Release1.13.60

Follow the request

  1. (1)What's in 1.13
  2. (2)The road to 1.13

Five new checks follow what a visitor sends all the way into your server.

The full story in the app

What's in 1.13

15 changes in 1.13.60

Added

  • Server request forgery checkFlags code where a visitor's input decides which address your server calls, for example a URL passed straight to fetch.
  • Command injection checkFlags code where a visitor's input reaches a shell command or decides which program your server runs.
  • SQL injection checkFlags code where a visitor's input is written into the text of a database query instead of passed as a parameter.
  • Path traversal checkFlags code where a visitor's input decides which file your server reads or writes.
  • Unsafe redirect checkFlags code where a visitor's input decides where a redirect on your domain sends people.
  • Both lines in every findingEach finding names the line where the input arrives, the line that uses it, and how to fix it.
  • Where the new checks lookJavaScript and TypeScript in Next.js routes and server actions, Express and Hono.
  • A page for this release/updates/1.13 shows all 18 checks on one map, the new checks by example, and their benchmark results.

Improved

  • What we checked lists the new checksThe report has a fourth group, What a request can make your server do, with one line per new check.
  • Unread code is never a passCode the checks could not read, such as an unsupported framework, is reported as not checked.
  • Progress shows the code checksWhile a scan runs, the code checks appear in the progress list and in the count.

Fixed

  • Reading a token is not checking itThe access check no longer treats a decoded but unverified token as a signed-in user.
  • Framing protection as browsers see itA frame-ancestors rule set only in the page's HTML no longer counts, because browsers ignore it there.
  • File probes wait for your permissionLooking for files like .env needs you to confirm first that the site is yours.
  • A missing repository shows in the reportIf your repository cannot be read, the website checks still run and each code check says it could not.

The road to 1.13

12 smaller updates shipped before 1.13, 16 to 23 September 2026. Everything in them is part of this release.

  1. 1.1.5

    Every change counted, and a report that promises only what works

    Added

    • Version numbersEvery change now carries a version number and is recorded in this log.

    Improved

    • The report promises only what worksThe GitHub fix is not offered until it is switched on, and its page marks the steps as Planned.
    • Settings without promisesThe settings page lists only features that work today.
    • Legal linksTerms and Privacy appear on the sign-in page once their addresses are set.

    Fixed

    • Domain check wordingThe message about an outdated DNS record now reads correctly.
    • A wrong app addressA malformed app link shows There is nothing here instead of an error page.
    • Settings keep your inputA rejected save keeps the alert address you typed.
  2. 1.2.6

    The update log, and the build you are on

    Added

    • Updates pageEvery shipped release at app.vallit.net/updates, newest first, with what was added, improved and fixed.
    • Version in the sidebarThe sidebar shows the version you are on, with a dot until you have read the newest release.

    Improved

    • The checker names its versionRequests from Vallit's checker carry the release number in their user agent, so a firewall rule can allow them.
    • robots.txt and sitemapPublic pages are listed for search engines; signed-in pages and reports are excluded.
  3. 1.3.22

    Two checks that read code, and a repository to read

    Added

    • Access control checkFollows every API route, server action and procedure to the database and reports where strangers or other customers can reach records.
    • Payment integrity checkFollows checkout and payment webhooks and reports fake payments, prices set in the browser, double credits and cancelled plans that keep access.
    • AI second opinion on every findingAn AI reviewer reads the code path behind a finding, names the line that decides it and drops findings it rules out.
    • A quick first lookA smaller AI model rates each finding first. Tested on 126 judged findings, it dropped none of the real ones.
    • Connect your codeOn the app page you install the Vallit GitHub App, pick the repository that belongs to the app, and can disconnect at any time.
    • Only your chosen repository is readAccess is issued for a single check and never stored; only the person who installed the app can connect it.

    Improved

    • One button to connect codeGitHub's logo, one sentence, one button and three steps that tick off as you go.

    Fixed

    • Checks survive a broken code connectionIf the repository cannot be read, the website checks still run and the report still arrives.
    • GitHub outages stay on the pagePicking a repository while GitHub is unreachable shows a message instead of an error screen.
    • The pre-check retries when rate-limitedA busy minute no longer sends every finding straight to the full review.
  4. 1.4.27

    The log as one document, and checkpoints instead of sentences

    Added

    • Version index beside the logOn a wide screen, a list of all versions sits next to the log and jumps to each release.
    • The update log inside the appThe sidebar opens the log in place; the dot disappears once you have read it.

    Improved

    • Short entries instead of sentencesEvery entry starts with what changed, followed by a short detail.
    • A readable line lengthLines in the log are about eighty characters wide on every screen.
    • A visible unread dotThe dot in the sidebar now has enough contrast to be seen.

    Fixed

    • Screen readers hear two phrasesAn entry's title and its detail are no longer read as one run-together word.
    • Unknown update addressesAn address under /updates that does not exist shows a page with a way back to the log.
    • The front page appears without the databaseIf the database is out of reach when an update goes out, the front page shows without its live report card.
  5. 1.5.29

    A database that stays awake

    Improved

    • Checks run again after the 19 September stopOur old database ran out of its monthly allowance and stopped; Vallit now runs on a new one.
    • No database access over HTTPThe database's web interface answers no request for this app's tables.
  6. 1.6.30

    GitHub connects when the app is already installed

    Fixed

    • Connect GitHub with an existing installVallit asks you to sign in with GitHub first, so an account that already installed the app sees its repositories instead of GitHub's settings.
  7. 1.7.40

    The App, restructured

    Added

    • InboxOne list of everything that needs you across all apps: incidents, unconfirmed domains and low scores, worst first, with what Vallit is already fixing.
    • Apps in the sidebarEvery app with its status dot is one click away from any screen. The sidebar collapses to icons and remembers your choice.

    Improved

    • Home as a short noteA greeting, one sentence on how your apps are doing, the next action, your apps as rows and what Vallit did.
    • The app page, top to bottomHow the app is doing, what needs you, uptime, the guardian's log and the reports, with one main button.
    • A new look when signed inThe app, sign-in and sign-up use a warm ivory background, serif titles and a single column.
    • Settings and Billing on one page eachEach opens with a sentence on where you stand, then its sections; invoices are listed as rows.

    Fixed

    • The old Fixes addressThe former Fixes page now opens the inbox.
    • Sign-up errors in plain wordsA short password or a malformed email shows our own message instead of the browser's.
  8. 1.8.47

    Gaps no check knows yet, and the way to a released fix

    Added

    • Sampling switch on every app pageYou can let an AI reviewer look for problems no check covers yet, within the checks you already allowed, or leave your app out.
    • Fix pull requests, if you allow themA tested fix can arrive as a pull request on your connected repository. This is off until you switch it on.
    • New problems are fixed app by appWhen sampling finds a problem no check covers, we count the apps it affects and roll out its fix in stages.
  9. 1.9.48

    The code checks read only the app

    Fixed

    • Test and example code skippedThe code checks skip top-level test, example and benchmark folders, so findings come from the code your app actually runs.
  10. 1.10.54

    The report shows what it checked

    Added

    • What we checkedEvery report lists each question the checks asked of your website and your code, marked Safe, Found or Not run.
    • A seal for a clean reportWhen nothing was found anywhere, the report shows a drawn seal and one sentence saying so.

    Improved

    • Unconnected code is namedA report without a connected repository says the code was not checked, and the owner gets a link to connect it.
  11. 1.11.55

    Connect your DNS with its logo

    Added

    • DNS provider logosThe domain step shows Cloudflare, GoDaddy, IONOS, Vercel, Namecheap, Netlify, Strato and Hetzner, and preselects the one your domain uses.
    • One-click record setupYou press Continue, approve the record on your provider's page and come back with the domain confirmed.
    • Available provider by providerOne-click setup switches on for each DNS provider as soon as that provider has approved Vallit.

    Improved

    • Manual setup in three stepsEvery provider gets three short steps, a link to the right settings page and the record to copy.
    • Cloudflare token keptConnecting with a Cloudflare API token still works; it now sits folded away under the manual steps.
    • A clear result after approvingA cancelled or unfinished approval says so, and a record that is still spreading is checked again automatically.
  12. 1.12.56

    Your domain, right on Home

    Improved

    • Connect your DNS from HomeWhen your domain still needs its record, Home shows the DNS provider logos as the next step instead of sending you to the app page.
    • One name to typeThe record shows only the name your provider's form asks for, under that provider's label: Name, Host, Host name or Prefix.
  13. 1.13.60

    Follow the request · released 23 September 2026