Map your web surface. Validate evidence. Ship safer.
HexForge Security Lite is a free community scanner for authorized web security review. It focuses on passive checks, visible attack surface, configuration issues, and clean technical evidence without exploit automation.
{
"edition": "Lite Community",
"mode": "defensive",
"scope": "authorized targets only",
"checks": ["headers", "tls", "cookies", "cors", "forms", "routes", "client_surface"],
"output": ["evidence", "severity", "confidence", "recommendations"],
"roadmap": ["Pro automation", "Specter enterprise"]
}
Routes, API-like paths, parameters, forms, headers, TLS and client-side signals are mapped for safer manual review.
Three steps. Clean evidence.
Lite is built to help you understand a web target you own or are authorized to test. It does not brute force, exploit, or submit attack payloads.
Enter URL
Use an owned, lab, internal, or explicitly authorized target.
Analyze safely
Lite checks headers, TLS, cookies, redirects, CORS, forms, endpoints and passive client surface.
Review results
See severity, confidence, evidence, recommendations, endpoint mapping and exportable JSON.
Try Lite now. Join the Pro waitlist.
Optional: leave your Google email so Brandon can notify you when HexForge Pro and Specter are ready. Lite remains free and does not require login.
Built for signal, not noise.
Lite reviews headers, cookies, CORS, TLS, redirects, discovery files, metadata, forms, parameters, endpoint routes and passive client surface.
Headers and browser
CSP, HSTS, Referrer-Policy, Permissions-Policy, X-Content-Type-Options and iframe protection.
Crawler and surface map
Read-only same-origin crawl, visible routes, API-like paths, query parameters and endpoint mapping without fuzzing.
Evidence and translations
Every finding includes location, evidence, recommendation, confidence and multi-language rendering.
Scan โ Map โ Validate โ Decide.
HexForge Lite stays conservative: it fetches safely, maps visible surface, validates findings, and leaves active confirmation to authorized manual review.
Lite stays free. Pro and Specter grow the platform.
HexForge is being built as a real product line: Lite for the open-source community, Pro for individual power users, and Specter for advanced/enterprise workflows.
Safer by design.
The community edition is intentionally useful without becoming an exploit framework.
- Passive HTTP/TLS checks
- Read-only crawler with small limits
- Parameter and form discovery without submission
- No brute force, no exploit payload automation
Support HexForge development
If HexForge Security Lite helps you, support development or visit the official HexForgeAI website.
Run a defensive scan or inspect the source.
Use HexForge Lite on targets you own, lab environments, or systems where you have explicit authorization.