OPEN-SOURCE DEFENSIVE SECURITY AUTOMATION

Map your web surface. Validate evidence. Ship safer.

HexForge Security Lite is a free community scanner for authorized web security review. It focuses on passive checks, visible attack surface, configuration issues, and clean technical evidence without exploit automation.

Open source Lite edition Passive and read-only by design Built for students, builders, and small teams
hexforge-lite.json
{
  "edition": "Lite Community",
  "mode": "defensive",
  "scope": "authorized targets only",
  "checks": ["headers", "tls", "cookies", "cors", "forms", "routes", "client_surface"],
  "output": ["evidence", "severity", "confidence", "recommendations"],
  "roadmap": ["Pro automation", "Specter enterprise"]
}
HexForge logo emblem
HexForge Lite Free, defensive, structured.
Surface-first workflow

Routes, API-like paths, parameters, forms, headers, TLS and client-side signals are mapped for safer manual review.

20+focused modules
0exploit actions in Lite
7interface languages
MITopen-source license
How it works

Three steps. Clean evidence.

Lite is built to help you understand a web target you own or are authorized to test. It does not brute force, exploit, or submit attack payloads.

01

Enter URL

Use an owned, lab, internal, or explicitly authorized target.

02

Analyze safely

Lite checks headers, TLS, cookies, redirects, CORS, forms, endpoints and passive client surface.

03

Review results

See severity, confidence, evidence, recommendations, endpoint mapping and exportable JSON.

What it checks

Built for signal, not noise.

Lite reviews headers, cookies, CORS, TLS, redirects, discovery files, metadata, forms, parameters, endpoint routes and passive client surface.

๐Ÿ›ก๏ธ

Headers and browser

CSP, HSTS, Referrer-Policy, Permissions-Policy, X-Content-Type-Options and iframe protection.

๐Ÿงญ

Crawler and surface map

Read-only same-origin crawl, visible routes, API-like paths, query parameters and endpoint mapping without fuzzing.

๐Ÿ“Œ

Evidence and translations

Every finding includes location, evidence, recommendation, confidence and multi-language rendering.

Lite workflow

Scan โ†’ Map โ†’ Validate โ†’ Decide.

HexForge Lite stays conservative: it fetches safely, maps visible surface, validates findings, and leaves active confirmation to authorized manual review.

01Normalize URL
02Fetch safely
03Map routes and forms
04Validate & deduplicate
05Render translated report
Product roadmap

Lite stays free. Pro and Specter grow the platform.

HexForge is being built as a real product line: Lite for the open-source community, Pro for individual power users, and Specter for advanced/enterprise workflows.

Lite Open-source defensive scanner, passive checks, endpoint mapping, evidence, recommendations, demo reports, and community use.
Pro Planned paid tier for stronger automation, richer reports, integrations, AI-assisted summaries, and productivity workflows.
Specter Planned premium/enterprise direction for deeper orchestration, team use, advanced reporting, and controlled security automation.
Lite boundaries

Safer by design.

The community edition is intentionally useful without becoming an exploit framework.

  • Passive HTTP/TLS checks
  • Read-only crawler with small limits
  • Parameter and form discovery without submission
  • No brute force, no exploit payload automation
Ready to try it?

Run a defensive scan or inspect the source.

Use HexForge Lite on targets you own, lab environments, or systems where you have explicit authorization.