What is detektd?

2 min read

An external scanner, nothing to install

detektd audits your app from the outside, the way an attacker would: no code access, no SDK to integrate, no agent to deploy, no cloud credentials to hand over. You give it a public URL, the scan does the rest by making real HTTP requests against it, the same way a browser or a script would.

  • No source code is ever read: everything found is inferred from network traffic, HTTP responses, the JS actually shipped to the browser, and endpoints that actually respond.
  • No standing access to your infra: no cloud API key, no database access, no webhook installed in your repo.

Two modes: passive and active

The classic (passive) scan is read-only. The active scan adds probes that write, call RPCs and verify per-user authorization, using a logged-in test account.

  • Passive: free, ~2 minutes, no login required. Covers security headers, exposed secrets, RLS posture on reads, dependency CVEs, infra exposure.
  • Active: Pro-only, needs domain ownership verified first. Adds write, RPC, CSRF, rate-limit and per-user authorization (BOLA/IDOR) tests, classes of finding that are structurally invisible without a logged-in account.

What the engine actually checks

"Security scanner" is vague; here are the actual families of checks that run on every scan, in roughly the order the engine runs them:

  • Exposed secrets & credentials: API keys, tokens, .env files, private keys reachable publicly.
  • Security headers & transport: CSP, HSTS, HTTPS redirect, badly scoped cookies, dangerous cache headers.
  • Supabase: RLS policies, anon-key posture, storage buckets, realtime channels, public RPC endpoints.
  • Auth & per-user authorization: sessions, and in active mode, BOLA/IDOR (reaching another user's resource).
  • Dependencies & frameworks: known CVEs in manifests (npm, pip, go...) and detected frameworks (Next.js, and so on).
  • Infrastructure exposure: open ports, admin panels, exposed vector/cache databases, dangling subdomains (takeover).
  • Supply chain: exposed source archives, suspicious or typosquatted dependencies.
  • AI surface: exposed system prompts, prompt-injection-prone endpoints, unauthenticated MCP tools.

Every finding names the exact check that caught it, never a score with no detail. See "Understanding findings" for the full format.

Which stack?

Supabase is the best-covered stack, but the engine runs 190+ named checks against any modern stack: Next.js, Firebase, a custom backend, and so on. A site with no Supabase is still a normal, complete, scored scan: the "Supabase" families above simply don't apply, everything else runs the same.

Was this article helpful?