One scan to catch them all

323 checks across your repo and your live services. Filter by the platform they run against, by what they are about, or both.

Guard my app · Free
Platform
Category
323 checks

Security & compliance

152 checks
Direct prompt injection: request input in a system/instruction prompt Source codeAI app safety Indirect prompt injection: fetched/DB/file content into prompt or tool context Source codeAI app safety Model output run as raw SQL (LLM-authored query executed unparameterized) Source codeAI app safety Excessive agency: over-powered tool-using agent, no scoping/human-in-loop Source codeAI app safety Sensitive data disclosure: secret or unminimized PII in the model prompt Source codeAI app safety JWT verify without algorithm check Source codeAI-generated code risks jwt.decode used instead of jwt.verify — token signature not checked Source codeAI-generated code risks Weak password hash (MD5/SHA/low-bcrypt) Source codeAI-generated code risks Deprecated/insecure crypto primitive Source codeAI-generated code risks eval / dynamic exec on user input Source codeAI-generated code risks TLS verification disabled Source codeAI-generated code risks Commented-out secret Source codeAI-generated code risks Raw/unparameterized SQL on user input (A03) Source codeAI-generated code risks Secret-shaped NEXT_PUBLIC_ env var (A02) Source codeAI-generated code risks SSRF — fetch to user-controlled URL (A10) Source codeAI-generated code risks Next.js middleware-only authz (CVE-2025-29927) Source codeAI-generated code risks Path traversal: request path into a filesystem sink, no containment Source codeAI-generated code risks Open redirect: user-controlled redirect target, no validation Source codeAI-generated code risks SSRF via connection string / non-fetch sink / DNS rebinding Source codeAI-generated code risks Known-risky / deprecated package Source codeDependency supply chain postinstall script in unknown dep Source codeDependency supply chain Header/recipient injection Source codeEmail safety Unverified sender / no SPF·DKIM·DMARC Source codeEmail safety API-key exposure Source codeEmail safety PII/secret in email or logs Source codeEmail safety HTML injection Source codeEmail safety No throttling Source codeEmail safety Missing unsubscribe Source codeEmail safety No input validation at route boundary Source codeError handling & resilience PII columns discovered (inventory) Source codeGDPR & privacy Special-category / financial PII unprotected Source codeGDPR & privacy Plaintext credential / unhashed sensitive column Source codeGDPR & privacy User object logged — may write PII to logs Source codeGDPR & privacy No retention / erasure path on PII table Source codeGDPR & privacy Missing consent capture Source codeGDPR & privacy PII flows to third-party processor (verify DPA) Source codeGDPR & privacy No HTTP security headers configured Source codeHTTP security headers Authorization header logged in plaintext Source codeObservability gaps Unverified webhook Source codePayment safety Missing idempotency Source codePayment safety Client-trusted amount Source codePayment safety Secret-key exposure Source codePayment safety PCI/card-data handling Source codePayment safety Unhandled failure/dispute Source codePayment safety Client-success fulfillment Source codePayment safety Hardcoded config / credential Source codeProduction readiness No rate limit on public POST Source codeProduction readiness Permissive CORS with credentials Source codeProduction readiness Object fetched by request id with no owner check (IDOR) Source codeRoute authorization Missing auth guard on a state-changing or sensitive route Source codeRoute authorization Broken function-level authz: privileged operation with no role check Source codeRoute authorization Mass assignment: request body written wholesale into a model Source codeRoute authorization Third-party action pinned to mutable tag GitHubActions supply chain Pull_request_target with PR-head checkout (pwn-request) GitHubActions supply chain Secret value echoed in run step GitHubActions supply chain Workflow missing permissions block GitHubActions supply chain Script injection via github.event expression in run step GitHubActions supply chain CI pipeline failing repeatedly GitHubActions supply chain Production config file with hardcoded values GitHubEnv & config hygiene Package publish token passed as CLI argument (log-visible) GitHubRelease & branch safety Commit signing not required GitHubRepository protection posture GitHub Actions allows all third-party actions GitHubRepository protection posture Secret-scanning push protection disabled GitHubRepository protection posture Org does not require two-factor authentication GitHubRepository protection posture Hardcoded provider API token GitHubSecret hygiene Committed .env file GitHubSecret hygiene Committed private key or certificate GitHubSecret hygiene Known-vulnerable dependency (Dependabot) GitHubSupply-chain alerts Open code-scanning (SAST) alert GitHubSupply-chain alerts Active leaked secret (secret scanning) GitHubSupply-chain alerts Project is publicly visible GitLabGitLab project posture Group does not require two-factor authentication GitLabGitLab project posture Secret push protection disabled GitLabGitLab project protection Known-vulnerable dependencies GitLabGitLab scanner findings Open SAST findings GitLabGitLab scanner findings Active leaked secrets GitLabGitLab scanner findings Service-role key exposed in client-side code — full RLS bypass SupabaseAuth & service-role key safety Service-role client queries a table with no tenant filter SupabaseAuth & service-role key safety Anon-key client used for a privileged write SupabaseAuth & service-role key safety IDOR risk: user_id from request body used in Supabase query without JWT verification SupabaseAuth & service-role key safety No auth check before a Supabase query in a route handler SupabaseAuth & service-role key safety Email OTP expiry over 1 hour (interception window) SupabaseAuth hardening & exposure config Manual account linking enabled without a product need SupabaseAuth hardening & exposure config Refresh-token reuse interval over 30 seconds SupabaseAuth hardening & exposure config Schemas beyond public exposed through the data API SupabaseAuth hardening & exposure config Unauthenticated edge function SupabaseAuth hardening & exposure config Legacy keys / HS256 still enabled SupabaseAuth hardening & exposure config RLS enabled on a table but no CREATE POLICY found — app rows locked out SupabaseMigration & schema safety Postgres extension enabled without review SupabaseMigration & schema safety RLS disabled on a table — cross-tenant rows accessible SupabaseRLS & tenant isolation No RLS policy found for a queried table — lockout or bypass risk SupabaseRLS & tenant isolation Over-permissive RLS policy on a table — no tenant scoping SupabaseRLS & tenant isolation RLS-denial spike SupabaseRuntime error logs Storage bucket is public — objects readable without auth SupabaseStorage safety No RLS policy on storage.objects for a bucket SupabaseStorage safety Storage upload has no MIME type or file-size limit SupabaseStorage safety getPublicUrl() used for user-specific storage object — enumerable by anyone SupabaseStorage safety Signed URL TTL long enough to act as a public URL SupabaseStorage safety Neon connection string with embedded password committed to source NeonConnection hygiene .env.production committed with DATABASE_URL (not gitignored) NeonConnection hygiene ?sslmode=disable in connection string NeonConnection hygiene TLS certificate verification disabled in a production-scoped file NeonConnection hygiene DATABASE_URL logged / included in error context NeonConnection hygiene Same endpoint hostname in dev + prod env files NeonConnection hygiene Missing sslmode=require in production config NeonConnection hygiene Connection string in test fixture / snapshot NeonConnection hygiene Neon project accepts connections from any IP — no allowlist and public connections not blocked NeonCost & ops health IP allowlist set but public connections not blocked NeonCost & ops health Postgres version end-of-life (< 14) NeonCost & ops health Unprotected role on the primary/protected branch NeonCost & ops health IP allow-list not scoped to protected branches NeonCost & ops health Over-permissioned or team-wide integration VercelAccount supply chain Suspended/disabled integration still installed VercelAccount supply chain Non-marketplace integration with multiple scopes VercelAccount supply chain Excessive OWNER count VercelAccount supply chain Large number of pending invites VercelAccount supply chain Domain not verified with Vercel VercelAccount supply chain Domain DNS misconfiguration detected by Vercel VercelAccount supply chain Log drain pointing at an unrecognized third-party host VercelAccount supply chain No deployment protection (password/SSO/trusted-IP all absent) VercelDeployment posture OIDC issuer in global mode (tokens honored beyond this team) VercelDeployment posture Firewall enabled but no managed rulesets active VercelDeployment posture Preview deployments publicly accessible with staging data signals VercelPreview deploy safety Production/live secret found in preview env scope config VercelPreview deploy safety productionBrowserSourceMaps: true VercelPreview deploy safety Source maps enabled without environment guard in bundler config VercelPreview deploy safety No robots noindex for preview environments VercelPreview deploy safety Debug/verbose logging without production guard VercelPreview deploy safety Live Stripe secret key exposed via NEXT_PUBLIC_ prefix VercelPublic env exposure Secret-named value behind a client-bundle prefix VercelPublic env exposure Ambiguous key or credential name behind a client-bundle prefix VercelPublic env exposure System env vars auto-exposed to every build (autoExposeSystemEnvs) VercelPublic env exposure Production secret env var older than a year (rotation hygiene) VercelPublic env exposure Unproxied A/AAAA/CNAME records expose the origin IP CloudflareDNS & origin exposure Wildcard DNS record widens the attack surface CloudflareDNS & origin exposure No DMARC record (domain can be spoofed in email) CloudflareDNS & origin exposure Mail domain (has MX) missing an SPF record CloudflareDNS & origin exposure SSL mode off/flexible (unencrypted origin hop) CloudflareEdge TLS posture Minimum TLS version below 1.2 CloudflareEdge TLS posture Always Use HTTPS is off CloudflareEdge TLS posture DNSSEC not active on the zone CloudflareEdge TLS posture Automatic HTTPS Rewrites off (mixed-content risk) CloudflareEdge TLS posture TLS 1.3 not enabled CloudflareEdge TLS posture HSTS missing, disabled, or max-age under 6 months CloudflareEdge TLS posture 0-RTT early data enabled (request replay risk) CloudflareEdge TLS posture No managed WAF ruleset on a production zone CloudflareWAF & rate limiting No rate-limiting rules on the zone CloudflareWAF & rate limiting Security Level essentially off (no IP challenges) CloudflareWAF & rate limiting Browser Integrity Check off CloudflareWAF & rate limiting Connected Cloudflare API token never expires CloudflareWorkers, Pages & API tokens Row-Level Security off / no policies (Postgres) Your databaseDatabase security posture Encryption at rest off (SQL Server TDE) Your databaseDatabase security posture

Cost

34 checks
Polling where webhook exists Source codeCost controls SELECT * / over-fetching Source codeCost controls Unbounded retries / log storm Source codeCost controls Missing cache TTL / unbounded cache Source codeCost controls Cron runs every minute on full scan Source codeCost controls Missing caching on hot reads Source codeScalability antipatterns Unfiltered Realtime subscription broadcasts every mutation SupabaseRealtime & cost Realtime channel never unsubscribed — connection leak SupabaseRealtime & cost Polling loop queries Supabase on a short interval — use Realtime instead SupabaseRealtime & cost select('*') fetches every column — unnecessary egress SupabaseRealtime & cost Branch created in PR workflow with no delete-on-close NeonBranching & migrations Compute ran continuously for 30 days (no scale-to-zero) NeonCost & ops health Storage growing — likely orphaned branch data NeonCost & ops health No spend quota on non-trial project NeonCost & ops health Ephemeral branch past expiry date NeonCost & ops health Preview/feature branch accumulating compute with no expiry NeonCost & ops health Non-primary branch > 1 GiB logical size NeonCost & ops health Non-primary branches hold 5× primary storage NeonCost & ops health Neon autosuspend disabled — compute bills as always-on NeonIdle compute cost Autosuspend timeout > 1 h on non-prod branch NeonIdle compute cost Pinned min/max CU (no scale-down) NeonIdle compute cost Pool with idleTimeoutMillis: 0 or missing (long-lived process) NeonIdle compute cost Background poll < 5 min interval hitting DB NeonIdle compute cost Health-check SELECT used by uptime monitor NeonIdle compute cost force-dynamic on non-personalized route VercelCaching & cost Missing revalidate / cache option on public data fetch VercelCaching & cost maxDuration > 60 s on non-streaming function VercelCaching & cost Image optimizer disabled (unoptimized: true) VercelCaching & cost Overly broad image remotePatterns wildcard VercelCaching & cost Unbounded collection response without pagination or streaming VercelCaching & cost Heavy bundle dependency in serverless route VercelCaching & cost Paid-plan zone with negligible traffic (idle spend) CloudflareWorkers, Pages & API tokens High-volume Worker (Workers cost driver) CloudflareWorkers, Pages & API tokens Large R2 bucket storage (storage cost) CloudflareWorkers, Pages & API tokens

Performance

26 checks
PrismaClient instantiated on every serverless invocation Source codeCost controls Unbounded fan-out / no concurrency cap Source codeCost controls N+1 DB queries — per-ID fetch inside map() Source codeScalability antipatterns Unbounded query / no pagination Source codeScalability antipatterns Whole table / large file in memory Source codeScalability antipatterns Sync CPU-heavy work in request path Source codeScalability antipatterns Event-loop blocking Source codeScalability antipatterns Data API max_rows unbounded or above 10000 SupabaseAuth hardening & exposure config Missing index on a hot query column — sequential scan SupabasePerformance advisors N+1 Supabase queries: .from() called inside a loop SupabasePerformance advisors select('*') without .limit() — unbounded result set SupabasePerformance advisors createClient() called inside a request handler — avoids connection reuse SupabasePerformance advisors Unused index — wasted write overhead SupabasePerformance advisors Edge route uses pg driver — Neon connections will exhaust on cold starts NeonConnection pooling Direct endpoint instead of -pooler in serverless NeonConnection pooling new Pool/new Client inside handler body (not singleton) NeonConnection pooling max pool size > 10 in serverless context NeonConnection pooling Missing @neondatabase/serverless in edge (general) NeonConnection pooling Foreign key has no covering index Your databaseSchema & indexes Large table with only its base/PK index Your databaseSchema & indexes SQL Server heap (no clustered index) Your databaseSchema & indexes MongoDB collection with no indexes Your databaseSchema & indexes Large MongoDB collection with only the _id index Your databaseSchema & indexes SQL Server auto-shrink enabled Your databaseSchema & indexes Slow-query signal (normalized) Your databaseSchema & indexes Heap cache-hit ratio under 0.90 on a hot table Your databaseSchema & indexes

Stability

30 checks
Swallowed exception on a critical path Source codeError handling & resilience Unhandled promise rejection Source codeError handling & resilience await on external call without try/catch Source codeError handling & resilience No timeout on fetch/DB/HTTP Source codeError handling & resilience No retries / backoff on external call Source codeError handling & resilience No circuit breaker on critical path Source codeError handling & resilience process.exit in library code Source codeError handling & resilience Console.log-only / no structured logger Source codeObservability gaps No request / correlation IDs Source codeObservability gaps No error-reporting integration Source codeObservability gaps No health / readiness endpoint Source codeObservability gaps Health endpoint doesn't check DB Source codeObservability gaps No distributed tracing (multi-service) Source codeObservability gaps Silent failure / fire-and-forget Source codeObservability gaps A specific workflow failing repeatedly GitHubActions supply chain Connection-pool exhaustion SupabaseRuntime error logs Statement-timeout/slow-query SupabaseRuntime error logs Repeated constraint violations SupabaseRuntime error logs API 5xx spike SupabaseRuntime error logs Repeated apply_migration failures NeonCost & ops health Failed-op ratio > 10% NeonCost & ops health Neon PITR retention window is less than 1 day NeonCost & ops health PITR retention < 7 days (production) NeonCost & ops health Worker runtime error rate elevated (last 24h) CloudflareWorkers, Pages & API tokens Worker throwing unhandled exceptions (last 24h) CloudflareWorkers, Pages & API tokens Worker exceeding CPU/memory limits (last 24h) CloudflareWorkers, Pages & API tokens Pages project's latest production deployment failed CloudflareWorkers, Pages & API tokens Pages project has repeated recent deployment failures CloudflareWorkers, Pages & API tokens Out-of-date engine major version Your databaseDatabase security posture MySQL table uses MyISAM (no transactions) Your databaseSchema & indexes

Code quality

35 checks
Hallucinated / nonexistent API call Source codeAI-generated code risks @ts-ignore masking type error Source codeAI-generated code risks TODO/FIXME/mock data in production Source codeAI-generated code risks Dead / never-imported file Source codeAI-generated code risks Scaffold boilerplate left uncustomised Source codeAI-generated code risks Inconsistent auth/error patterns Source codeAI-generated code risks No lockfile committed — installs are non-deterministic Source codeDependency supply chain Lockfile out of sync with manifest Source codeDependency supply chain Unpinned / floating version in deps Source codeDependency supply chain Abandoned package in dependencies Source codeDependency supply chain Mixed package managers Source codeDependency supply chain No automated tests in an app repo Source codeEngineering practices Critical module (auth/payments/data) untested Source codeEngineering practices TypeScript strict mode is off — whole classes of bugs go undetected Source codeEngineering practices Unsafe type escapes on external input Source codeEngineering practices No CI test/typecheck/lint gate Source codeEngineering practices Missing README / runbook docs Source codeEngineering practices Oversized untested core module Source codeEngineering practices Throwing string literal Source codeError handling & resilience Missing / stale .env.example Source codeProduction readiness No CI gates on main Source codeProduction readiness Missing .env.example GitHubEnv & config hygiene Config value hardcoded instead of env var GitHubEnv & config hygiene Env vars used in code but missing from .env.example GitHubEnv & config hygiene No CODEOWNERS file GitHubRelease & branch safety No Dependabot config — dependency updates not automated GitHubRelease & branch safety Dependabot security updates disabled GitHubRepository protection posture Connected repo is archived GitHubRepository protection posture No pushes for 90+ days on a scanned production repo GitHubRepository protection posture Delete-branch-on-merge disabled GitHubRepository protection posture Missing .gitignore coverage for env files GitHubSecret hygiene Connected project is archived GitLabGitLab project posture Source branches kept after merge GitLabGitLab project posture Table has no primary key Your databaseSchema & indexes MySQL table not utf8mb4 Your databaseSchema & indexes

Releases

46 checks
Bundle bloat (serverless) Source codeCost controls Native-build dep in serverless target Source codeDependency supply chain No SIGTERM / graceful shutdown Source codeProduction readiness Health endpoint behind auth / misleading Source codeProduction readiness No feature-flag on risky path Source codeProduction readiness DB migration runs in the same step as server start Source codeProduction readiness Destructive migration without shim Source codeProduction readiness Debug/dev mode in prod config Source codeProduction readiness Global mutable state in serverless Source codeScalability antipatterns No CI workflows — no status checks to gate merges GitHubRelease & branch safety Production deploy job without environment protection GitHubRelease & branch safety Automated release triggered on every push without a tag/release guard GitHubRelease & branch safety Default branch is unprotected GitHubRepository protection posture Branch protection too weak GitHubRepository protection posture Default branch is unprotected GitLabGitLab project protection Branch protection too weak GitLabGitLab project protection Merge allowed without a passing pipeline GitLabGitLab project protection Out-of-date Postgres SupabaseDatabase DR & network PITR disabled SupabaseDatabase DR & network Backups failing/none SupabaseDatabase DR & network Disk pressure / read-only lockdown SupabaseDatabase DR & network SSL not enforced SupabaseDatabase DR & network Network open to 0.0.0.0/0 SupabaseDatabase DR & network Migration drops a table or column with no rollback path SupabaseMigration & schema safety Column type change may silently truncate data SupabaseMigration & schema safety CREATE INDEX on a table without CONCURRENTLY — locks writes during deploy SupabaseMigration & schema safety Table subscribed via Realtime but absent from the supabase_realtime publication SupabaseRealtime & cost Hardcoded connection string in migration config (not env var) NeonBranching & migrations Destructive migration drops table with no rollback path NeonBranching & migrations DELETE FROM without WHERE in migration NeonBranching & migrations PII or large seed data inside migration file NeonBranching & migrations CI creates branch but sets wrong DATABASE_URL NeonBranching & migrations gitForkProtection: false — forked PRs get env vars + OIDC token VercelDeployment posture Single-region function defaults with a cross-region database VercelDeployment posture Short maxDuration with active crons VercelDeployment posture OOM crashes in recent production deployments VercelDeployment posture High ERROR-state deployment rate VercelDeployment posture No production deployments recorded VercelDeployment posture Runtime 5xx / error-level failures on the latest production deployment VercelDeployment posture No promotion-gate checks before production, or a blocking check failed yet promoted VercelDeployment posture Production deployments shipping with failing checks VercelDeployment posture Node-only API in edge runtime VercelEdge runtime readiness Node-incompatible or oversized dependency in edge runtime VercelEdge runtime readiness Heavy DB/network work in middleware.ts VercelEdge runtime readiness Middleware missing config.matcher (runs on all routes) VercelEdge runtime readiness Edge data-fetch route missing preferredRegion VercelEdge runtime readiness

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.