Skip to content

Security Tools

25 tools. Password generators, hash tools, encryption, and security analyzers.

Sponsor this category

Passwords & Keys

5 tools

Generate a strong secret, then test the ones you already use.

Hashing & HMAC

5 tools

Hash text or a file, sign a payload, and compare digests.

Encryption & Secrets

4 tools

Encrypt a message, share a note inside a link, test a 2FA code.

Secure Note Sharing

Create encrypted, self-destructing notes with password protection and expiration.

Security

2FA Code Tester

Test and verify TOTP two-factor authentication codes from your authenticator app.

API

Email & Identity Checks

3 tools

Validate an address or a phone number before you store it.

Privacy & Web Safety

8 tools

Strip metadata, redact data, and audit what a site sets on you.

EXIF Remover

Remove metadata from photos to protect your privacy. Strip GPS, camera info, and timestamps.

Security

DOCX Metadata Remover

Strip the author, company, template and editing history a Word document carries in its properties, without uploading the file.

Beta

Data Sanitizer

Sanitize user input for HTML, SQL, XSS, and other security threats.

API

Cookie Analyzer

Analyze browser cookies for security attributes like Secure, HttpOnly, and SameSite.

API

CSP Header Generator

Build a Content-Security-Policy header from presets and directives, with a meta tag and warnings for unsafe sources.

Beta API

Windows Update Settings Generator

Generate .reg files, PowerShell scripts, and batch files to control Windows Update behavior. Disable auto-updates, block restarts, manage driver updates.

API

Security guides

All 18

Sponsor FindUtils

Every request is reviewed by a person. You get an exact quote before anything goes live.

  • Category pages Any of 15 categories
  • Tool pages Exact paths you name
  • Category + tool One plan, one quote
Request a placement review

About this category

About Security Tools

FindUtils provides 25 browser-based security tools for password generation and strength checks, MD5 and SHA hashing, HMAC signatures, AES text encryption, 2FA code testing, and removing metadata from documents and photos. The generators and encoders use the Web Crypto API and run in your browser. The two tools that have to reach the network say so on the page, and neither sends your secret: the password breach checker and the email security checker. To decode or verify JWT tokens, use the JWT Decoder in Developer Tools; to check SSL certificates or HTTP security headers, use the Network tools. FindUtils.com is not the GNU findutils package.

Frequently Asked Questions

Are these security tools safe to use?

Almost entirely, and where it is not, the page says so. Passwords you generate, text you encrypt and hashes you compute are handled in your browser with JavaScript and the Web Crypto API, and are never sent anywhere. Two tools have to reach the network to do their job, and neither sends your secret: the password breach checker uses the k-anonymity method, sending only the first five characters of your password's SHA-1 hash to Have I Been Pwned so the password itself never leaves your device, and the email security checker looks up public DNS records for the domain you enter. Anything you paste into the other tools stays local, which you can confirm by watching your browser's network tab. These pages also load third-party analytics and advertising scripts, which see the page you are on but not what you type.

Can I trust the password generator?

The FindUtils password generator uses the Web Crypto API's crypto.getRandomValues() function, which provides cryptographically secure pseudo-random number generation (CSPRNG). This is the same entropy source used by browsers for TLS/SSL connections and is considered secure for generating passwords, tokens, and cryptographic keys. The generator runs locally in your browser with no server communication. You can customize password length from 4 to 128 characters and select character sets including uppercase, lowercase, numbers, and special symbols. The tool also displays real-time password strength analysis using the zxcvbn algorithm, showing estimated crack time and entropy bits for each generated password.

What hash algorithms are supported?

For text, the hash generator computes MD5, SHA-1, SHA-256 and SHA-512 at once, and the hash comparison tool checks a value against MD5, SHA-1, SHA-256, SHA-384 or SHA-512. The HMAC generator signs a message with a secret key using SHA-1, SHA-256, SHA-384 or SHA-512. The file hash calculator reads a file in your browser and gives its MD5, SHA-1, SHA-256 and SHA-512 checksums, which you can compare against a published value to confirm a download was not changed. The SHA family uses the browser's built-in Web Crypto API; MD5, which Web Crypto does not offer, runs in a small JavaScript implementation. Results are shown in hexadecimal. Use MD5 and SHA-1 only for checksums, not for security, and use a slow password hash such as bcrypt or Argon2 to store passwords.

Can I check if my password has been leaked?

Yes. The FindUtils password breach checker uses the Have I Been Pwned (HIBP) API with a k-anonymity privacy model. When you enter a password to check, the tool computes its SHA-1 hash locally in your browser, then sends only the first 5 characters of the hash prefix to the HIBP API. The API returns all known breached password hashes that share that prefix, and your browser checks locally whether your full hash appears in the returned set. This means your actual password, and even its complete hash, is never transmitted over the network. Have I Been Pwned is a widely used public database of passwords exposed in data breaches. The API path is different: see the tool page for what an API call sends.

Categories people open next.