Security checks
Every check
RepoFort runs.
RepoFort currently runs 57 security checks across your GitHub repository and deployed site — covering secrets, authentication, injection attacks, HTTP headers, and more.
Secrets & Credentials
Credentials and sensitive values committed to code or exposed to the browser.
Authentication
Session verification, access guards, and identity checks on protected routes.
API Security
CORS policy, CSRF protection, and rate limiting on API endpoints.
Frontend Security
Client-side injection risks including XSS and dynamic code execution.
Database Access
SQL injection and unsafe raw query patterns that bypass parameterization.
Configuration
Cookie flags, error handling, command injection, and other server hardening issues.
HTTP Security Headers
Browser security directives including CSP, HSTS, and clickjacking protection.
lib/security/security-catalog.ts, the single source of truth that mirrors the live scanner rule files. The dashboard Security Guide is generated from the exact same catalog, so both surfaces always show the same set of checks and the same count. Adding one entry there updates this page, the guide, and every count automatically on the next deploy. Detection patterns and payloads are deliberately not published here.Run all 57 checks against your repo.
Free tier · No install required · Results in under 60 seconds.