Lints security.txt against RFC 9116 and the EU Cyber Resilience Act reporting contact point that has applied since 11 September 2026. Runs entirely in your browser — nothing is uploaded.
Get the full version - workspace scan + dated JSON report
$29 once · one licence key per person or team seat · 7-day full refund. A security consultant reviewing a disclosure contact and policy starts around $150 an hour.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
13 rules that decide whether a vulnerability report ever reaches you
A security consultant reviewing a disclosure contact and policy starts around $150 an hour
Buy the full version — $29It reads a security.txt file and applies 13 rules from RFC 9116 and the EU Cyber Resilience Act disclosure expectation. It flags a missing or expired Expires line, a Contact that is not a URI, http:// URIs, duplicated fields, a Canonical that is not the /.well-known path, a CSAF link that is not provider-metadata.json, unknown field names and unparsable lines, each on its own line number.
Maintainers, platform and security engineers who ship software or connected products into the EU and own the /.well-known/security.txt file for their domain. If a stranger finding a live exploit has to guess where to send it, this file is your job, and since 11 September 2026 the Cyber Resilience Act treats it as part of your reporting duty.
Since 11 September 2026 the EU Cyber Resilience Act, Regulation (EU) 2024/2847 Article 14, gives you 24 hours for an early warning, 72 hours for a notification and 14 days for a final report on an actively exploited vulnerability, with fines up to 15 million euro or 2.5% of turnover. A chatbot cannot know today's date, so it will not tell you your Expires line ran out 75 days ago.
Linting the file you have open is free and complete: all 13 rules, every line, no key, no watermark, no limit on how often you run it. The full version changes the scope and the ownership. It scans every security.txt in the workspace in one pass and exports a dated JSON report you keep and attach to an audit or a customer questionnaire.
A security consultant reviewing a disclosure contact point and policy starts around $150 an hour, and the review is a snapshot that goes stale the day the Expires value passes. The extension is $29 once, runs on every save, and on the sample file in this repository it returns 9 findings from a 10-line file in under a second.
One question, answered by the person who built it. Your email only if you want the answer sent.