A few things we built for ourselves that are useful on their own -- no login, no catch.
Build a correct Coraza / ModSecurity SecLang WAF rule from simple fields -- no SecLang syntax to memorize. Copy the result straight into your own config.
Open toolCheck any site's HTTP response for HSTS, CSP, X-Frame-Options, and other security headers in seconds.
Open tool