Web Security Scanner
Context
The rest of the portfolio presents projects narratively (context, actions, results): nothing the visitor can actually try. That kind of hands-on experience is what creates the strongest impact in an interview.
What was done
Built a public tool that checks security headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options) and inspects a submitted domain's TLS certificate (protocol, validity, expiration), with a score out of 100 and a plain-language explanation for each point. Deliberately limited to the strict necessary: no port scanning, short timeouts, rate limiting (5 scans/minute/IP), and an SSRF guard blocking any target resolving to a private or local address.
Result
A public, working tool that visitors can test directly on the site — including on their own domain.