Nine new checks for everything around your code: database rules, the libraries you install, keys left in your repository, and the domain your email and your customers trust.
Every check Vallit runs
Vallit runs 118 checks, from the address a visitor types to the repository behind the app. The nine marked new look at what your own code never shows: the rules in your database, the libraries you install, what sits in your repository, and the domain your email comes from.
New in 1.15
Checked from outside
Read in your code
Your address
Up and answering
Certificate
Redirect to https
Search listing
Domain renewal (new in 1.15)
Email in your name (new in 1.15)
Forgotten subdomains (new in 1.15)
Outdated encryption
Claimable subdomains
Your pages
Browser protections
Script policy strength
Cookie protection
Shared cache sign-ins
Insecure content
Password forms
Exposed keys
Libraries on your pages (new in 1.15)
Hijacked script hosts
Raw HTML
Unpinned outside files
Framework version
Messages between pages
SVG images
Forwarding links
Left in public
Published config files
Backups and open folders
Development mode
Keys in links
Password files
Admin tools
Storage file lists
Your API
Who may call your API
Cookies for other sites
Who can reach which data
Where money can leak
Who your app believes
Sign-in token keys
Guessable codes
Signature checks
GraphQL schema
Password guessing
Session keys
Session cookie settings
Server Action origins
Links that change data
Sign-in with other services
Token trust anchors
Private cache owners
Your server
Server request forgery
Command injection
Path traversal
Unsafe redirects
Who can spend your AI budget
Scheduled jobs
Keys in responses
Code injection
AI tools
Certificate checks
Secrets in logs
Image optimizer
Webhook senders
Search patterns
Enforced webhook verification
Nested object writes
Archive destinations
Your data
SQL injection
Database search commands
Database row security
Sign-up settings (new in 1.15)
File storage (new in 1.15)
Database rules (new in 1.15)
Firebase database
Firebase rules
Password storage
Encryption strength
Database views
Database functions
Rules on editable fields
Sign-in records
Anonymous uploads
Your repository
Vulnerable libraries (new in 1.15)
Committed secrets (new in 1.15)
Keys named for the browser
GitHub Actions
Environment in the bundle
Published folder
Infrastructure state
Malicious action releases
A container is configured to run in privileged mode
A container is configured to share the host network
A container is configured to share host processes
A container is configured to share host communication channels
A container is configured to mount a host container-engine socket
A container is configured to mount the host filesystem root
A container is configured to request broad system administration
A container is configured to run without a seccomp filter
A container is configured to run without AppArmor confinement
A container explicitly requests the root account
An S3 policy grants public object reads
An S3 policy grants public object changes
An S3 bucket configuration enables a public ACL
A security group permits worldwide administration ingress
A security group permits worldwide database port ingress
An RDS configuration requests a public address
An RDS configuration disables storage encryption
An RDS configuration disables automated backups
An IAM policy configuration grants unrestricted actions
An IAM role trust policy allows any AWS principal
A workflow job requests every available write permission
Pull request code can run on a self-hosted runner
npm certificate validation is disabled in repository configuration
An npm registry is configured over plain HTTP
A remote workflow step uses a mutable reference
An EBS template explicitly requests no volume encryption
An ElastiCache template disables transport encryption
An ElastiCache template disables storage encryption
A CloudTrail template switches off trail recording
A CloudFront template permits plain HTTP requests
Nine new checks, one example each
Each one reads something a stranger can reach, or an attacker would look up first, and points at the exact line where it gives way. All of them only read: nothing is changed on your app.
Data
Libraries
Repository
Domain and email
supabase/migrations/20260114093000_todos.sql
create table public.todos ( id uuid primary key default gen_random_uuid(), user_id uuid references auth.users not null, title text not null);alter table public.todos enable row level security;create policy "Allow all" on public.todos for all using (true) with check (true);
Where it gives way
HighRead in your code
Anyone can change or delete data without signing in
What can happen
A stranger rewrites or wipes every todo from their own browser, with the public key every visitor already has.
How to fix it
Replace the rule with owner rules: signed-in users, and only rows where auth.uid() matches user_id.
How well they did
The nine checks are new in 1.15, so we tested them before they shipped. Two writers who had never seen them built 54 cases each: apps with a real problem, and safe setups built to look like one.
real problems found
54 of 54
Across both blind sets, as the checks ship.
false alarms on 54 safe setups
0
Setups built to look like a problem without being one.
Each check, from the first blind run to what ships
The first run found 51 and raised 2 false alarms. The misses and the false alarms were fixed before release; both sets now guard against slipping back.
Problems found by each new check, first run and as shipped
Check
First run
As shipped
Database rules
5 of 6
6 of 6
Sign-up settings
6 of 6
6 of 6
File storage
6 of 6
6 of 6
Vulnerable libraries
6 of 6
6 of 6
Libraries on your pages
5 of 6
6 of 6
Committed secrets
6 of 62 false alarms
6 of 6
Email in your name
5 of 6
6 of 6
Domain renewal
6 of 6
6 of 6
Forgotten subdomains
6 of 6
6 of 6
What's in 1.15
14 changes in 1.15.68
Added
Sign-up settings checkFlags a Supabase project where anyone can sign up with an address they do not own, or get a session without an account.
File storage checkFlags Supabase storage that shows its bucket list to strangers, and which buckets are public.
Database rules checkReads your Supabase migrations and flags tables without row security and rules that let anyone change everyone's rows.
Vulnerable libraries checkLooks up the exact library versions your lockfile installs in a public vulnerability database, and flags packages known to be malicious.
Libraries on your pagesFlags libraries your pages load, such as jQuery or Bootstrap, whose stated version has a known flaw.
Committed secrets checkFlags secret keys and environment files written into your repository, naming the file and line, never the value.
Email in your nameFlags a domain whose SPF or DMARC records let others send email that claims to come from you.
Domain renewal checkWarns when your domain registration runs out within thirty days.
Forgotten subdomains checkFlags subdomains that still point at a cloud service that no longer exists, where anyone could take the name.
A page for this release/updates/1.15 shows every check on one map, an example for each new check, and how the new checks scored on two blind example sets.
Improved
What we checked has a fifth groupWhat your repository carries lists the library and secret checks when a repository is connected.
Only what a lookup needsLibrary lookups send a package name and version, domain lookups send the domain name, and nothing touches your app.
Platform addresses are left outApps on addresses like vercel.app skip the email and domain checks, because those records belong to the platform.
Fixed
Reduced motion shows the list at onceWith reduced motion switched on, What we checked and its seal appear at once instead of fading in over three seconds.
The road to 1.15
3 smaller updates shipped before 1.15, 23 September 2026. Everything in them is part of this release.
What's new in the footerEvery public page, the front page included, shows the newest release in its footer, with links to that release and to all updates.
Improved
Updates as bulletsEvery change in the log is its own bullet: the change on the first line, what exactly happened beneath it, and no dash.
Every release since 1.0 rewrittenEach entry now names the new feature and what exactly changed, instead of a short slogan.
A lighter headerThe Updates link moved from the header to the footer, so the header fits on a 320 pixel wide phone.
Fixed
The front page counts rightThe list of website checks no longer says five checks above eleven.