What KeptShut watches
Ten modules. Your plan decides how deep each one goes. Public checks are always allowed. Deep checks need proof you own the target.
Live exposure scan
A web-readable .env, .git, CLAUDE.md or backup. Directory listing. Debug mode left on. Admin routes reachable with no auth, checked as both the .php and the extensionless form. Anon keys in the front-end bundle. Missing CSP and HSTS. Dangling CNAMEs. Expired certificates on forgotten subdomains.
Repository scan
Runs on every push. Packages that do not exist in the registry. Secrets committed by accident. A .gitignore that misses CLAUDE.md or .cursorrules. Routes with no server-side authorisation. SQL built by concatenation. CSRF switched off. Lockfile integrity and malicious-package alerts.
Bill-shock guard
Spend velocity per key and per endpoint across your AI, SMS, cloud and payment providers. Alarms on send-to-verify ratio. Pre-authorised revoke of an abusive key. A finder for keys that are dead or scoped far too wide.
Panel watch
An outside-in fingerprint of your control panel, web server, PHP and database versions, matched hourly against the known-exploited list. Exposed ports. SSH password auth left on. Backup readiness, and a warning when your only copy of a signing key sits on one disk.
Domain posture
Transfer lock, registry lock, DNSSEC, CAA, expiry runway and auto-renew across every domain you own. An MFA checklist for the accounts that can take everything. Your recovery email checked against breach dumps. DMARC enforcement path and lookalike-domain watch.
Rattle test
Two accounts, and we try to reach one from the other. Price and coupon tampering on checkouts. Card-testing gate checks. A red-team pass on your own chatbot. Verified-owned targets only.
Clone and impersonation
Certificate-transparency logs and typo permutations for your brand. A perceptual hash of your real login page against new lookalikes. Android stores swept for a clone with your package name and a different signing certificate.
AI and MCP
A public scanner and trust registry for MCP servers, covering tool-description poisoning, over-broad scopes, OAuth conformance and rug-pull manifest diffs. Plus your AI-crawler policy and LLM-output rendering.
Compliance-lite
Payment-page script inventory with tamper diff and SAQ-A evidence. A trust page and questionnaire autofill. A data inventory that maps where personal data actually lives. A breach rehearsal and an "I have been hacked" runbook.
Secure-build kit
Free. Security rule packs for CLAUDE.md and .cursorrules, OpenLiteSpeed deny blocks with a canary test, row-level-security and CSP starters, and pre-submission checks for Android.