Skip to content
A giant neon-green swamp tardigrade blasting a glowing beam at extortionist bugs labeled SEO Spam, Malware, Data Theft, DDoS Threat and 'Pay Up Or Else'.

Scan your app for the low-level muck. Free.

https://

Free scan, no signup. See every problem — and every fix — in ~20s. No card, no paywall. Only scan a domain you own.

165
domains scanned
38
high-severity found
25
critical found
20%
of domains cut issues by 50%+
40%
of domains are now clean

The tardigrade doesn't die.

It survives radiation, boiling, freezing, and the vacuum of space. It's also deeply stupid. Boring, indestructible, impossible to shake down. Be the tardigrade.

Meet the swamp's bad actors →
80%

of "bounty" reports to small apps are low-level config, not real vulns

30s

is all it takes a script kiddie to run a scanner and draft a ransom email

$0

what the fixes cost you — vs. the $500+ these emails demand

What the scan looks at

Every check maps to something a lowlife would screenshot and demand money for. You see all of it free.

Email spoofing

SPF · DKIM · DMARC

The #1 shakedown. No DMARC means anyone can send phishing that looks like it's from you. We check all three records.

Exposed files & secrets

.env · .git · keys

A public .env or downloadable .git folder is the classic "pay me or I leak it" email. We probe for the files that get vibe-coded apps ransomed.

Security headers

HSTS · CSP · more

Missing HSTS, no Content-Security-Policy, clickjacking-friendly headers — free findings for anyone running a scanner against you.

TLS & HTTPS

certs · redirects

Expired certs, http:// that doesn't upgrade, weak TLS versions. Ugly browser warnings and easy bounty-report fodder.

Cookies

Secure · HttpOnly

Session cookies missing Secure/HttpOnly/SameSite flags are stealable. We flag every cookie that's dressed wrong.

DNS hardening

DNSSEC · CAA

DNSSEC off and no CAA record round out the checklist a "researcher" will pad their extortion email with.

How it works

1

Scan free

Drop your domain. A passive, external scan — no access, no agent, nothing installed — reads your DNS, TLS, headers, and exposed files in about 20 seconds. No signup, no card.

2

Fix it — free

Every issue in plain English with the exact fix, worst-first — plus one copy-paste prompt you hand straight to your AI (Cursor, Claude, v0) to fix it all at once.

3

Monitor it

Verify your domain and the tardigrade keeps watch — re-scanning on a schedule and emailing you the moment a hole reopens, so today's fixes stay fixed.

New: keep it closed

One scan fixes today. Monitoring keeps it fixed.

A header you drop, a cert that expires, a DNS record that gets overwritten — holes reopen. Have the tardigrade re-scan on a schedule and tell you the moment one does. Free monthly, or pennies a day for live alerts.

See monitoring plans →
Why we built this

Someone tried to extort us over a DNS record.

Yesterday evening we got a friendly-looking email. Someone had “found a security issue” on one of our sites and asked, politely, whether we ran a bug bounty. We don't. We said thanks and that we'd take a look.

Within the hour it turned. “Pay me, or I disclose this publicly and start emailing your users.” A harmless favor became a shakedown, fast.

The “critical vulnerability”? A missing DMARC record. One line of DNS. Five minutes and zero dollarsto fix — if you even know it's there. We didn't. So we lost an evening to a TXT record.

That's stupid, and it happens to people shipping fast every day. Nobody should get extorted over config they never knew was missing. So we built buckingfugs to find the low-level stuff a shakedown artist finds — before they do.

Want the full picture? We broke down how the fake bug bounty shakedown works, and there's more on who we are and why we built this.

— the buckingfugs crew · still a little annoyed

Straight answers

So it's actually free? What's the catch?

No catch. Every finding and every fix is free — what's wrong, the proof, the exact how-to-fix, and a copy-paste prompt for your coding AI. Nobody should get shaken down over config they never knew was missing, so we don't gate it. If it saved you a headache, there's an optional tip jar (Protect the Swamp). That's it.

What do I actually get?

For each problem: the precise fix (the DNS record to add, the header to set, the file to lock down) plus one master prompt you paste into Cursor / Claude Code / v0 / ChatGPT that tells it to fix everything, tailored to your stack. All free.

Is this real hacking / a pentest?

No. Passive, non-intrusive checks only — reading your DNS records and public HTTP responses. Nothing gets attacked or broken. It's the low-level hygiene layer, not a red team.

Can I scan any website?

Only domains you own or control. It's your app's hygiene we're checking — not someone else's.

Will this make me un-hackable?

Nope, and anyone who says that is lying. This covers the low-level BS — the ~80% of "findings" that are just missing config. It makes you a boring target instead of a profitable one.

Want more? Read the field notes on the blog, meet the bad actors we scan for, or talk to the crew.