert. I have done that job for thirty years, so I turned it into tools you can run yourself.
They are written for business users — companies, sole traders, associations and institutions. The suspicious-message check serves private users just as well.
Four tools running
Legitimacy check
Before you pay on a site you don’t know — what public data says about it.
Domain age, whether it lists a company ID (for .hr), payment methods, who is behind it and how to reach them, whether it imitates a known name. We open the page in a real browser, like your customer, and show what stands out. Works for someone else’s shop you check before buying, and for your own site.
Your site’s vulnerabilities
An attack rarely starts at the big hole. It starts at the thing you forgot.
The plugin that arrived with the theme three years ago, the port someone opened and never closed, the subdomain built for testing and then forgotten. The check looks only at what is publicly exposed and writes out everything it finds with a name, a version and instructions for fixing it yourself.
Email source check
Most frauds do not look like frauds. That is why they work.
What gives them away is hidden in the headers — which server the message really came from, who signed it, where the links actually lead. Paste the source of the message or attach the .eml and you get a list of what does not add up.
GDPR check
A privacy policy describes what your site does. The check shows what it actually does.
I open your site with a real browser, as an ordinary visitor, and read which tracking cookies are set before anyone clicks anything. You get their names, not an estimate.
True of all four
Everything I find, with a name and a version. No “you have seven problems, pay to see which”.
No subscription, no card, no trial. The tool runs, it finishes, that is all.
The site-vulnerability and GDPR checks need an email confirmation on the domain being checked. The email check and the legitimacy check do not even need that.
Where is the catch
Why this is free.
When someone offers an expert’s work at no charge, the question is fair. Here is the answer, without hedging.
- Most flaws are the same three or four things.
I have been finding them for thirty years, over and over. There is no reason to charge for them when a tool finds them faster than I do.
- I am not selling the findings, I am selling the fix.
You get the findings in full — name, version and instructions. If you fix it yourself and never call me, the tool did the job it exists for.
- I do not collect your data.
This page has no tracking cookies and no third-party analytics. It would be awkward for a tool that checks other people’s privacy to track its own visitors.
- The arithmetic works even if nine out of ten pay nothing.
The tenth calls when they hit something that needs a person, a scope and a signature. That is the whole business model.