Free tools
Hack Check
Type an address. We check it against the Tarsier Threat Index, open the page in isolation, follow the redirects, and read every script. Then we show our work.
How to use it
- Open Hack Check under Tools and enter any public http or https address. Private and internal addresses are refused.
- Press Scan my website and stay on the page while the isolated browser does its visit.
- Read the verdict, then the checklist, then the numbered findings. Every finding quotes its evidence.
How the verdict works
The report ends in one of three states. A Tarsier Threat Index hit or a known-bad host means flagged. A hidden link, a packed script, a hop to another site, a script from a host Pica does not trust, or a script that only the crawler or only the browser received means worth a closer look. Ordinary unidentified scripts are listed, and they do not change the verdict by themselves. Anything else is reported as no known malware indicators, which is exactly what a remote look can say and all it can say.
What it checks
- Host and script reputation against the Tarsier Threat Index, Tarsier's own distilled list. A miss is not a clean bill of health.
- A crawler fetch, then a browser visit, compared for cloaking and unusual scripts.
- Outside scripts, classified as analytics, advertising, CDN, payments, video, chat, or unknown.
- Hidden frames, packed inline scripts, hidden off-site links, a base tag that rewrites links, off-site forms, and downloads.
- How the browser is armed: content policy, HSTS, sniffing, frames, referrer, permissions, cookies, server version, cross-origin reads, mixed content, and SPF with DMARC when the domain accepts mail.
A remote scan cannot prove a server is clean. Server-side infections, backdoors, and filesystem malware need access this tool deliberately does not take.
Limits
Five free scans a day per visitor. Tarsier customers get the same look every day on all 50 sites, with change detection against yesterday.