What a Security Check covers
The same checks on every plan, free or paid. 83 of the rules were written for mistakes that work fine until someone looks. Pick your stack to see what they catch in your app, and what they miss.
- Secrets
- 214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
- Dependencies
- Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
- Code
- 83 rules for mistakes that work fine until someone looks, plus 344 general rules at Low.
- Configuration
- Dockerfile, Kubernetes, Terraform, and 27 mobile checks.
New: AI and payment checks
We now flag the mistakes AI-built apps make when they connect to an LLM or to Stripe: AI output that runs as code, reaches your database or lands in your page as HTML, API keys shipped to the browser, Stripe webhooks anyone can fake, and checkouts where the buyer sets their own price. 26 new checks in JavaScript, TypeScript and Python.
- AI integration
- AI output run as code or a command Critical
- AI output run as SQL Critical
- LangChain allowed to run code on your server Critical
- AI output shown as HTML High
- An AI API key in the browser High
- LangChain allowed to call any address High
- AI choosing the URL or file your server uses Moderate
OpenAI, Anthropic, Vercel AI SDK, Google GenAI, LiteLLM and LangChain, plus tool and MCP-server handlers.
- Stripe payments
- A webhook anyone can fake Critical
- A failed signature check that is ignored Critical
- The signature check skipped when the secret is missing High
- The buyer setting their own price High
Express, Next.js route handlers, Fastify, Flask, FastAPI and Django.
- Login and API security
- Login tokens signed with a secret written in the code High
- Login token signature check turned off High
- Flask session key written in the code High
- Whole project folder served to the web High
- Any website able to use your users' logins Moderate
JavaScript, TypeScript and Python.
- Improved
Secret keys in public env vars: Vite variables are checked too. Keys that are public by design, such as Firebase web keys, Stripe publishable keys and Supabase anon keys, are no longer reported by this check, and each leaked key is one finding, not two.
What these don't check
- Data is followed within one file. AI output that passes through your own helper in another file is not followed.
- AI providers other than the ones above, or raw HTTP calls to an AI API.
- Payment providers other than Stripe.
- A Stripe signature check in shared middleware or a guard in another file. That handler may be flagged even though it is protected.
- Whether an AI endpoint has a login or a rate limit.
What it covers for your app
Pick what you built with.
- Secrets
Covered: Stripe, OpenAI, Anthropic, AWS and GitHub keys, in your files and git history
Covered: A Supabase service-role key, found as a JSON Web Token
Not covered: A Postgres DATABASE_URL connection string
- Dependencies
Covered: package-lock.json, yarn.lock, pnpm-lock.yaml and bun.lock
Not covered: bun.lockb, the binary lockfile (commit the text bun.lock)
Not covered: devDependencies, skipped on purpose
- Code
Covered: Supabase row-level security: open policies, RLS switched off, policies trusting user_metadata
Covered: Admin checks only in "use client" components, swapped IDs, server actions with no auth check
Covered: Server secrets in NEXT_PUBLIC_ variables
Covered: AI output run as code or SQL, or shown as HTML, and AI keys shipped to the browser
Covered: Stripe webhooks anyone can fake, and checkouts where the buyer sets the price
- Configuration
Covered: Your Dockerfile, if you have one
Not covered: Vercel project settings
Try
Where it stops
Secrets
- Database connection strings: MongoDB, Postgres, Redis, AMQP.
- Providers without their own rule, such as Postmark, PayPal, Vercel, Segment and Docker Hub. Only a key-named, random-looking value is flagged.
Dependencies
- Development and test dependencies.
bun.lockb, andgo.sumwithoutgo.mod.- Unpinned ranges in
requirements.txt, and Maven versions set by a parent or BOM. - CocoaPods beyond the 8 pods on our own list.
Code and configuration
- Ruby, Rust, Elixir, PHP and Objective-C code.
- Docker Compose files. Helm, CloudFormation and ARM templates are not claimed.
Everything else
- Your running app. Nothing is built, installed or run.
- On an individual plan, a repository over 500 MB or 20,000 files: no git history for secrets, and code rules read the first 20,000 files. The report says so.
A clean report means these checks found nothing blocking on that commit. It is a good sign and never a guarantee.
Try it on your own code.
One free check per repository. No card. Compare plans