KeptShut

What KeptShut watches

Ten modules. Your plan decides how deep each one goes. Public checks are always allowed. Deep checks need proof you own the target.

M1

Live exposure scan

A web-readable .env, .git, CLAUDE.md or backup. Directory listing. Debug mode left on. Admin routes reachable with no auth, checked as both the .php and the extensionless form. Anon keys in the front-end bundle. Missing CSP and HSTS. Dangling CNAMEs. Expired certificates on forgotten subdomains.

M2

Repository scan

Runs on every push. Packages that do not exist in the registry. Secrets committed by accident. A .gitignore that misses CLAUDE.md or .cursorrules. Routes with no server-side authorisation. SQL built by concatenation. CSRF switched off. Lockfile integrity and malicious-package alerts.

M3

Bill-shock guard

Spend velocity per key and per endpoint across your AI, SMS, cloud and payment providers. Alarms on send-to-verify ratio. Pre-authorised revoke of an abusive key. A finder for keys that are dead or scoped far too wide.

M4

Panel watch

An outside-in fingerprint of your control panel, web server, PHP and database versions, matched hourly against the known-exploited list. Exposed ports. SSH password auth left on. Backup readiness, and a warning when your only copy of a signing key sits on one disk.

M5

Domain posture

Transfer lock, registry lock, DNSSEC, CAA, expiry runway and auto-renew across every domain you own. An MFA checklist for the accounts that can take everything. Your recovery email checked against breach dumps. DMARC enforcement path and lookalike-domain watch.

M6

Rattle test

Two accounts, and we try to reach one from the other. Price and coupon tampering on checkouts. Card-testing gate checks. A red-team pass on your own chatbot. Verified-owned targets only.

M7

Clone and impersonation

Certificate-transparency logs and typo permutations for your brand. A perceptual hash of your real login page against new lookalikes. Android stores swept for a clone with your package name and a different signing certificate.

M8

AI and MCP

A public scanner and trust registry for MCP servers, covering tool-description poisoning, over-broad scopes, OAuth conformance and rug-pull manifest diffs. Plus your AI-crawler policy and LLM-output rendering.

M9

Compliance-lite

Payment-page script inventory with tamper diff and SAQ-A evidence. A trust page and questionnaire autofill. A data inventory that maps where personal data actually lives. A breach rehearsal and an "I have been hacked" runbook.

M10

Secure-build kit

Free. Security rule packs for CLAUDE.md and .cursorrules, OpenLiteSpeed deny blocks with a canary test, row-level-security and CSP starters, and pre-submission checks for Android.

See what each plan includes