SECUREby UNKNOWN BUILDER
Built for the Solana ecosystem. Detect cloned project sites, fake trading bots, and faΓ§ade "protocols" that look real but have no backend. Run it on any URL β no ownership required. Mint a signed trust badge for your own legit project so your users can verify at a glance.
.js.map, we reconstruct the original source93+ patterns β API keys, wallet keys, database URIs, JWTs, AWS creds. Validators cut 90% of false positives automatically.
Queries Certificate Transparency logs and discovers every subdomain your org has ever had. Scans each one.
Parses your JS bundles to find every fetch(), axios, WebSocket, and GraphQL URL β including the ones your engineers forgot about.
If you accidentally ship .js.map in production, we recover the original source tree and scan it for secrets, TODOs, and internal hostnames.
Probes 230+ plausible bucket name variants per domain for public LIST access. One of the top 3 data-leak classes on the web.
13 static detection rules for Anchor programs: signer checks, account confusion, PDA collisions, unsafe close destinations, CPI trust boundaries.
CORS reflection, GraphQL introspection, host-header injection, HTTPβHTTPS redirect, Next.js build manifest leaks.
Diff the binary against the IDL to find instructions that are callable but undocumented β the hardest class of Solana attack surface to find manually.
Every scan produces a CISO-ready report: risk score, dollar exposure range, deploy-now detection rules for your SIEM, remediation timeline.
Paste any URL. We detect phishing clones (canonical/og:url mismatch, assets pulled from the original), faΓ§ade sites (static shell, no backend, dead forms, no API calls), fake token pages (contract addresses extracted and flagged for on-chain verification), and brand-domain impersonation (title brand β domain name). Four-way verdict with hard evidence. 5 credits per check, no ownership required.
Pass a Silver+ scan and an authenticity check, mint a signed badge, embed it on your site. Verified visitors see a police-shield with your security + authenticity score. Tamper-proof (HMAC signed), expires after 30 days β recurring verification built in.
Pick the tier that matches how deep you want to go. Each scan is a one-shot payment β no subscription, no auto-renewal. Pay with the platform token for a 25% discount.
Zero-commit try-out, before you pay.
Quick surface check, one host.
Full surface map of the app.
Professional audit depth.
Deep data β everything the platform can do.
Paste any URL β investigate scam copies, faΓ§ade sites and fake token pages.
Prove to your visitors this site is real and secure.