Free tools Windows power users keep installed
One-click scans. No signup required.
Use a screenshot API as an untrusted server-side fetch service. Authenticate the caller before starting browser work, accept only validated destinations, block private and metadata networks after every DNS resolution and redirect, isolate the renderer, enforce strict resource limits, and keep captured files and logs private for as short a time as practical. An API key by itself does not make arbitrary URL fetching safe.
The central risk is server-side request forgery (SSRF): a client supplies a URL and your service fetches it from your network. A successful attack can probe internal services, expose credentials or metadata, bypass network controls, or turn your renderer into an open proxy. The controls below apply whether you build the service yourself or use a hosted provider.
1. Define a safe request boundary
Decide first whether arbitrary destinations are actually required. The safest design is an endpoint that accepts a site identifier or a path from a finite list, then constructs the outbound URL from server-controlled components. If users must provide URLs, treat every character as hostile input.
Authenticate and authorize before browser work
- Terminate TLS at the edge and authenticate with
Authorization: Bearer …orX-API-Key: …before queuing a job. - Use tenant-level authorization: a valid caller should still be limited to the destinations and features its account is allowed to use.
- Support key rotation and immediate revocation. Keep secrets in a secret manager, not source control, configuration files, shell history, or client-side code.
- For APIs that support it, send credentials in headers or a request body, never in a URL. URLs commonly appear in reverse-proxy, browser, analytics, and application logs.
Do not forward the caller’s authentication headers, cookies, or arbitrary headers to the target site. Accept only explicitly named values and apply a separate policy to each one.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Accept only the schemes and ports you need
Use a maintained URL parser rather than string operations. In most products, allow https only and permit port 443 (or an explicitly documented alternate). Reject malformed URLs, embedded usernames or passwords, fragments when they have no business purpose, nonstandard IP encodings, and parser disagreements. Normalize the hostname to a canonical form before policy evaluation.
Prefer an origin allowlist
An allowlist of exact origins such as https://docs.example.com is stronger than a suffix check such as “ends with example.com.” If subdomains are required, define them precisely and test look-alike names, internationalized domains, and trailing-dot forms. Apply path rules after origin validation; never let a path rule substitute for an origin check.
2. Stop SSRF through DNS, IP, and redirects
Hostname validation alone is insufficient because DNS can resolve a permitted name to an unsafe address. Resolve the hostname at request time, classify every returned address, and reject destinations in these categories:
- Loopback addresses.
- RFC1918 and other private-network ranges.
- Link-local addresses.
- Multicast and other non-routable ranges.
- Cloud instance-metadata endpoints and equivalent provider-reserved ranges.
Perform the check for every address returned by DNS, using a well-tested IP library that understands IPv4, IPv6, mapped addresses, and unusual textual representations. Re-check immediately before connecting when your platform permits it, because DNS answers can change between validation and connection.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsRank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
Disable redirects or validate each hop
The initial URL may be public while a redirect points to an internal service. Disable redirects unless the product needs them. If redirects are enabled, resolve and apply the same scheme, origin, port, IP, and path policy to every hop, enforce a small maximum hop count, and reject a redirect that changes policy class. Do not rely on a browser’s default redirect behavior.
Use network egress controls as a second line of defense
Run the renderer in a separate worker or sandbox with no route to control planes, databases, queues, credentials endpoints, or administrative interfaces. Apply firewall or cloud egress rules that allow only the destinations your business needs. Network policy does not replace application validation, but it limits damage when a parser, browser, or dependency is bypassed.
3. Isolate and constrain the renderer
A browser is a large, frequently patched attack surface. Give the worker a dedicated identity with the minimum filesystem, network, and cloud permissions. Keep browser and operating-system patches current, disable unnecessary capabilities, and destroy the worker or browser context after a job when practical.
Bound every expensive option
Define limits in configuration and enforce them server-side rather than trusting client parameters.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
- Maximum viewport width, height, device scale, and full-page height.
- Maximum PDF paper size, page count, and output bytes.
- Navigation timeout and an overall job deadline.
- Maximum JavaScript execution or post-load wait time.
- Maximum response size and number of resources.
- Concurrency per tenant and globally.
- Retry count, backoff, and batch size.
Full-page captures, PDF generation, JavaScript-heavy pages, large viewports, long waits, and retries consume substantially more CPU, memory, bandwidth, and time than a fixed viewport. Meter them separately and charge them against the same tenant quota. Return HTTP 429 when a rate or quota limit is exceeded, and include a retry hint when you can calculate one.
Review feature flags as security controls
Features such as custom headers, cookies, user agents, JavaScript, custom CSS, click actions, selector waits, geolocation, timezone changes, request blocking, and arbitrary scripts expand the attack and data-exposure surface. Enable only what a use case needs. For example, prohibit caller-supplied Authorization headers, restrict cookies to an allowlisted domain, and require an elevated policy for JavaScript or PDF jobs.
4. Protect captured images, PDFs, and upstream data
Store privately and briefly
Output can contain passwords, personal data, internal dashboards, tokens rendered into a page, or information revealed by a logged-in session. Store files under an unguessable identifier in private object storage, encrypt them in transit and at rest, and expose them through an authorization check or a short-lived signed URL. Provide an explicit deletion operation and an automatic retention deadline. Review whether a provider retains or caches outputs and in which geography before sending private pages.
Do not turn the service into a proxy
Return the rendered artifact and a controlled status object, not arbitrary upstream HTTP responses, response headers, cookies, or browser stack traces. Strip internal network details from errors. A caller should learn that a policy check failed or a page timed out, not which private host answered.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Log for investigation without collecting secrets
Record a request ID, tenant, policy decision, duration, byte count, renderer outcome, and destination category. Redact API keys, cookies, authorization values, signed URLs, and sensitive query parameters. Avoid logging full target URLs when their paths or parameters may contain secrets; log a normalized origin or a salted identifier instead. Alert on blocked internal destinations, repeated policy failures, sudden quota spikes, unusual geographies, and repeated timeout or byte-limit failures.
5. A secure request flow
- Receive over TLS. Authenticate and authorize the caller before accepting expensive work.
- Parse and normalize. Use a maintained parser; allow only required schemes and ports; reject credentials, malformed hosts, and nonstandard IP forms.
- Apply destination policy. Check an exact origin, hostname, port, and path allowlist where possible.
- Resolve and classify. Block loopback, private, link-local, multicast, and metadata ranges for every DNS answer.
- Handle redirects safely. Disable them or validate every hop with the same rules.
- Queue in an isolated worker. Use least-privilege credentials and restricted egress.
- Enforce limits. Apply dimensions, full-page/PDF, JavaScript, timeout, bytes, concurrency, retry, and batch limits.
- Persist safely. Encrypt private output, use unguessable identifiers, enforce short retention, and provide deletion.
- Report minimally. Return a controlled result and request ID, not raw upstream data or stack traces.
- Observe and test. Measure outcomes and actively test DNS rebinding, redirect bypasses, alternate IP encodings, parser differentials, and quota exhaustion.
6. Hosted versus self-hosted screenshot services
The choice changes which controls you operate directly; it does not remove the SSRF responsibility. A hosted vendor still needs a destination policy for your use case, and you still need to review its retention, caching, region, and contractual terms before submitting private pages.
| Control area | Hosted service | Self-hosted service |
|---|---|---|
| URL and egress policy | Ask what schemes, ports, redirects, DNS checks, private ranges, and outbound networks are blocked; add your own allowlist before calling it. | You configure parsing, DNS/IP checks, redirect handling, firewall rules, and the allowlist. |
| Browser sandbox and patches | The provider operates browser workers and patching; verify isolation and security commitments. | You own sandbox design, patch cadence, worker lifecycle, and vulnerability response. |
| Credentials and tenants | Review tenant isolation, secret handling, support access, and audit controls. | You control identities and storage, but must implement isolation and rotation correctly. |
| Retention and geography | Confirm cache behavior, regions, deletion guarantees, and export paths. | You choose storage, region, retention, and deletion, while operating them continuously. |
| Limits and observability | Check documented timeouts, quotas, concurrency, status codes, request IDs, and logs. | You must build accounting, rate limiting, metrics, alerting, and incident workflows. |
| Rendering features | Verify JavaScript, selectors, full-page output, PDF, waits, and custom request controls against your policy. | You can expose any feature, but every additional capability needs a threat review and limit. |
| Cost at volume | Predictable per-request or plan pricing, plus any storage or egress charges. | Infrastructure, browser operations, bandwidth, patching, and engineering time become your costs. |
7. Provider-specific checks before production
Screenshot API documents a POST endpoint at https://api.screenshot-api.org/api/v1/screenshot, bearer or X-API-Key authentication, PNG/JPEG/WebP/PDF output, full-page and selector capture, JavaScript and CSS options, timeouts, caching, and structured 400, 401, 422, 429, and 502 errors. Its published allowance is 60 requests per minute and 500 screenshots per month on the free plan, with 429 responses for rate limiting. Treat these as provider documentation to verify in your contract and deployment: confirm privacy, retention, processing region, deletion, cache behavior, and network restrictions before sending private pages.
8. Troubleshooting common failures
| Symptom | Likely cause | Fix |
|---|---|---|
| Every request is rejected as unsafe | The URL fails scheme, origin, port, or IP policy. | Log the normalized policy decision (not secrets), then correct the allowlist or destination. Do not weaken checks to accept malformed forms. |
| A public hostname is blocked intermittently | DNS returns multiple addresses, including a private or link-local one. | Inspect all answers, reject unsafe sets, and use an origin whose DNS is stable and controlled. |
| The first page loads but a redirect fails | The redirect target was not revalidated. | Validate every hop or disable redirects; enforce a hop limit. |
| Jobs end with 429 | Tenant or provider rate/concurrency quota is exhausted. | Throttle at the caller, honor retry guidance, reduce parallelism, and review per-tenant budgets. |
| Jobs time out or consume excessive memory | Large full-page/PDF work, JavaScript, waits, or retries exceed limits. | Lower dimensions and deadlines, cap output bytes, restrict scripts, and separate heavy jobs into a bounded queue. |
| The image contains a consent banner or chat widget | The renderer captured the page before cleanup or the service does not remove those elements. | Use a documented consent/pop-up handling feature, a hide-selector rule, or controlled CSS; verify that the behavior is permitted for the site. |
| Users can retrieve another tenant’s file | Predictable object names or missing authorization on downloads. | Use unguessable IDs, enforce tenant checks on every read, and issue short-lived signed links. |
| Incident review finds secrets in logs | Full URLs, query strings, cookies, or headers were logged. | Redact at ingestion, rotate exposed credentials, purge old logs where possible, and log normalized categories instead. |
9. A practical security checklist
- TLS everywhere; credentials in headers or a secret manager where the API supports headers.
- Authentication, authorization, per-tenant quotas, rotation, and revocation.
- Maintained URL parser plus scheme, port, origin, and path policy.
- DNS/IP checks for private, loopback, link-local, multicast, and metadata ranges.
- Redirects disabled or checked hop by hop.
- Isolated, least-privilege renderer with restricted egress and patched browser.
- Limits for dimensions, full-page/PDF work, JavaScript, timeout, bytes, concurrency, retries, and batch size.
- Private encrypted storage, short retention, deletion, and a documented cache review.
- Redacted logs, request IDs, metrics, alerts, and security tests for bypasses.
Or skip the browser setup
ScreenshotNeo is a hosted screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—work with Claude, Cursor, and other MCP clients.
Use the documented one-call request and see the full parameter reference in the ScreenshotNeo documentation. The example uses the service’s access_key parameter; protect that URL from shell history, proxy logs, and application logs, and keep the key in a secret manager.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo also supports full-page captures with lazy images loaded, CSS-selector element capture, dark mode, 12 device presets and custom viewports, retina scale, PDF paper size/margins/landscape/page ranges, HTML/CSS-to-image, custom CSS and JavaScript, pre-capture clicks, hide selectors, selector/delay/network-idle waits, ad/tracker/request/resource blocking, custom headers/cookies/user agents and Authorization, timezone and geolocation, transparent backgrounds, resizing, selectable-TTL caching, signed public-image links, asynchronous jobs with signed webhooks, bulk capture of up to 100 URLs per call, a usage API, and an OpenAPI specification. Common screenshot-API parameter names are accepted to ease migration.
The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is on every plan, and yearly billing provides two months free. Create a free ScreenshotNeo account to start with the 1,000 monthly screenshots.
Frequently Asked Questions
Should a screenshot service ever accept arbitrary internet URLs?
Only when the product genuinely requires it and the service applies strict scheme, origin, DNS/IP, redirect, egress, and resource policies. A finite destination allowlist is safer and easier to audit.
How should I test an SSRF defense before launch?
Test alternate IPv4 and IPv6 forms, DNS answers that change, redirect chains, encoded hostnames, embedded credentials, private and metadata ranges, parser differences, oversized jobs, and quota exhaustion. Verify that blocked attempts produce no outbound connection and no secret-bearing log entry.
What evidence should I request from a hosted provider?
Request current documentation or contract terms covering network restrictions, browser isolation and patching, tenant separation, retention and deletion, cache behavior, processing regions, authentication, quotas, incident response, and auditability.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

