Security scanning for code and websites
RepoVerse reviews a GitHub repository's code and dependencies, or a live website's headers, cookies and scripts, and shows the evidence behind every finding. These guides explain each class of vulnerability it looks for, with a vulnerable example next to the fix.
Scanners
- GitHub security scanner for code, secrets and dependenciesScan a GitHub repository for injection flaws, leaked secrets and vulnerable dependencies. Data-flow traces from request to sink, lockfile-aware, with fixes.
- Website security scanner that shows its evidenceFree passive website security scan: HTTPS and HSTS, CSP, cookies, mixed content, exposed keys and outdated JavaScript libraries — with the exact header behind each finding.
- Security headers checker with a fix for every gapCheck a site's HTTP security headers — Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy — and get the exact line to add for each gap.
- Dependency vulnerability scanner that reads your lockfileCheck npm, yarn, pnpm, PyPI, Cargo, Composer and RubyGems lockfiles against the OSV vulnerability database. Exact installed versions, transitive paths and fixed releases.
- Find vulnerable JavaScript libraries on a live websiteFind outdated, vulnerable JavaScript libraries on any website — jQuery, lodash, Bootstrap, moment, DOMPurify, Next.js — even inside minified Vite and webpack bundles.
Vulnerabilities in code
- SQL injection: what it is and how to fix itWhat SQL injection (CWE-89) is, a vulnerable query next to the fixed one, and how to find string-built SQL in your code with data-flow analysis.
- Command injection: when a parameter runs a shell commandHow OS command injection (CWE-78) turns a request parameter into a second shell command, the safe execFile pattern, and how to find exec calls fed by user input.
- Code injection: request input passed to evalWhy eval, new Function and string timers on request data mean remote code execution (CWE-95), a real example from OWASP NodeGoat, and the fix.
- NoSQL injection: rewriting MongoDB queries from a requestHow MongoDB $where expressions and operator objects like {"$ne": null} let request data rewrite a query (CWE-943), with vulnerable and fixed examples.
- Cross-site scripting (XSS): how it works and how to stop itReflected, stored and DOM-based XSS (CWE-79) explained with vulnerable and fixed code, plus the template, CSP and cookie settings that limit the damage.
- SSRF: when a request decides where your server connectsHow SSRF (CWE-918) lets a request choose where your server connects — internal services, cloud metadata at 169.254.169.254 — and how to build URLs safely.
- Path traversal: reading files outside the intended folderHow ../ sequences in a file name escape the intended folder (CWE-22) to read config files and keys, and the resolve-and-check pattern that stops it.
- Open redirect: your domain as a phishing linkHow an unvalidated redirect parameter (CWE-601) turns your domain into a trusted-looking link to a phishing page, and how to allow only local paths.
- ReDoS: how one regular expression can stall a serverWhy nested quantifiers like ([0-9]+)+ make a regex backtrack exponentially (CWE-1333), how a few dozen characters stall a Node.js server, and how to rewrite them.
- IDOR: changing one number to see someone else's dataHow changing an ID in a URL exposes other users' data (IDOR, BOLA, CWE-639), why a login check is not an ownership check, and how to scope lookups to the session.
- CSRF: requests your users never meant to sendHow CSRF (CWE-352) makes a logged-in visitor's browser submit forms to your site, and how CSRF tokens and SameSite cookies stop it in Express and other frameworks.
- Hardcoded secrets: API keys in code, commits and bundlesFind API keys, tokens and passwords committed to a repository or shipped in a website's JavaScript (CWE-798), why deleting the file is not enough, and how to rotate them.
- Vulnerable dependencies: the code you did not writeMost application code is third-party. How vulnerable dependencies get into a project (CWE-1395), why the lockfile is what matters, and how to pick the upgrade that fixes it.
- Insecure deserialization: data that runs as codeWhy deserialising untrusted data with pickle, yaml.load, Java serialization or node-serialize runs attacker code (CWE-502), and the JSON-plus-validation alternative.
- Password storage: hash with bcrypt, scrypt or Argon2Why passwords must never be stored in plaintext or with MD5/SHA-1 (CWE-256, CWE-916), and how to hash and verify them correctly with bcrypt, scrypt or Argon2.
- Log injection: forging entries in your own logsHow line breaks in request data forge fake log entries (CWE-117) and hide attacks from whoever reads the logs, and how structured logging and stripping CR/LF prevent it.
Website and transport security
- Secure session cookies: the flags and the login stepSet session cookies safely: Secure, HttpOnly and SameSite flags (CWE-614, CWE-1004), regenerating the session at login against fixation, with Express examples.
- Content Security Policy: writing one that actually protectsWrite a Content-Security-Policy that actually stops XSS: why unsafe-inline, unsafe-eval and wildcard sources defeat it, nonces and strict-dynamic, and a policy to start from.
- HTTPS and HSTS: closing the plain-HTTP gapWhy every site needs HTTPS, a 301 redirect from HTTP and a Strict-Transport-Security header (CWE-319), what max-age to use, and how to avoid mixed content.
- Clickjacking: stolen clicks through an invisible frameHow clickjacking (CWE-1021) hides your page in an invisible frame to steal clicks, and the two headers — CSP frame-ancestors and X-Frame-Options — that prevent it.