06/02/2026
New Release: EPSS Lookup Tool v2.7
As a cybersecurity company, we decided to treat our free EPSS Lookup Tool the same way we'd treat a client environment - with a full security and code review.
The result is v2.7, a stronger, more reliable tool.
🔒 Security Improvements:
• Implemented a stricter Content Security Policy by moving JavaScript to external files, allowing us to remove unsafe-inline scripts and block inline-script injection attempts.
• Enforced HTTPS everywhere with HSTS and proxy-aware HTTP→HTTPS redirects.
• Added lock-protected rate limiting and optimized exploit intelligence lookups to reduce unnecessary upstream API requests and database growth.
• Strengthened output escaping for all third-party data rendered by the application.
🛠 Reliability Fixes:
• Fixed a "Copy Results" issue that could affect newly published CVEs without exploit intelligence data.
• Corrected a data pipeline issue affecting historical EPSS, LEV, and threat actor data updates, while adding automated backend cleanup.
• Updated the NIST LEV reference link to the correct source.
Security tools should be maintained with the same standards we'd apply to client engagements, whether they're free or not.
Fast EPSS, CVSS, KEV, LEV, and exploit intelligence lookups are still free with no signup, no API keys, and no usage limits.
Try it out: https://na2.hubs.ly/H05V4lp0
💻 Stay tuned for a 2.o walkthrough - coming soon!