← jwatte.com

Mega Security Analyzer

Security audit in a single pass across eight layers: TLS version and cipher suite, post-quantum hybrid key-exchange support, HTTP security header coverage, CSP strictness, DNS email authentication (SPF / DKIM / DMARC / CAA), MITRE ATT&CK tactic alignment, pattern-matched CWE / OWASP Top 10 / SANS Top 25 weakness indicators, and outdated JavaScript / dependency-version detection. A 3-probe consensus filters caching-layer false positives so you only see real issues. Read the walkthrough. Related: Outdated JS libraries · Modern security headers · Post-quantum crypto · Server-side probe architecture · WordPress hardening.

📖 Learn why this matters

Context and background

Read the story behind this tool: Seven Security Layers In One Scan. Mega Security Analyzer →  ·  New: why outdated libraries are the web's most common unpatched hole →

Standards & frameworks this scan maps to (18)

Every finding is aligned to a published security framework or standard, so you can hand the result to an auditor, insurer, MSP, or SOC in the language they already file it under. All marks are nominative fair use.

Threat & weakness taxonomies
MITRE ATT&CK (Enterprise)
Adversary tactics & techniques — each finding badged with its TA/T ID
CWE
Common Weakness Enumeration — the weakness class behind each finding
CWE/SANS Top 25
The 25 most dangerous software weaknesses
CVE / NVD
Public vulnerability IDs — the version layer maps old libraries to their CVEs
Application-security standards
OWASP Top 10 (2021)
Web app risk categories, incl. A06 Vulnerable & Outdated Components
OWASP ASVS
Application Security Verification Standard
OWASP Top 10 for LLM Apps
AI / prompt-injection surface (see the AEO analyzer)
Governance & control frameworks
NIST CSF 2.0
Govern / Identify / Protect / Detect / Respond / Recover
NIST SP 800-53 Rev 5
Security & privacy controls catalog
CIS Controls v8.1
Prioritized, prescriptive safeguards (Control 2: software inventory)
PCI DSS 4.0
Payment-card data security (TLS, headers, patching)
ISO/IEC 27001:2022
Information-security management system standard
Protocol & crypto standards
TLS 1.3 — RFC 8446
Transport encryption
HSTS — RFC 6797
HTTP Strict Transport Security
CSP Level 3 (W3C)
Content Security Policy
SPF / DKIM / DMARC / CAA
Email auth + CA authorization (RFC 7208 / 6376 / 7489 / 8659)
security.txt — RFC 9116
Machine-readable disclosure contact
ML-KEM — NIST FIPS 203
Post-quantum key encapsulation (hybrid KEX)