Learn
Rule catalog
Every detection rule in the scanner — 77 in total — with its severity and CWE/OWASP mapping. Use it to understand what each finding means and to teach a checklist.
Hardcoded credentials embedded in connection URL
Any file · secret-credentials-in-url
Missing Strict-Transport-Security header
vercel.json · vercel-strict-transport-security
Missing Content-Security-Policy header
vercel.json · vercel-content-security-policy
Missing Permissions-Policy header
vercel.json · vercel-permissions-policy
Dependency below known-safe version
package.json · pkg-vuln*
Known compromised release (hijacked maintainer)
package.json · pkg-compromised*
Dev tool shipped in production dependencies
package.json · pkg-devtool-in-deps*
No audit script
package.json · pkg-missing-audit-script
No HEALTHCHECK
Dockerfile · docker-no-healthcheck
node_modules not ignored
.gitignore · gitignore-missing-node-modules
Sensitive host path mounted
docker-compose.yml · compose-sensitive-mount*
Seccomp/AppArmor/SELinux disabled
docker-compose.yml · compose-unconfined*
Database port published on all interfaces
docker-compose.yml · compose-public-datastore*
Missing security headers
nginx.conf · nginx-missing-security-headers