Best for
- Releases shipping without any security review at all
- Making 'did anyone check the permissions?' a checklist line instead of a hope
- Small teams needing the 80% pass that fits in an afternoon
What you give it
- The release: the diff or feature, and access to run the checks
What you get back
- The pass/fail list: each check run, with the failing evidence where found
- Findings ranked by exploitability, each with its fix — most are one-line-to-small
- The repeatable version: the checklist tuned to your stack, ready for every future release
How it works
- Runs checks in exploitability order: access control first (the highest-yield class), then injection surfaces, auth flows, secrets, headers, dependencies.
- Tests the deny paths, not just the allow paths: the wrong user, the expired token, the other tenant's id.
- Collects evidence per finding: the request that proves it, so fixes are verifiable and severity arguable.
- Leaves the checklist tuned to your stack behind — the pass is repeatable or it is theatre.
Example
You: Run the security pass on the new client-portal release before Thursday.
Result: The afternoon's findings: the document-download endpoint checks login but not ownership (the classic — any logged-in user could fetch any document by id; fixed and tested same day), the new search parameter reached the query builder unparameterised in one of its three paths (fixed), two dependencies with known exploits in the lockfile (updated), missing security headers on the new subdomain (added), and the debug endpoint that was never meant to deploy (removed). Eleven checks passed clean — also recorded, because an audit trail is the checklist's second product.
Limits — please read
- A checklist pass catches the common classes; novel design flaws need threat modelling, deep targets need specialists — it says which when.
- Checks run against what is testable pre-release; production-config-only issues get a deploy-day verification list.
- Clean passes are recorded too; absence of evidence beats evidence of absence-of-looking.