Enternovate Open · Mhangani
An ethical web security audit toolkit. It runs OWASP-aligned header, TLS, cookie and CORS checks with a 0-100 posture score and board-ready reports. Passive checks only. Always authorized and scoped.

Test your defenses the way an attacker would. Never cross the line. Mhangani runs passive, OWASP-aligned checks. It turns them into a score you can act on and reports you can show.
Mhangani audits security headers against OWASP guidance. It checks CSP, HSTS, X-Frame-Options and Referrer-Policy. Each check gives a clear pass or fail and remediation.
It parses certificates and checks TLS posture. This covers protocol support, cipher strength, expiry and trust chain. Mhangani scores each against current best practice.
It audits Set-Cookie attributes (Secure, HttpOnly, SameSite) and CORS policy. These checks find the subtle misconfigurations attackers use.
Every check feeds a graded posture score with per-finding detail. You see exactly what lowers your score and what fixes it.
Render the same audit as HTML, JSON or Markdown. Share it with a client, a board or your own ticketing.
Mhangani runs passive checks only. Every audit is authorized and scoped. It audits what you own or have permission to test. Nothing more.
$ mhangani audit https://example.com
$ mhangani report --format html --out report.html
$ mhangani report --format json --out findings.json
$ mhangani grade --url https://example.com
Run the audit. Let Xavani triage the findings. One request such as 'audit this site and fix the headers' starts the work.
Mhangani stores findings in the Nyarhi knowledge graph. Gavaza covers the compliance side.
The free local toolkit also comes as PromptShield and the platform's audit features. They are hosted, scheduled and multi-tenant.