What is detektd?
2 min read
An external scanner, nothing to install
detektd audits your app from the outside, the way an attacker would: no code access, no SDK to integrate, no agent to deploy, no cloud credentials to hand over. You give it a public URL, the scan does the rest by making real HTTP requests against it, the same way a browser or a script would.
- No source code is ever read: everything found is inferred from network traffic, HTTP responses, the JS actually shipped to the browser, and endpoints that actually respond.
- No standing access to your infra: no cloud API key, no database access, no webhook installed in your repo.
Two modes: passive and active
The classic (passive) scan is read-only. The active scan adds probes that write, call RPCs and verify per-user authorization, using a logged-in test account.
- Passive: free, ~2 minutes, no login required. Covers security headers, exposed secrets, RLS posture on reads, dependency CVEs, infra exposure.
- Active: Pro-only, needs domain ownership verified first. Adds write, RPC, CSRF, rate-limit and per-user authorization (BOLA/IDOR) tests, classes of finding that are structurally invisible without a logged-in account.
What the engine actually checks
"Security scanner" is vague; here are the actual families of checks that run on every scan, in roughly the order the engine runs them:
- Exposed secrets & credentials: API keys, tokens, .env files, private keys reachable publicly.
- Security headers & transport: CSP, HSTS, HTTPS redirect, badly scoped cookies, dangerous cache headers.
- Supabase: RLS policies, anon-key posture, storage buckets, realtime channels, public RPC endpoints.
- Auth & per-user authorization: sessions, and in active mode, BOLA/IDOR (reaching another user's resource).
- Dependencies & frameworks: known CVEs in manifests (npm, pip, go...) and detected frameworks (Next.js, and so on).
- Infrastructure exposure: open ports, admin panels, exposed vector/cache databases, dangling subdomains (takeover).
- Supply chain: exposed source archives, suspicious or typosquatted dependencies.
- AI surface: exposed system prompts, prompt-injection-prone endpoints, unauthenticated MCP tools.
Every finding names the exact check that caught it, never a score with no detail. See "Understanding findings" for the full format.
Which stack?
Supabase is the best-covered stack, but the engine runs 190+ named checks against any modern stack: Next.js, Firebase, a custom backend, and so on. A site with no Supabase is still a normal, complete, scored scan: the "Supabase" families above simply don't apply, everything else runs the same.