Every check
RepoFort runs.
RepoFort currently runs 57 security checks across your GitHub repository and deployed site, covering secrets, authentication, injection attacks, HTTP headers, and more. Open any rule to see why it matters and how to fix it.
Secrets & Credentials
Credentials and sensitive values committed to code or exposed to the browser.
Authentication
Login checks, session verification and guards on protected routes and endpoints.
API & Input Handling
CORS, CSRF, rate limiting, and unsafe handling of request input such as path traversal and command injection.
Frontend Security
Client-side injection risks including XSS and dynamic code execution.
Database Queries
SQL injection and raw query patterns that bypass parameterization.
Configuration
Cookie flags, error handling, HTTPS redirects and other server hardening.
HTTP Security Headers
Browser security headers such as CSP, HSTS and clickjacking protection, plus headers that disclose your stack.
Run all 57 checks
against your repo.
Free tier · No install required · Results in under 60 seconds.