
Scan your app for the low-level muck. Free.
The tardigrade doesn't die.
It survives radiation, boiling, freezing, and the vacuum of space. It's also deeply stupid. Boring, indestructible, impossible to shake down. Be the tardigrade.
Meet the swamp's bad actors →of "bounty" reports to small apps are low-level config, not real vulns
is all it takes a script kiddie to run a scanner and draft a ransom email
what the fixes cost you — vs. the $500+ these emails demand
What the scan looks at
Every check maps to something a lowlife would screenshot and demand money for. You see all of it free.
Email spoofing
The #1 shakedown. No DMARC means anyone can send phishing that looks like it's from you. We check all three records.
Exposed files & secrets
A public .env or downloadable .git folder is the classic "pay me or I leak it" email. We probe for the files that get vibe-coded apps ransomed.
Security headers
Missing HSTS, no Content-Security-Policy, clickjacking-friendly headers — free findings for anyone running a scanner against you.
TLS & HTTPS
Expired certs, http:// that doesn't upgrade, weak TLS versions. Ugly browser warnings and easy bounty-report fodder.
Cookies
Session cookies missing Secure/HttpOnly/SameSite flags are stealable. We flag every cookie that's dressed wrong.
DNS hardening
DNSSEC off and no CAA record round out the checklist a "researcher" will pad their extortion email with.
How it works
Scan free
Drop your domain. A passive, external scan — no access, no agent, nothing installed — reads your DNS, TLS, headers, and exposed files in about 20 seconds. No signup, no card.
Fix it — free
Every issue in plain English with the exact fix, worst-first — plus one copy-paste prompt you hand straight to your AI (Cursor, Claude, v0) to fix it all at once.
Monitor it
Verify your domain and the tardigrade keeps watch — re-scanning on a schedule and emailing you the moment a hole reopens, so today's fixes stay fixed.
One scan fixes today. Monitoring keeps it fixed.
A header you drop, a cert that expires, a DNS record that gets overwritten — holes reopen. Have the tardigrade re-scan on a schedule and tell you the moment one does. Free monthly, or pennies a day for live alerts.
Someone tried to extort us over a DNS record.
Yesterday evening we got a friendly-looking email. Someone had “found a security issue” on one of our sites and asked, politely, whether we ran a bug bounty. We don't. We said thanks and that we'd take a look.
Within the hour it turned. “Pay me, or I disclose this publicly and start emailing your users.” A harmless favor became a shakedown, fast.
The “critical vulnerability”? A missing DMARC record. One line of DNS. Five minutes and zero dollarsto fix — if you even know it's there. We didn't. So we lost an evening to a TXT record.
That's stupid, and it happens to people shipping fast every day. Nobody should get extorted over config they never knew was missing. So we built buckingfugs to find the low-level stuff a shakedown artist finds — before they do.
Want the full picture? We broke down how the fake bug bounty shakedown works, and there's more on who we are and why we built this.
Straight answers
So it's actually free? What's the catch?
No catch. Every finding and every fix is free — what's wrong, the proof, the exact how-to-fix, and a copy-paste prompt for your coding AI. Nobody should get shaken down over config they never knew was missing, so we don't gate it. If it saved you a headache, there's an optional tip jar (Protect the Swamp). That's it.
What do I actually get?
For each problem: the precise fix (the DNS record to add, the header to set, the file to lock down) plus one master prompt you paste into Cursor / Claude Code / v0 / ChatGPT that tells it to fix everything, tailored to your stack. All free.
Is this real hacking / a pentest?
No. Passive, non-intrusive checks only — reading your DNS records and public HTTP responses. Nothing gets attacked or broken. It's the low-level hygiene layer, not a red team.
Can I scan any website?
Only domains you own or control. It's your app's hygiene we're checking — not someone else's.
Will this make me un-hackable?
Nope, and anyone who says that is lying. This covers the low-level BS — the ~80% of "findings" that are just missing config. It makes you a boring target instead of a profitable one.
Want more? Read the field notes on the blog, meet the bad actors we scan for, or talk to the crew.