Finds superseded standard editions and repealed laws cited in your .rst/.md docs — ISO 27001:2013, PCI DSS 3.2.1, FIPS 140-2, Privacy Shield, the old SCCs — with the date each one died. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
Finds the standards and laws your reStructuredText or Markdown docs still cite after they died, and the date each one died; 44 rules, 30 findings in the 57-line sample page
GRC consultants bill $150-$300 an hour to read compliance documentation; a single page review is rarely under an hour
Buy the full version — $29It reads a reStructuredText, Markdown or plain text document and flags every standard edition, framework version and legal instrument you cite that has been superseded, withdrawn or repealed. Each finding names the replacement and the date the old one died. It ships 44 rules; the 57-line sample page returns 30 findings — 23 dead citations, 6 warnings, 1 note.
Maintainers of open source projects with a Sphinx security page, SaaS teams who answer customer security questionnaires, and compliance writers who keep an ISO 27001 statement of applicability or a trust page in Markdown. If your documentation is reviewed by an auditor or a procurement team, a stale citation is their first finding.
Grep finds a string you already suspected; it cannot tell you that PCI DSS v3.2.1 was retired on 2024-03-31, and it misses citations that reStructuredText wrapped across a line break. In the 57-line sample page shipped with the extension, 30 findings come back and 3 of them are wrapped that way. A chatbot is trained on the corpus that wrote the stale citations in the first place.
Checking the document open in your editor is free and complete: all 44 rules, every finding, every replacement date, no key and no limit on how often you run it. The licence adds a different job, not more of the same one. It sweeps the whole workspace and writes a dated STALE-CITATIONS.md report, file by file, that you can hand to somebody else.
GRC consultants bill $150 to $300 an hour for documentation review, and one dense compliance page rarely takes less than an hour to check against current editions. The licence is $29 once. The point is not only the money: a person reads the page the day you ask, and the standards move afterwards.
One question, answered by the person who built it. Your email only if you want the answer sent.