APIs & protocols
// schema · transport · injectionEngine fingerprinting, introspection and field-suggestion schema leaks, batching, schema-aware depth and alias limits, verbose resolver errors, mutation CSRF, and injection or SSRF reachable only through a resolver.
Read the breakdown →
A real HTTP/2 + protobuf client, not a port check: server-reflection enumeration, plaintext and self-signed transport, broken mutual TLS proven by an accept-with / refuse-without differential, and per-field injection into unary methods.
Read the breakdown →
The systems audits care about and scanners skip: WSDL parsing and operation enumeration, in-band and blind XXE, WS-Addressing ReplyTo SSRF, verbose faults, and SQL / XPath / command injection per operation.
Read the breakdown →
Databases & datastores
// injection · exposure · leaked credsOperator-injection payloads, exposed-instance + connection-string misconfigurations, and Mongoose privilege-escalation flaws.
Read the breakdown →
Five ways to find the cache behind an app — leaked config, client errors, dict:// SSRF, the host's own port, a serverless REST token in the bundle — then a read-only audit: unauthenticated access, RCE primitives and their preconditions, module CVEs, RESP command injection.
Read the breakdown →
The classes the Security Advisor can't see: a service_role key leaked in the client bundle, tables live-exploitable via the Data API, missing WITH CHECK writes, anon-callable RPCs, and public storage.
Read the breakdown →
The classes the console can't see are live: an Admin SDK service_account key leaked in the bundle, a world-readable/writable Realtime Database, public Storage, open Firestore, and auth email enumeration — and it never flags your public apiKey.
Read the breakdown →
Confirmed by the PostgreSQL wire protocol, not an open port: TLS availability, the authentication method the server really demands, passwordless trust access, and exposed .pgpass, pg_hba.conf and pg_dump files.
Read the breakdown →
Platforms, frameworks & CMS
// version · config · known CVEsCore + plugin fingerprinting cross-referenced to CVEs, wp-json / ?author= user enumeration, and the xmlrpc.php brute-force + pingback-SSRF surface.
Read the breakdown →
A real secret shipped in the client bundle, exposed source maps, the CVE-2025-29927 middleware bypass, and the /_next/image SSRF — never the public NEXT_PUBLIC_ keys, and a Vercel-hosted app correctly shows the CVE negatives.
Read the breakdown →
The graded /actuator ladder up to a leaked heap dump, Log4Shell and Text4Shell confirmed out-of-band, a Spring4Shell binding differential, and Tomcat CVEs matched on a verbatim version.
Read the breakdown →
What the Admin Console structurally can't see: the JWT config.json that is your application, Box client secrets and API tokens in shipped code, As-User impersonation driven by a caller-supplied id, and a Box SDK that compared webhook signatures without a constant-time function.
Read the breakdown →
A live secret or whsec_ signing key in your bundle, a Stripe config in the web root, a webhook receiver whose source is public and never verifies Stripe-Signature, and an unvalidated Connect redirect_uri. Your publishable key is never flagged.
Read the breakdown →
Version-gated CVEs matched against the version n8n itself reports, a management API returning real workflow or credential objects anonymously, and a workflow export carrying a stored credential. The public bootstrap document and the SPA catch-all stay silent.
Read the breakdown →
Auth & identity
// forgery · flow takeover · enumerationAuth0, Okta, Cognito, Keycloak or your own middleware: alg:none and RS256→HS256 forgery, cracked HMAC secrets, jku/kid injection, and an unregistered redirect_uri that really issues a code.
Read the breakdown →
A client_secret shipped to the browser, a config admitting localhost callbacks, an unregistered redirect_uri that really issues a code, and a callback route that forwards the code off-origin. Your client_id and JWKS are never flagged.
Read the breakdown →
An Admin REST API answering anonymously with a real realm or client object, a realm export carrying a client secret, and an issuer that follows a request header. The public realm document, admin console HTML and theme bundles stay silent.
Read the breakdown →
A client secret or AKIA key compiled into the browser bundle, and an Amplify config carrying a secret. Your user pool id, app client id, identity pool id, open sign-up and guest identities are public by design and are never flagged.
Read the breakdown →
Infrastructure & consoles
// unauthenticated admin · exposed datastoresAn anonymous API server or kubelet, plus Grafana, Jenkins, Consul, etcd, Prometheus, Elasticsearch, Kibana, Vault, phpMyAdmin, a Docker registry, debug pages, open Redis/Mongo and world-listable buckets — marker-confirmed, never a bare 200.
Read the breakdown →
Whether your origin is still reachable directly, making the WAF, rate limiting, bot management and Access optional — proved by content correlation, never a status code, and never by port-scanning. Plus Worker/Pages secrets in a public .dev.vars.
Read the breakdown →
AI & agent frameworks
// prompt injection · OOB SSRF · code-execMore breakdowns are being written from the live detection catalog. Want a specific stack next? Tell us.