We built decloak.dev as the web intelligence service for the modern era. Start for free with features for vibe coders all the way through to Enterprise!
We've just launched Decloak on @peerpush_com!
Click the link below and help us reach more people!
We're on a mission ot help everyone get better at improving their web security! Whether you're a vibe coder or a professional pentester!
🚀 peerpush.com/p/decloak
Decloak by @decloakdev
Exposed API keys. Misconfigured DBs. Vulnerable libraries. Catch them all🔥
AI agent runs full site investigation + penetration testing.
Available - decloak.dev/?ref=microlaunch
Paste your URL + your scored security report (15 secs)
3/ Trezor's vendor breach kept getting worse. First, 67K more customers exposed because the vendor kept data it was required to delete. Then attackers used the breach itself to send fake "security alert" phishing emails to 347K addresses, weaponizing the trust a real breach notification depends on.
4/ And KDDI, a major Japanese telecom, exposed 14.2M accounts through a vulnerability in third-party software inside one shared email platform. One flaw, six ISPs' worth of customers. Full roundup: decloak.dev/journal/uncloake…
1/ A green padlock tells a visitor almost nothing about whether the connection behind it is actually well configured. Four separate things can each quietly go wrong while it stays green.
2/ Expiry's the one everyone knows. Chain validation is invisible until it breaks for the wrong client. Protocol version, still accepting TLS 1.0/1.1? And cipher strength, the one almost nobody checks manually, because there's no browser warning for it.
3/ A cert can be freshly issued, correctly chained, and still served over a deprecated protocol with a weak cipher. Still shows the padlock. Still fails a real review. We check all four automatically. Full breakdown: decloak.dev/journal/your-ssl…
Decloak has just launched on @MicroLaunchHQ! Thanks for your help @SaidAitmbarek
We'd appreciate any upvotes to help with our listing😄
We've launched an exclusive promotion for 50% off for two months no ANY paid plan, which you can find on our page!
microlaunch.net/p/decloakweb…
3/ Most scanners either silently skip what they can't test or quietly overclaim coverage. We'd rather say exactly why something's out of scope. That's a trust signal, not a weakness.
4/ Also found our own reference table was still citing the outdated 2021 standard while building this. Rebuilt the whole mapping on 2025. Free on every plan: decloak.dev/journal/every-re…
1/ Most scanners stop at the login page. Decloak's authenticated scan mode doesn't, and for passkeys specifically, the usual workaround (script the login) doesn't even apply.
2/ WebAuthn is built so there's no credential to store or script. The login ceremony requires a physical gesture on the actual device. Nothing to paste into an automation script, by design.
3/ So we capture a session instead. Log in normally, a browser extension captures the resulting session, the agent crawls behind it, dashboards, account pages, everything a scan would otherwise never see. Full writeup: decloak.dev/journal/how-decl…
Decloak now reports on what findings map to the OWASP Top 10 categories. This brings our security intelligence platform feature count to 66! And we keep going!
Onto the next build...