Curated Directory

The dev & security stack we actually use

Forty hand-picked tools — network, DNS, security headers, SEO, password managers, design, AI, privacy. Every entry is something we use daily. No affiliate links, no paid placements, no AI wrapper fluff. Plain rel="nofollow" links to the official site.

01 · Network & DNS (6)

🌐
DNS, CDN, DDoS protection, Workers (serverless edge), Pages (JAMstack hosting), Email routing. sitetrace.it.com is hosted on Pages; the API runs on Workers.
// sitetrace's actual infra. Free tier covers everything we need.
🔍
Public DNS-over-HTTPS (DoH) and DNS-over-TLS resolvers. Used inside the browser for client-side DNS lookups — no app server needed.
// sitetrace's /dns-tools uses 1.1.1.1 over DoH for privacy.
📡
BGP routing inspection, ASN lookups, prefix advertisements. The single best answer to "where is this IP actually routed from".
// pair with sitetrace's /ip-lookup for the full picture.
🛰
mtr (My Traceroute)
Combines traceroute + ping into a single live diagnostic. Shows packet loss + jitter per hop. The right tool when a network is being weird.
// terminal-only. pair with sitetrace's /ping/ for browser-only check.
📑
Certificate Transparency log search. Every certificate ever issued for any domain, with the issuing CA, validity dates, and SAN list. The data layer behind sitetrace's /cert-checker.
// open, free, no API key. slow UI → sitetrace wraps with 24h cache.
📜
The authoritative source for every Internet protocol. RFC 7231 (HTTP semantics), RFC 6962 (CT), RFC 8446 (TLS 1.3) — when in doubt, the RFC is right.
// dry reading. better than any blog post on protocol mechanics.

02 · Security & Headers (6)

🛡
Tim Sneath's classic A-F grader for HTTP security headers. The historical reference. sitetrace's /headers-checker is a faster, no-queue alternative.
// use both. securityheaders.com for the historical baseline.
🔒
Live TLS configuration grading. Cipher suites, protocol versions, chain order, session resumption, vulnerabilities. The single best answer to "is my HTTPS correctly configured".
// pair with /cert-checker (history) for full TLS picture.
🐛
Open Web Application Security Project. The OWASP Top 10, the Secure Headers Project, the ASVS standard. The canonical references for "what is web app security".
// if you've never read OWASP Top 10, start there.
👁
Troy Hunt's breach corpus. The API lets you check a password or email against 8+ billion compromised records without sending the password in cleartext (k-anonymity).
// sitetrace-api blocks disposable domains + could integrate HIBP later.
🤖
Free CAPTCHA alternative. No puzzles, no images, no "I am not a robot" — passive browser-fingerprint challenges. sitetrace-api's /api/signup is scaffolded to use it.
// no user friction, free up to 1M validations/mo.
🪪
Mozilla's reference for browser security: CSP, CORS, Same-Origin Policy, Subresource Integrity, Permissions Policy. The right place to look up exactly what each header does.
// if MDN doesn't have it, the browser doesn't support it.

03 · SEO & Websites (6)

📊
Free, official. The only source of truth for what Google sees on your site. Index coverage, manual actions, Core Web Vitals, search performance.
// sitetrace's organic traffic source of truth. Ed owns the dashboard.
📈
Microsoft's equivalent of GSC. Less traffic than Google but Bing + DuckDuckGo + Yahoo all use it. Submit sitemaps, see crawl errors.
// free, no downside. ~10% of search traffic is here.
⚡
Google's Core Web Vitals checker. LCP, FID, CLS, plus suggestions. The right baseline for "is my page fast".
// sitetrace pages target 95+ PSI mobile / 100 desktop.
🗺
Open Graph preview debugger. sitetrace's /og-preview is a similar but free / no-signup alternative with Slack/LinkedIn/Discord panels side-by-side.
// use both. opengraph.xyz for Twitter/Facebook specifically.
📡
The official way to force Facebook to re-scrape your og:image. Required after every og:image change.
// cache-bust og:image URLs with ?v=N for instant fixes.
🧭
Free sitemap.xml generator. sitetrace's sitemap is hand-maintained (40 pages, all listed) but this is the right move for sites in the 200+ URL range.
// small → hand-written. large → generate.

04 · Developer & API (7)

⌨️
Default editor for everything. The extension ecosystem is the only reason it's not just a text editor — sitetrace uses GitHub Copilot + Prettier + ESLint.
// Ed's primary editor. Free, runs on every platform.
🐙
Source hosting. sitetrace.cloud + sitetrace-tracker both live here. The Pages + Cloudflare pairing auto-deploys on every push to main.
// sitetrace's source of truth. CF Pages watches main.
🚀
Serverless edge functions. sitetrace-api runs entirely on Workers — KV for cache, D1 for accounts, R2 for screenshots. Free up to 100k req/day.
// sitetrace-api's runtime. $0/month with free tier.
📬
API testing. Hoppscotch is the open-source alternative (browser-based, free). sitetrace-api's /api/openapi generates a Postman collection.
// hoppscotch for browser. postman for offline.
🟢
JavaScript runtime. sitetrace's build scripts + Workers runtime + frontend tooling all run Node. LTS version only.
// sitetrace scripts are .mjs, run with Node 20 LTS.
🐚
Default shell for sitetrace's agents. Autosuggestions on by default; no plugin config needed. Ed uses PowerShell on Windows.
// mac/linux: fish. windows: powershell 7.
🧪
Browser automation for end-to-end tests. sitetrace's e2e-launch-test.mjs uses puppeteer-core; Playwright is the modern alternative with cross-browser support out of the box.
// Playwright > Puppeteer for new projects.

05 · AI & Productivity (7)

🧠
The model powering this build. Ed runs MiniMax Code (mavis) as the development agent — code review, build, push, deploy, all from a terminal.
// agent of record for sitetrace. Not endorsing — describing.
✍️
Direct chat for long-form reasoning. Use them as a "second pair of eyes" — paste a code snippet or essay and ask "what am I missing".
// pair with sitetrace's /api/ai-content-detector to check your own drafts.
🔍
Search with cited sources. Best of both: a real-time web search plus an LLM that summarizes and links. Replaces 30% of Ed's "let me Google this and read 5 tabs".
// default for "what is X" + "compare X vs Y" queries.
📓
Local-first markdown notes. Plain text files on disk, no vendor lock-in, works offline. Ed's tracker-roadmap.csv + ROADMAP.md live in a sibling repo, mirrored as Obsidian vault.
// local-first. plain text. no SaaS.
📝
Markdown editors. Typora for distraction-free writing, VS Code for code-heavy docs. Both produce clean, readable markdown with no proprietary lock-in.
// .md always. never .docx. never Notion blocks.
🖼
Image generation. Use for blog headers, social images, mockups. Ed uses it via mcode-tools, not direct API. Generation cost is real (don't over-iterate).
// sitetrace OG cards are generated, not photographed.
🎙
Open-source speech-to-text from OpenAI. Run locally on your own machine. Free, accurate, no quota. The right tool for transcribing meetings or audio without sending audio to a cloud service.
// local-only. no audio leaves your laptop.

06 · Password & Auth (4)

🔑
Open-source password manager. Free for personal use, $10/year for premium. Ed's recommendation for everyone; sitetrace's own staff uses it.
// self-hostable. FOSS. cross-platform.
🔐
Offline password database, single file, no cloud. The right choice if you don't trust any cloud-based password manager with your vault.
// offline-only. the most privacy-preserving.
📱
Hardware 2FA token. USB-A, USB-C, NFC, and Lightning variants. The right defense against phishing — even if your password leaks, the attacker can't use it without the physical key.
// $25-50 each. buy two. store one offsite.
🆔
TOTP authenticator apps. The free fallback to hardware keys. Authy for cloud-synced TOTP, MS Authenticator if you're in the Microsoft ecosystem.
// TOTP > SMS. hardware keys > TOTP.

07 · Design & Color (5)

🎨
Browser-based design tool. Free for personal use, $15/user/mo for teams. The right choice over Sketch (Mac-only) or Adobe XD (subscription-bundled).
// browser-based. cross-platform. free tier is generous.
🌈
Utility-first CSS framework. sitetrace uses the CDN build (`cdn.tailwindcss.com`) — no build step, no Node config, just a `