// TECHNOLOGIES

What NewScan finds, per stack.

A growing index of technology-specific breakdowns. Each one lays out the exact payloads, misconfigurations, and application flaws NewScan checks for on that stack — and how it reproduces every signal before recording a finding. Every breakdown below is live coverage that ships today, not a roadmap.

APIs & protocols

// schema · transport · injection

Databases & datastores

// injection · exposure · leaked creds

Platforms, frameworks & CMS

// version · config · known CVEs
WordPress LIVE

Core + plugin fingerprinting cross-referenced to CVEs, wp-json / ?author= user enumeration, and the xmlrpc.php brute-force + pingback-SSRF surface.

Read the breakdown →

Vercel & Next.js LIVE

A real secret shipped in the client bundle, exposed source maps, the CVE-2025-29927 middleware bypass, and the /_next/image SSRF — never the public NEXT_PUBLIC_ keys, and a Vercel-hosted app correctly shows the CVE negatives.

Read the breakdown →

Spring Boot & Java LIVE

The graded /actuator ladder up to a leaked heap dump, Log4Shell and Text4Shell confirmed out-of-band, a Spring4Shell binding differential, and Tomcat CVEs matched on a verbatim version.

Read the breakdown →

Box LIVE

What the Admin Console structurally can't see: the JWT config.json that is your application, Box client secrets and API tokens in shipped code, As-User impersonation driven by a caller-supplied id, and a Box SDK that compared webhook signatures without a constant-time function.

Read the breakdown →

Stripe LIVE

A live secret or whsec_ signing key in your bundle, a Stripe config in the web root, a webhook receiver whose source is public and never verifies Stripe-Signature, and an unvalidated Connect redirect_uri. Your publishable key is never flagged.

Read the breakdown →

n8n LIVE

Version-gated CVEs matched against the version n8n itself reports, a management API returning real workflow or credential objects anonymously, and a workflow export carrying a stored credential. The public bootstrap document and the SPA catch-all stay silent.

Read the breakdown →

Auth & identity

// forgery · flow takeover · enumeration

Infrastructure & consoles

// unauthenticated admin · exposed datastores

AI & agent frameworks

// prompt injection · OOB SSRF · code-exec

More breakdowns are being written from the live detection catalog. Want a specific stack next? Tell us.