Nine new checks for everything around your code: database rules, the libraries you install, keys left in your repository, and the domain your email and your customers trust.

Every check Vallit runs

Vallit runs 118 checks, from the address a visitor types to the repository behind the app. The nine marked new look at what your own code never shows: the rules in your database, the libraries you install, what sits in your repository, and the domain your email comes from.

  • New in 1.15
  • Checked from outside
  • Read in your code
  1. Your address

    • Up and answering
    • Certificate
    • Redirect to https
    • Search listing
    • Domain renewal (new in 1.15)
    • Email in your name (new in 1.15)
    • Forgotten subdomains (new in 1.15)
    • Outdated encryption
    • Claimable subdomains
  2. Your pages

    • Browser protections
    • Script policy strength
    • Cookie protection
    • Shared cache sign-ins
    • Insecure content
    • Password forms
    • Exposed keys
    • Libraries on your pages (new in 1.15)
    • Hijacked script hosts
    • Raw HTML
    • Unpinned outside files
    • Framework version
    • Messages between pages
    • SVG images
    • Forwarding links
  3. Left in public

    • Published config files
    • Backups and open folders
    • Development mode
    • Keys in links
    • Password files
    • Admin tools
    • Storage file lists
  4. Your API

    • Who may call your API
    • Cookies for other sites
    • Who can reach which data
    • Where money can leak
    • Who your app believes
    • Sign-in token keys
    • Guessable codes
    • Signature checks
    • GraphQL schema
    • Password guessing
    • Session keys
    • Session cookie settings
    • Server Action origins
    • Links that change data
    • Sign-in with other services
    • Token trust anchors
    • Private cache owners
  5. Your server

    • Server request forgery
    • Command injection
    • Path traversal
    • Unsafe redirects
    • Who can spend your AI budget
    • Scheduled jobs
    • Keys in responses
    • Code injection
    • AI tools
    • Certificate checks
    • Secrets in logs
    • Image optimizer
    • Webhook senders
    • Search patterns
    • Enforced webhook verification
    • Nested object writes
    • Archive destinations
  6. Your data

    • SQL injection
    • Database search commands
    • Database row security
    • Sign-up settings (new in 1.15)
    • File storage (new in 1.15)
    • Database rules (new in 1.15)
    • Firebase database
    • Firebase rules
    • Password storage
    • Encryption strength
    • Database views
    • Database functions
    • Rules on editable fields
    • Sign-in records
    • Anonymous uploads
  7. Your repository

    • Vulnerable libraries (new in 1.15)
    • Committed secrets (new in 1.15)
    • Keys named for the browser
    • GitHub Actions
    • Environment in the bundle
    • Published folder
    • Infrastructure state
    • Malicious action releases
    • A container is configured to run in privileged mode
    • A container is configured to share the host network
    • A container is configured to share host processes
    • A container is configured to share host communication channels
    • A container is configured to mount a host container-engine socket
    • A container is configured to mount the host filesystem root
    • A container is configured to request broad system administration
    • A container is configured to run without a seccomp filter
    • A container is configured to run without AppArmor confinement
    • A container explicitly requests the root account
    • An S3 policy grants public object reads
    • An S3 policy grants public object changes
    • An S3 bucket configuration enables a public ACL
    • A security group permits worldwide administration ingress
    • A security group permits worldwide database port ingress
    • An RDS configuration requests a public address
    • An RDS configuration disables storage encryption
    • An RDS configuration disables automated backups
    • An IAM policy configuration grants unrestricted actions
    • An IAM role trust policy allows any AWS principal
    • A workflow job requests every available write permission
    • Pull request code can run on a self-hosted runner
    • npm certificate validation is disabled in repository configuration
    • An npm registry is configured over plain HTTP
    • A remote workflow step uses a mutable reference
    • An EBS template explicitly requests no volume encryption
    • An ElastiCache template disables transport encryption
    • An ElastiCache template disables storage encryption
    • A CloudTrail template switches off trail recording
    • A CloudFront template permits plain HTTP requests

Nine new checks, one example each

Each one reads something a stranger can reach, or an attacker would look up first, and points at the exact line where it gives way. All of them only read: nothing is changed on your app.

supabase/migrations/20260114093000_todos.sql
create table public.todos (  id uuid primary key default gen_random_uuid(),  user_id uuid references auth.users not null,  title text not null);alter table public.todos enable row level security;create policy "Allow all" on public.todos  for all using (true) with check (true);

Where it gives way

HighRead in your code

Anyone can change or delete data without signing in

What can happen
A stranger rewrites or wipes every todo from their own browser, with the public key every visitor already has.
How to fix it
Replace the rule with owner rules: signed-in users, and only rows where auth.uid() matches user_id.

How well they did

The nine checks are new in 1.15, so we tested them before they shipped. Two writers who had never seen them built 54 cases each: apps with a real problem, and safe setups built to look like one.

real problems found
54 of 54
Across both blind sets, as the checks ship.
false alarms on 54 safe setups
0
Setups built to look like a problem without being one.
Each check, from the first blind run to what ships

The first run found 51 and raised 2 false alarms. The misses and the false alarms were fixed before release; both sets now guard against slipping back.

Problems found by each new check, first run and as shipped
CheckFirst runAs shipped
Database rules5 of 66 of 6
Sign-up settings6 of 66 of 6
File storage6 of 66 of 6
Vulnerable libraries6 of 66 of 6
Libraries on your pages5 of 66 of 6
Committed secrets6 of 62 false alarms6 of 6
Email in your name5 of 66 of 6
Domain renewal6 of 66 of 6
Forgotten subdomains6 of 66 of 6

What's in 1.15

14 changes in 1.15.68

Added

  • Sign-up settings checkFlags a Supabase project where anyone can sign up with an address they do not own, or get a session without an account.
  • File storage checkFlags Supabase storage that shows its bucket list to strangers, and which buckets are public.
  • Database rules checkReads your Supabase migrations and flags tables without row security and rules that let anyone change everyone's rows.
  • Vulnerable libraries checkLooks up the exact library versions your lockfile installs in a public vulnerability database, and flags packages known to be malicious.
  • Libraries on your pagesFlags libraries your pages load, such as jQuery or Bootstrap, whose stated version has a known flaw.
  • Committed secrets checkFlags secret keys and environment files written into your repository, naming the file and line, never the value.
  • Email in your nameFlags a domain whose SPF or DMARC records let others send email that claims to come from you.
  • Domain renewal checkWarns when your domain registration runs out within thirty days.
  • Forgotten subdomains checkFlags subdomains that still point at a cloud service that no longer exists, where anyone could take the name.
  • A page for this release/updates/1.15 shows every check on one map, an example for each new check, and how the new checks scored on two blind example sets.

Improved

  • What we checked has a fifth groupWhat your repository carries lists the library and secret checks when a repository is connected.
  • Only what a lookup needsLibrary lookups send a package name and version, domain lookups send the domain name, and nothing touches your app.
  • Platform addresses are left outApps on addresses like vercel.app skip the email and domain checks, because those records belong to the platform.

Fixed

  • Reduced motion shows the list at onceWith reduced motion switched on, What we checked and its seal appear at once instead of fading in over three seconds.

The road to 1.15

3 smaller updates shipped before 1.15, 23 September 2026. Everything in them is part of this release.

  1. 1.14.61

    A clearer update log

    Added

    • What's new in the footerEvery public page, the front page included, shows the newest release in its footer, with links to that release and to all updates.

    Improved

    • Updates as bulletsEvery change in the log is its own bullet: the change on the first line, what exactly happened beneath it, and no dash.
    • Every release since 1.0 rewrittenEach entry now names the new feature and what exactly changed, instead of a short slogan.
    • A lighter headerThe Updates link moved from the header to the footer, so the header fits on a 320 pixel wide phone.

    Fixed

    • The front page counts rightThe list of website checks no longer says five checks above eleven.
  2. 1.14.63

    Updates in the app, and version numbers that mean something

    Added

    • Updates popup in the appPressing the version bottom left in the sidebar shows the newest releases; the expand button opens the whole log.
    • Big updates open in fullA big update stands out in the popup and in the log and opens on its own page inside the app.
    • The same log on vallit.netEvery release is published so vallit.net/updates can list the same releases as the app.

    Improved

    • No footer in the appapp.vallit.net shows no footer; the Terms and Privacy links sit under the sign-in form once they exist.
    • Version numbers that mean somethingOnly a big update moves the middle number; every other change moves the last one.
  3. 1.14.65

    Help pages move to vallit.net

    Added

    • Help pages on vallit.net/docs, in preparationEvery screen of the app has its help page assigned, and the links appear in the app once the pages open.

    Improved

    • Help pages stay true to the appA change to a screen now updates its help page, with pictures and messages taken from the app itself.
  4. 1.15.68

    The whole perimeter · released 23 September 2026