How to Use the Pigfox Tools — A Beginner's Guide

This page explains, in plain language, every free tool on Pigfox: what it does, when you'd reach for it, and exactly how to use it — step by step. No technical background needed.

Many of these are OSINT tools — open-source intelligence, which just means finding out things from information that is already public, gathered in one place and made easy. Others analyze a page or an email you point them at. None of them break into anything or touch private data; they only read what you give them or what is already out in the open. Use them responsibly and within the law.

Here's what's covered, grouped by what each tool is for. This index is generated from the tool registry, so every live tool is listed automatically — a link jumps to its guide below; a tool whose guide is still being written is marked.

OSINT & security checks

SEO & marketing analyzers

  • AI-Access Checker — See which AI crawlers your robots.txt allows or blocks, plus llms.txt and a JS-dependency check.
  • Open Graph / Social Preview Checker — Check a page's Open Graph and Twitter Card tags and preview its social card.
  • Cognitive Load Analyzer — Analyze a web page's design-induced friction across cited dimensions.
  • Keyword Generator — Turn a product or page description into structured keyword ideas grouped by theme and intent.
  • Salary Counter-Offer Script — Draft a salary counter-offer email, talking points, and a fallback line from a plain description of your offer.
  • Homepage Density Optimizer — Find the optimal number of homepage items by maximizing traffic × conversion, with a closed-form Lambert-W solution.

Utilities

  • Redirect Chain Tracer — Trace every hop a URL redirects through and flag downgrades, loops, and meta-refresh.

The tools at a glance:

ToolWhat it checksYou provideBest for
TraceCheckWhether a person has the public footprint they claim (0–100 advisory score)Name + claimed role (optional photo)Vetting a stranger who contacted you
Domain ReconA website's public DNS records and subdomainsA domain (e.g. example.com)Due diligence on a company or site
EXIF Metadata CheckHidden data inside a photo (GPS, camera, date)An image file, up to 5 MBChecking what a photo reveals before you post it
Fake Recruiter CheckA recruiter's footprint plus a scam red-flag checklistRecruiter's name (optional photo)Sanity-checking an out-of-the-blue job offer
Job-Offer Legitimacy CheckSignals to investigate in a job offer or recruiter message, plus the sender domain's ageThe offer text (and optionally the sender email or website)Sanity-checking an unsolicited job offer
Candidate Photo VerifyWhere else a candidate's photo appears online (reverse-image evidence)A candidate photo (JPEG/PNG/WebP, up to 5 MB)Recruiters spotting a reused or stock profile photo
Timeline Discrepancy CheckerInternal-consistency signals in a résumé — overlaps, date-vs-total mismatches, gaps, impossible datesRésumé or career-timeline textA first pass over a résumé's internal logic
Email Header AnalyzerAn email's route, SPF/DKIM/DMARC results, and sender-identity mismatchesThe raw email headersChecking whether a suspicious email is genuine
Website Legit CheckA website's trust signals in one pass — domain age, TLS, redirects, email-security DNS, security headersA website domainA quick trust profile of an unfamiliar site
Counterparty Due-Diligence CheckA counterparty's website trust signals, plus optional contact-email breach exposureA counterparty domain (and optionally a contact email)B2B due diligence on a supplier, client, or partner
Document Authenticity CheckStructural integrity signals in a PDF — incremental updates, appended content, cross-reference and date anomaliesA PDF (up to 10 MB)Spotting a PDF that was edited after it was created
Phishing & BEC Email AnalyzerPhishing & BEC warning signs, with an advisory risk scoreA suspicious email (headers + body)Deciding whether a scary-looking email might be a scam
DNS Email-Security CheckSPF, DMARC, MX & DKIM strictness, with an anti-spoofing gradeA domain (optional DKIM selector)Checking if your domain can be spoofed
Data-Breach & Exposure CheckWhether an email appears in known data breaches, and what was exposedAn email addressFinding out if your accounts are compromised
Certificate-Transparency Subdomain FinderA domain's subdomains from certificate-transparency logs, with issuer & validityA domainMapping your own attack surface
Prompt-Injection & System-Prompt-Leak TesterWhether an LLM system prompt resists 5 attack categories (OWASP LLM Top 10)Your system promptHardening an AI feature's system prompt
Username CheckerWhere a username exists across a curated set of platformsA usernameMapping a public footprint by handle
Username Cross-Platform CheckWhere a handle is present across a curated set of platforms (presence only)A handleDue-diligence footprint mapping by handle
Security Headers GraderA site's HTTP security headers (CSP, HSTS, framing, nosniff, and more)A URLHardening a site's response headers
SSL/TLS Certificate CheckerA domain's live TLS certificate — issuer, SANs, expiry, chain, TLS versionA domainCatching an expiring or misconfigured certificate
AI-Access CheckerWhich AI crawlers your robots.txt allows or blocks, plus llms.txt and a JS-dependency checkA URLSeeing whether AI assistants can read your site
Open Graph / Social Preview CheckerA page's Open Graph and Twitter Card tags, with a preview of its social cardA URLChecking how a link looks when shared
Cognitive Load AnalyzerA page's design-induced friction across cited dimensionsA page URLFinding what makes a page feel hard to use
Keyword GeneratorKeyword ideas grouped by theme and search intentA description of what you offerKick-starting keyword research
Salary Counter-Offer ScriptA drafted salary counter-offer — email, talking points, and a fallback lineA description of your offer and what you wantGetting words on the page for a salary negotiation
Homepage Density OptimizerThe optimal number of homepage items that maximizes traffic × conversionTwo items-vs-conversion measurements (or a known λ), optional dilution rate μDeciding how many items to feature on a homepage
Redirect Chain TracerEvery hop a URL redirects through, with downgrade, loop, and meta-refresh flagsA URLSeeing where a short or tracking link really goes

If your question is whether a particular email address has been exposed in a data breach, rather than whether a single message is genuine, use the Breach Check below.

The step-by-step guides below are grouped the same way as the index above. Each one explains what the tool is, when you'd reach for it, and exactly how to use it.

OSINT & security checks

1. TraceCheck

What it is. Imagine someone emails you claiming to be a recruiter at a big company, or an investor, or a hiring manager. TraceCheck helps you answer one simple question: does this person actually exist in public, under the name and role they claim? Real professionals usually leave traces — a company profile, past roles, news mentions. TraceCheck runs a live web search and gives you an advisory footprint-consistency score out of 100, along with the links it found.

When you'd use it. A stranger reaches out with an opportunity that sounds great, and you want a quick gut-check before replying or sharing anything about yourself.

How to use it, step by step:

  1. In Subject name, type the person's full name (for example, Jane Smith).
  2. In Claimed role, type the role they say they have — for example recruiter, VC partner, hiring manager, or a company name.
  3. Optionally, attach a profile photo they sent you. This runs a reverse-image / "catfish" check to see whether the picture belongs to someone else.
  4. Click Check footprint and wait a few seconds — it's running a real search, so it isn't instant.

How to read the result. You'll get a score out of 100, a count of how many signals were found, and a list of evidence links (things like a Wikipedia page, LinkedIn profile, or news articles). A higher score means lots of consistent public presence was found. A low score means very little verifiable footprint turned up — which is a reason to be careful and dig deeper, not proof that they are a scammer. It's an advisory signal to use alongside your own judgement.

Good to know (limits). You get 3 free checks in a rolling 30-day window. After that you'll see a friendly "paid checks coming soon" message instead of a result.

Try TraceCheck →


2. Domain Recon

What it is. Every website lives at a domain (like example.com). Behind that domain is a set of public "phone book" entries called DNS records that say where the site lives and who handles its email. Domain Recon looks those up for you, and also tries to discover the domain's subdomains (like mail.example.com or staging.example.com).

When you'd use it. You're checking out a company, doing a bit of due diligence, or you're simply curious how a website is set up.

Which one do I want? Reach for Domain Recon when you want a broad profile of a domain — its addresses, mail servers, name servers and text records, with subdomains alongside them.

How to use it, step by step:

  1. Type a domain like example.com. Pasting a full URL straight from the address bar is fine — it's reduced to the domain for you.
  2. Click Run recon. Results appear below after a few seconds.

How to read the result. You'll see several lists, each explained here in plain terms:

  • IPv4 / IPv6 (A / AAAA) — the numeric internet addresses the domain points to.
  • Mail servers (MX) — the servers that receive the domain's email.
  • Name servers (NS) — who runs the domain's DNS (often the hosting or DNS provider).
  • TXT records — miscellaneous text notes, like anti-spam settings and verification tokens.
  • Subdomains — other hostnames under the domain, discovered from public certificate logs.

Good to know (limits). The tool is completely passive — it only reads already-published information and never contacts the target's own servers. The subdomain part uses a free public service (crt.sh, a log of website security certificates), which can sometimes be slow or unavailable. If that happens, the DNS records still show and a short note explains that subdomain discovery was skipped.

Try Domain Recon →


3. EXIF Metadata Check

What it is. When a phone or camera takes a photo, it often tucks hidden details inside the image file — this is called EXIF metadata. It can include the exact GPS location where the photo was taken, the camera or phone model, and the date and time. This tool reads that hidden data and shows it to you.

When you'd use it. You want to know whether a photo reveals where it was taken — for example, to check what one of your own photos might be giving away before you post it, or to understand a picture someone sent you.

How to use it, step by step:

  1. Click to choose an image file — a JPEG, PNG, or WebP, up to 5 MB.
  2. Click View metadata.

How to read the result. If the photo carries metadata, you'll see it laid out clearly: if there's a location, you get the GPS coordinates plus a map link; you'll also see the camera make and model, the date taken, and technical details like dimensions and orientation. If you instead see "No metadata found," that's completely normal — screenshots and photos saved from social media usually have their metadata stripped away, so there's simply nothing hidden to show.

Good to know (privacy). Your image is never stored. It's read to pull out the metadata during your request and then discarded — nothing is written to disk or a database.

Try EXIF Metadata →


4. Fake Recruiter Check

What it is. Fake recruiters are one of the most common job scams — someone poses as a recruiter for a real company to get money or personal details out of you. The Fake Recruiter Check is a focused version of TraceCheck built for exactly this situation: it runs the same public-footprint search (with the role already set to "recruiter") and pairs it with a checklist of warning signs.

When you'd use it. A recruiter messages you out of the blue — maybe with an offer that seems too good to be true — and something feels off.

How to use it, step by step:

  1. Enter the recruiter's name. The Claimed role field is already filled in as "recruiter," so you don't have to.
  2. Optionally attach the profile photo they used, for a reverse-image / catfish check.
  3. Click Check footprint and wait a few seconds for the advisory score and evidence links.

Watch for these red flags (any one is worth pausing over; several together is a strong warning):

  • Messaging from a free email address (like gmail) instead of a real company domain.
  • Asking you to pay for training, equipment, or an "onboarding kit."
  • Pressure and urgency — "the offer expires today."
  • Rushing you off-platform to WhatsApp or Telegram.
  • Little or no verifiable public footprint under their name.

How to read the result & limits. Just like TraceCheck, the score is an advisory signal — a low score means "verify further," not proof of a scam. Use it together with the red-flag checklist above. This tool shares the same 3-free-checks-per-30-days allowance as TraceCheck.

Try the Fake Recruiter Check →


5. Job-Offer Legitimacy Check

What it is. Paste a job offer or recruiter message and this tool reads it for the patterns worth a second look — the ones common in job-offer scams, like upfront-payment requests, off-platform contact, mismatched sender domains, and too-good-to-be-true pay. It uses an AI model to read the message and, if you add the sender's email or website, checks how recently that domain was registered. It surfaces signals to investigate, never a verdict.

When you'd use it. An offer lands out of the blue and you want a structured second read before you reply, share personal details, or send any money.

How to use it, step by step:

  1. Paste the full offer or recruiter message into The offer or recruiter message box.
  2. Optionally add the sender email or company website (for example recruiter@acme-hiring.com or acme-hiring.com) so the domain's age can be checked.
  3. Click Check this offer.

How to read the result. You'll get any sender-domain age plus a list of signal cards — each with a category, a severity badge, what was observed, and why it's worth checking. These are prompts for your own follow-up, not conclusions. If nothing stands out you'll see a short "nothing stood out" note, which is reassuring but not a guarantee.

Good to know (limits). This runs an AI model, so it's metered: 1 free check per day, then a friendly note points you to the plans. Read the signals alongside your own judgement.

Try the Job-Offer Check →


6. Candidate Photo Verify

What it is. For recruiters and hiring teams: upload a candidate's photo and this tool runs a reverse-image search to show where else that picture appears online. A photo that turns up as stock imagery, or on unrelated profiles under other names, is a signal worth investigating — not proof of anything by itself.

When you'd use it. A candidate's photo feels off, or you want a quick due-diligence step before advancing someone you've only met online.

How to use it, step by step:

  1. Choose the Candidate photo — a JPEG, PNG, or WebP up to 5 MB.
  2. Click Run the reverse-image check and wait a few seconds.

How to read the result. You'll see counts of exact and similar matches and how many distinct sites they came from, any associated names or entities, and a list of pages using the image. Treat matches as leads to verify — the same face can appear legitimately in many places.

Good to know (privacy & limits). Your photo is held in memory only for the lookup and never stored. This uses a metered search vendor, so it's 1 free check per day.

Try the Candidate Photo Verify →


7. Timeline Discrepancy Checker

What it is. Paste a résumé and this tool reads it for internal-consistency signals: roles that overlap in time, stated totals that don't match the dates, unexplained gaps, and technologies or certifications dated before they existed. It uses an AI model to extract the claims, then checks them against each other. It flags things to look into, not conclusions about the person.

When you'd use it. You're screening a CV and want its internal timeline sanity-checked before you invest in an interview.

How to use it, step by step:

  1. Paste the full work history into Résumé or career-timeline text.
  2. Click Check for discrepancies.

How to read the result. Each finding has a category, a severity badge, a description, and — where possible — the lines it came from. They're starting points for a conversation, not judgements; dates are often just typos. "No internal discrepancies" means nothing stood out this pass.

Good to know (limits). v1 checks internal consistency only — it makes no external calls and verifies nothing against the outside world. It runs an AI model, so it's 1 free check per day.

Try the Timeline Checker →


8. Email Header Analyzer

What it is. Every email carries hidden headers that record which servers it passed through and whether it passed the standard anti-forgery checks. The Email Header Analyzer reads those headers and lays them out in plain terms: the route the message took, the SPF/DKIM/DMARC results, and whether the visible sender matches the address the mail actually came from.

When you'd use it. An email looks like it's from your bank, a colleague, or a service you use, and you want to check whether it's genuine before clicking anything.

How to use it, step by step:

  1. Open the message and find its raw headers — in Gmail, the three-dot menu → Show original; in Outlook, File → Properties or View → Message details.
  2. Copy everything and paste it into the box.
  3. Click Analyze headers. The report appears immediately below.

How to read the result. A green run of SPF, DKIM, and DMARC all passing is a good sign. A fail — especially DMARC — or a From domain that doesn't match the Return-Path is worth pausing over. The Received table shows the message's journey from origin to your inbox; unusual origins or long unexplained delays can be telling.

Good to know (privacy). The headers you paste are read during your request and then discarded — nothing is stored. The analysis is entirely local and never contacts the sender's servers.

Try the Email Header Analyzer →


9. Website Legit Check

What it is. Enter a domain and this tool runs several live checks at once — how old the domain is, its TLS certificate, where it redirects, its email-security DNS, and its security headers — and gathers the results as signals to investigate. A brand-new domain with weak setup is worth caution; none of it is a verdict on the site.

When you'd use it. A shopping site, a "partner," or a link you were sent is unfamiliar and you want a fast trust read before trusting it with money or data.

How to use it, step by step:

  1. Type the Website domain (for example example.com).
  2. Click Check this website and wait a few seconds while the checks fan out.

How to read the result. You'll see the domain's age and a list of signals, each with a category, a severity badge, and what was observed; any checks that couldn't run are listed separately. Weigh the signals together — one weak header isn't much, but a very young domain plus several weak signals is worth more caution.

Good to know (limits). The checks are passive — public records and live connections only. It fans out several live checks, so it's 1 free check per day.

Try the Website Legit Check →


10. Counterparty Due-Diligence Check

What it is. A business-facing door onto the same trust checks as the Website Legit Check, aimed at vetting a supplier, client, or partner. Enter their domain — and optionally a contact email — and it gathers website trust signals plus, if you add an email, whether that address appears in known breaches. All of it is signals to investigate for your own due diligence.

When you'd use it. Before onboarding a new counterparty, or before acting on a change to their payment details, you want a documented due-diligence pass.

How to use it, step by step:

  1. Enter the Counterparty website domain (for example acme-supplier.com).
  2. Optionally add a Contact email to include a breach-exposure signal.
  3. Click Run the due-diligence check.

How to read the result. You get the domain's age, a list of website trust signals (category, severity, observation), and — if you supplied an email — a breach-exposure signal. Checks that couldn't run are listed. These support your own judgement; they aren't a rating of the company.

Good to know (limits). Passive checks only. It fans out several live checks, so it's 1 free check per day.

Try the Counterparty Check →


11. Document Authenticity Check

What it is. Upload a PDF and this tool inspects its internal structure — not its words — for integrity signals: incremental updates layered on the original, content appended after signing, and cross-reference or date anomalies. These are the fingerprints left when a PDF is edited after the fact. It surfaces signals to investigate, not a judgement on whether the document is genuine.

When you'd use it. Someone sends a bank statement, invoice, or certificate as a PDF and you want a structural sanity check before relying on it.

How to use it, step by step:

  1. Choose the PDF document — up to 10 MB.
  2. Click Check this document.

How to read the result. You'll see the filename, a short summary, and a list of integrity signals (category, severity, observation); anything that couldn't be checked on the file is listed too. An incremental update is normal for many PDFs — read the signals as prompts to look closer, not proof of tampering.

Good to know (privacy & limits). The scan is pure structure — no AI, no external calls — and your file is never stored. A full scan runs per request, so it's 1 free check per day.

Try the Document Authenticity Check →


12. Phishing & BEC Email Analyzer

What it is. Where the Email Header Analyzer inspects the technical route of a message, the Phishing Analyzer reads the content of a suspicious email and scores how likely it is to be a scam. It looks for the tricks phishing and "business email compromise" messages rely on: lookalike domains, links that hide their true destination, high-pressure language, requests to confirm a password, and sudden changes to bank details.

When you'd use it. An email tries to alarm or rush you — "your account will be suspended," "confirm your password," "our bank details have changed" — and you want a second opinion before you act.

How to use it, step by step:

  1. Copy the suspicious email — ideally the raw source, including headers and the HTML body (in Gmail, Show original).
  2. Paste it into the box and click Analyze email.
  3. Read the score and the checklist of signals that fired, each with the exact snippet that triggered it and what to do about it.

How to read the result. The score is out of 100 and grouped into low, medium, or high. It's advisory — a high score means "treat this as hostile and verify," not a courtroom verdict. The value is in the checklist: it shows you why the email looked risky, so you learn the patterns.

Good to know (privacy). The email is analyzed in memory during your request and discarded. Nothing is stored, and the tool never contacts the sender or opens any link.

Try the Phishing Analyzer →


13. DNS Email-Security Check

What it is. The previous two tools help you judge an email you received. This one checks an email domain from the defender's side: does it stop other people from sending fake mail in its name? It reads the domain's SPF, DMARC, and (optionally) DKIM records and grades how spoof-proof it is.

When you'd use it. You own or manage a domain and want to know whether scammers can impersonate it — or you're vetting a company's security hygiene.

How to use it, step by step:

  1. Enter a domain like example.com. Pasting a full URL straight from the address bar is fine — it's reduced to the domain for you.
  2. Optionally add a DKIM selector if you know it (found in a sent message's DKIM-Signature header, the s= value). Leave it blank otherwise.
  3. Click Check DNS security.

How to read the result. You get a letter grade from A to F and a card for each record. SPF ending in -all and DMARC at p=reject is the gold standard; ~all or p=none means protection is partial. Each card includes the exact fix to raise your grade.

Good to know. The tool only reads public DNS. It never sends email and never connects to the domain's servers.

Try the DNS Security Check →


14. Data-Breach & Exposure Check

What it is. Companies get hacked, and when they do, their users' email addresses and passwords often end up in public leaks. The Breach Check tells you whether your email address has appeared in any known breach, which ones, and what kind of data was exposed — so you know which passwords to change.

When you'd use it. Periodically, or right after you hear a service you use was hacked, to see whether your address is caught up in it.

How to use it, step by step:

  1. Enter one of your own email addresses.
  2. Click Check for breaches.
  3. Read the list of breaches, when each happened, and what was exposed.

How to read the result. If your address turns up, don't panic — it usually means a site you signed up for was breached, not that you did anything wrong. Change any password you reused, starting with your email and bank, and turn on two-factor authentication. If nothing is found, that's reassuring but not a guarantee; keep using unique passwords.

Good to know (privacy). Your email is used only to run the lookup during your request and is never stored or added to any list.

Try the Breach Check →


15. Certificate-Transparency Subdomain Finder

What it is. Every time a website gets an HTTPS certificate, that certificate — including the hostname it covers — is written to a public log called certificate transparency. The Subdomain Finder searches those logs to list a domain's subdomains, like mail.example.com or staging.example.com, along with who issued each certificate and when it's valid.

When you'd use it. You manage a domain and want to see everything of yours that's exposed to the internet — including forgotten staging or admin hosts that are easy to overlook and risky to leave running.

Which one do I want? Reach for the Subdomain Finder when the only question is enumerating subdomains from certificate logs, with the issuer and validity of each certificate.

How to use it, step by step:

  1. Enter a domain like example.com. Pasting a full URL straight from the address bar is fine — it's reduced to the domain for you.
  2. Click Find subdomains and wait a few seconds.
  3. Review the table of discovered subdomains, each with its certificate issuer and validity dates.

How to read the result. Each row is a hostname that has had a public certificate. Look for anything you didn't expect — old test sites, admin panels, or services you thought were retired — and make sure each is patched, protected, or shut down.

Good to know. This is passive: it only reads public certificate logs and never scans or contacts the domain's servers. Use it on domains you own or are authorized to assess. A free shared log source can occasionally be slow; a note will tell you if so.

Try the Subdomain Finder →


16. Prompt-Injection & System-Prompt-Leak Tester

What it is. If you build anything on top of an AI model, you write a system prompt — the hidden instructions that tell the model how to behave. Attackers try to break those instructions ("ignore everything above and…") or trick the model into revealing them. This tool reads your system prompt and tells you, category by category, whether it's likely to hold up, mapped to the industry-standard OWASP LLM Top 10.

When you'd use it. Before shipping an AI chatbot, assistant, or agent — or when reviewing one — to catch weak spots in its instructions.

How to use it, step by step:

  1. Paste your system/developer prompt into the box (no secrets or API keys — they aren't needed).
  2. Click Analyze prompt.
  3. Read the per-category verdicts and the concrete rule each one suggests adding.

How to read the result. Each of five attack categories comes back hardened, partial, or vulnerable, with a plain explanation and a fix you can paste straight into your prompt. A "hardened" result is encouraging but not a guarantee — always follow up with real adversarial testing.

Good to know (safety & privacy). This is analysis only: it evaluates the text you paste locally and never sends your prompt to any model, attacks any endpoint, or makes any outbound request. Nothing is stored. It's the defensive companion to the LLM engineering work behind this site.

Try the Prompt-Injection Tester →


17. Username Checker

What it is. People tend to reuse the same handle everywhere. The Username Check takes a username and looks for it across a curated set of platforms, showing you where a profile with that name exists and linking straight to it. It's a footprint tool, like a lightweight TraceCheck keyed on a handle instead of a name.

When you'd use it. To see how far your own handle spreads across the web, or to gather public profile links for someone during due diligence.

How to use it, step by step:

  1. Enter a username like octocat.
  2. Click Check username and wait a few seconds while the platforms are checked in parallel.
  3. Review the grid: each platform shows found, not found, or unknown, with a link to any profile found.

How to read the result. "Found" means a profile with that name exists on that site — not that it belongs to a particular person, since handles are widely reused. "Unknown" means the site blocked or didn't give a reliable answer. Use the found profiles as leads to verify, not as proof of identity.

Good to know. The checks are passive — they only request public profile pages — and run against a fixed, curated list of sites, so the tool can't be aimed at arbitrary targets. It's rate-limited to stay a good citizen.

Try the Username Check →


18. Username Cross-Platform Check

What it is. An investigator-framed door onto the same engine as the free Username Checker: enter a handle and it reports which of a curated set of platforms have a profile with that name. It's presence only — that a handle exists somewhere doesn't tie it to a particular person, since handles are widely reused.

When you'd use it. You're building a due-diligence footprint for a handle and want the presence map with the investigator framing.

How to use it, step by step:

  1. Enter the Handle (for example octocat).
  2. Click Check this handle and wait a few seconds while the probes fan out.

How to read the result. You'll see a summary like "handle X is present on N of M platforms" and a per-platform list marked present, absent, or unknown, with links. Use the present profiles as leads to verify — presence is not identity.

Good to know (limits). Passive, curated-list probes only. It fans out live probes, so it's 1 free check per day. For the same engine with no daily limit, use the free Username Checker.

Try the Username Cross-Platform Check →


19. Security Headers Grader

What it is. Enter a URL and this tool reads the site's HTTP security headers — the response settings that tell browsers how to protect your visitors — and sorts them into good, weak, and missing, with what each miss exposes. There's deliberately no made-up composite score; you see each header on its own merits.

When you'd use it. You run a site and want to know which security headers to add or tighten.

How to use it, step by step:

  1. Enter the URL (for example https://example.com).
  2. Click Grade headers.

How to read the result. You get a count of good, weak, and missing headers and a table row for each — its status band, current value, and what a miss exposes. Work down the weak and missing rows; each explains the risk so you can prioritize.

Good to know. Free to use. It only reads the page's response headers over a normal request — it never changes anything.

Try the Security Headers Grader →


20. SSL/TLS Certificate Checker

What it is. Enter a domain and this tool connects to it and reads the live TLS certificate: who issued it, which hostnames it covers, when it expires, whether the chain validates, and the negotiated TLS version and cipher. The headline number is simply how many days until it expires.

When you'd use it. You want to confirm a certificate is valid and not about to lapse — or to diagnose a browser TLS warning.

How to use it, step by step:

  1. Enter the Domain (for example example.com).
  2. Click Check certificate.

How to read the result. You'll see an expiry band (healthy, expiring soon, or expired) with the days remaining, a detail table (common name, SANs, issuer, validity dates, chain result, TLS version, cipher), and any warning flags. A negative day count means it has already expired.

Good to know. Free to use. It makes a normal TLS connection and reads the presented certificate; it changes nothing.

Try the SSL Certificate Checker →


SEO & marketing analyzers

21. AI-Access Checker

What it is. Enter a URL and this tool reads your robots.txt to show which AI crawlers (the bots behind assistants like ChatGPT and Perplexity) you allow or block, checks for an llms.txt file, and flags whether your page needs JavaScript to show its text — which many crawlers can't run.

When you'd use it. You want your content readable (or deliberately not) by AI assistants and search features, and you're not sure what you're currently allowing.

How to use it, step by step:

  1. Enter the URL (for example https://example.com).
  2. Click Check AI access.

How to read the result. You'll see whether robots.txt and llms.txt were found, an optional note on how much text renders without JavaScript, and a table of AI crawlers with each one's access — allowed, blocked, or other. Decide per crawler whether that matches what you want.

Good to know. Free to use. It only reads public files and the page's markup.

Try the AI-Access Checker →


22. Open Graph / Social Preview Checker

What it is. Enter a URL and this tool reads its Open Graph and Twitter Card tags — the metadata that decides how your link looks when shared on social media or chat — and renders the preview card so you can see the image, title, and description a share would show.

When you'd use it. Before or after publishing a page, you want to confirm its shared preview looks right and nothing is missing.

How to use it, step by step:

  1. Enter the URL (for example https://example.com).
  2. Click Check preview.

How to read the result. You'll see a rendered preview card (image with its dimensions, title, description, host), a list of any warnings, and a table of every tag found with its value. Fix any flagged gaps — a missing image or title is the usual culprit behind a bland-looking share.

Good to know. Free to use. It only fetches the page and reads its meta tags.

Try the Open Graph Checker →


23. Cognitive Load Analyzer

What it is. Enter a page URL and this AI-backed tool analyses the friction its design puts on a visitor — across dimensions drawn from cited research, like reading difficulty and the number of decisions a layout demands. It reports a composite friction band and per-dimension metric cards.

When you'd use it. A signup or landing page underperforms and you want a structured read of what's making it feel heavy.

How to use it, step by step:

  1. Enter the Page URL (for example https://example.com/signup).
  2. Click Analyze friction.

How to read the result. You'll see a composite friction band with a scope caveat, then per-dimension cards — each a name, a band, a value, and a short explanation (for example a reading-ease value, or a decision-count index). The bands are categorical reads, not a single validated score; use them to prioritize fixes.

Good to know (limits). The free tier shows the composite band and the headline finding; the remaining dimensions unlock on a plan. It's metered at 3 free analyses per month.

Try the Cognitive Load Analyzer →


24. Keyword Generator

What it is. Describe what you offer and this tool uses an AI model to turn it into structured keyword ideas — grouped into themes, each labeled by search intent and split into head terms, long-tail phrases, and questions. It's for ideation: it deliberately carries no volume, difficulty, or CPC data.

When you'd use it. You're starting content or SEO planning and want a fast, organized set of keyword angles to work from.

How to use it, step by step:

  1. Describe your product or page in Describe what you offer (for example, a subscription meal-kit service).
  2. Click Generate keyword ideas.

How to read the result. You'll get theme blocks, each with an intent badge and grouped lists of head terms, long-tail phrases, and questions. Use them as a starting map — take the ones that fit into a proper keyword tool for volume and difficulty.

Good to know (limits). It runs an AI model, so it's 1 free generation per day.

Try the Keyword Generator →


25. Salary Counter-Offer Script

What it is. Describe the offer you've received and what you're hoping for, and this tool uses an AI model to draft a salary counter-offer: a ready-to-adapt email, a set of talking points, and a graceful fallback line for if they say no. It's a starting draft to make your own, not negotiation advice.

When you'd use it. You've got an offer and want a professional first draft of your counter rather than staring at a blank page.

How to use it, step by step:

  1. In Your offer and what you want, describe the offer and your target (for example, offered $120k base, hoping for $135k).
  2. Click Draft my counter-offer.

How to read the result. You'll get an optional strategy line, an email script you can copy, a list of talking points, and a fallback line for a "no." Edit it to sound like you and to fit the real numbers before you send anything.

Good to know (limits). It runs an AI model, so it's 1 free draft per day.

Try the Counter-Offer Script →


26. Homepage Density Optimizer

What it is. How many items should a homepage feature before extra choice starts costing conversions? This tool answers it with a closed-form Lambert-W solution: give it two measurements of items-vs-conversion (or a decay rate λ you already know) and it computes the item count n* that maximizes traffic × conversion. The free page explains the maths; your personalised n* and curve need sign-in and one credit.

When you'd use it. You're deciding how many products, links, or cards to put on a homepage or landing page and want a principled number, not a guess.

How to use it, step by step:

  1. Choose how to supply λ — From two measurements (recommended), or enter a λ you already know.
  2. Fill in the number fields: for two measurements, the items and conversion at points A and B; optionally a dilution rate μ for SEO cannibalization.
  3. Click Find my optimal item count.

How to read the result. You'll get a sentence like "your optimal homepage item count is about n*," an optional diluted-model optimum if you set μ, and a utility-vs-item-count curve. n* is a count to aim near, not a hard rule — round to something practical.

Good to know. The maths explainer and example curve are free; the personalised result needs sign-in and one credit. It's pure maths — no AI.

Try the Homepage Density Optimizer →


Utilities

27. Redirect Chain Tracer

What it is. Enter a URL and this tool follows every redirect it makes — hop by hop — and shows the whole chain: each status code, the URL, its scheme, and how long the hop took. It flags the things that matter: protocol downgrades, redirect loops, over-long chains, and a meta-refresh on the final page.

When you'd use it. A shortened or tracking link is opaque and you want to see its real destination and route before you click it for real.

How to use it, step by step:

  1. Enter the URL (for example https://example.com).
  2. Click Trace redirects.

How to read the result. You'll get a table of hops — number, status code (or "blocked"), URL, scheme, and latency — plus warning flags. Watch for a downgrade from HTTPS to HTTP, a loop, or a long chain; the final URL is where the link actually lands.

Good to know. Free to use. Requests to internal or private addresses are blocked (SSRF protection), which can show up as a "blocked" hop.

Try the Redirect Chain Tracer →


Beyond the hosted tools

Not everything Pigfox publishes runs in your browser. repo-quarantine is a downloadable shell toolkit rather than a hosted tool: it runs an untrusted repository inside a disposable VirtualBox VM, so whatever the code does stays inside a sandbox you throw away afterwards. Reach for it when you want to inspect or actually run a repository you don't trust, without risking the machine you're sitting at.


A note on responsible use: these tools only surface information that is already public. Use what you find thoughtfully, respect people's privacy, and stay within the law and any applicable authorization.