Kodura SSL Analyzer
21 Sept 2026launched 10 days ago
0.00 ratings
n/aApple doesn’t publish installs
WorldwideSold in 50+ App Store storefronts
1.0latest version · 10 days ago
Screenshots
About
A TLS checker that tells you what is wrong, not just what is there. Point it at any host and port. It performs a real TLS handshake, reads the certificate chain the server actually sent, and turns it into plain language: what the problem is, why it matters, and what to change. SEES WHAT YOUR BROWSER HIDES Browsers and most phone tools quietly download any certificate a server forgot to include, so a misconfigured server looks perfectly healthy. This turns that repair off. If your server is missing an intermediate, you will see it here and nowhere else — which is why a site can work in Safari while your API client, your mobile SDK, or anything behind a strict firewall fails against it. ANSWERS IN THREE LAYERS A letter grade and one sentence you can read in a second. Then a finding for each problem — what was detected, the practical consequence, and the fix. Then every field of every certificate, for when you want to check the working yourself. WHAT IT CHECKS • Trust chain — complete, incomplete, or untrusted, and exactly where it breaks • Expiration — how long you have, and when to start worrying • Hostname — whether the certificate really covers the name you connected to • Certificate — signature algorithm, key size, validity dates • Protocols — which TLS versions are enabled, including ones that should not be • Cipher — forward secrecy and whether the negotiated suite is still sound THE CHAIN, DRAWN Every certificate the server presented, in order, leaf to root. Where a certificate is missing, the gap is drawn and labelled rather than quietly skipped. Tap any certificate for its full detail: subject, issuer, serial, both fingerprints, key, and every name it covers. BUILT FOR THE AWKWARD CASES Any port, not just 443. Self-signed certificates identified as such rather than dismissed. Deprecated TLS 1.0 and 1.1 reported against RFC 8996. Protocol probes that say "no answer" instead of claiming a version is disabled when the network simply swallowed the handshake. SHARE THE ANSWER Every scan exports as plain text — grade, chain, findings, impact and fix. Paste it into a ticket or send it to whoever owns the server. HISTORY Every endpoint you scan is kept, with its grade, so you can come back and see what you found. Rescan any of them in one tap. LIGHT AND DARK Both designed, not one inverted into the other. Fingerprints, serials and addresses are set in monospace so they stay readable at a glance and selectable when you need to paste one. NO ACCOUNT, NO BACKEND, NO ADS Scans run directly from your device to the host you type. Nothing is sent to Kodura. History never leaves the phone. There is no sign-up, no tracking prompt, and nothing to buy. Built by Kodura for network engineers, sysadmins and anyone who has lost an afternoon to a certificate that worked in a browser.Read more
A TLS checker that tells you what is wrong, not just what is there.
Point it at any host and port. It performs a real TLS handshake, reads the
certificate chain the server actually sent, and turns it into plain language:
what the problem is, why it matters, and what to change.
SEES WHAT YOUR BROWSER HIDES
Browsers and most phone tools quietly download any certificate a server forgot
to include, so a misconfigured server looks perfectly healthy. This turns that
repair off. If your server is missing an intermediate, you will see it here and
nowhere else — which is why a site can work in Safari while your API client,
your mobile SDK, or anything behind a strict firewall fails against it.
ANSWERS IN THREE LAYERS
A letter grade and one sentence you can read in a second. Then a finding for
each problem — what was detected, the practical consequence, and the fix. Then
every field of every certificate, for when you want to check the working
yourself.
WHAT IT CHECKS
• Trust chain — complete, incomplete, or untrusted, and exactly where it breaks
• Expiration — how long you have, and when to start worrying
• Hostname — whether the certificate really covers the name you connected to
• Certificate — signature algorithm, key size, validity dates
• Protocols — which TLS versions are enabled, including ones that should not be
• Cipher — forward secrecy and whether the negotiated suite is still sound
THE CHAIN, DRAWN
Every certificate the server presented, in order, leaf to root. Where a
certificate is missing, the gap is drawn and labelled rather than quietly
skipped. Tap any certificate for its full detail: subject, issuer, serial,
both fingerprints, key, and every name it covers.
BUILT FOR THE AWKWARD CASES
Any port, not just 443. Self-signed certificates identified as such rather than
dismissed. Deprecated TLS 1.0 and 1.1 reported against RFC 8996. Protocol
probes that say "no answer" instead of claiming a version is disabled when the
network simply swallowed the handshake.
SHARE THE ANSWER
Every scan exports as plain text — grade, chain, findings, impact and fix.
Paste it into a ticket or send it to whoever owns the server.
HISTORY
Every endpoint you scan is kept, with its grade, so you can come back and see
what you found. Rescan any of them in one tap.
LIGHT AND DARK
Both designed, not one inverted into the other. Fingerprints, serials and
addresses are set in monospace so they stay readable at a glance and
selectable when you need to paste one.
NO ACCOUNT, NO BACKEND, NO ADS
Scans run directly from your device to the host you type. Nothing is sent to
Kodura. History never leaves the phone. There is no sign-up, no tracking
prompt, and nothing to buy.
Built by Kodura for network engineers, sysadmins and anyone who has lost an
afternoon to a certificate that worked in a browser.
Versions
- Version 1.0First seen · 21 Sept 2026
Countries
Worldwide
Apple lists this app in 50 or more storefronts, so it is available almost everywhere.
Turkey
Chart positions
Not seen in the charts we track yet.