In the making23 September to 9 October 2026

The next release

118 updates have shipped since 1.15, The whole perimeter. All of it goes into the next big release.

So far

Oldest first. Every update is live in the app.

  1. 1.15.73

    Who your app believes

    Added

    • Admin rights from editable profilesFlags code that picks admins or paid plans from profile data users can change themselves, such as Supabase user_metadata or Clerk unsafeMetadata.
    • Sign-ins nobody checksFlags server code that trusts getSession() or a self-decoded token and then skips row-level security, so a made-up cookie could pose as anyone.
    • Fake sign-in eventsFlags Clerk webhooks that create, change or delete users in your database without checking Clerk's signature.
    • Strangers on your AI billFlags endpoints that send what a visitor types to a paid AI model with no sign-in and no rate limit.
    • The browser picks the modelFlags AI calls where the request chooses the model or the maximum answer length.
    • A fix kit for eachEvery new finding comes with steps for Supabase, Clerk and hand-built sign-ins, code to copy, and a way to test the fix.

    Improved

    • Report lines for the new checksA report that ran the code checks now says in plain words when none of the five problems was found.
    • The answer card names its checkOn a phone, the card under a release map names the check it answers. The 1.15 map shows the two new code checks.
    • Pages and middleware are read tooThe new checks also follow Server Component pages, Next.js middleware and tRPC procedure middleware, and apps whose only server code is their Supabase migrations.

    Fixed

    • Clerk's default middleware is understoodRoutes protected with the matcher from Clerk's setup guide now count as protected in the access check.
  2. 1.15.77

    A cover for the whole perimeter

    Improved

    • The 1.15 page opens full screenA lighthouse ringing its island in light fills the first screen, with the title and numbered links to each section on it.
    • The lighthouse lights the pageThe page opens at night, the lantern comes on and its light spreads over the whole picture before the title appears.
    • Sharp on every screenThe picture comes in five widths up to 3840 pixels, and a phone held upright gets a tall version of its own.
    • Calm when you scrollThe picture drifts a little slower than the page and the title fades. With reduced motion switched on, both stay still.
    • Inside the app tooThe page opened from What's new shows the same picture as a card beside the sidebar.
    • Shared links show the lighthouseA link to the 1.15 page shows the new picture.
    • Big releases open on their covervallit.net/updates shows each big release with its opening sentence and its picture, the lighthouse for 1.15.
    • Examples in one rowOn both release pages the examples sit in one numbered row with a line under the one shown. A phone scrolls the row sideways.
    • Clearer benchmarksThe page now says the nine checks are new in 1.15. Two numbers show their blind test: 54 of 54 found, no false alarm.
    • The 1.15 story on vallit.netvallit.net shows the same check map, examples and numbers as the 1.15 page.
  3. 1.15.79

    A calmer app, every building block polished

    Added

    • A six cell code fieldThe sign-in code lands digit by digit, shakes once when refused and turns ink when accepted.
    • Graphs for the guardian's numbersA sparkline, a score gauge, a 90 day uptime strip, a change chip and labelled bars.
    • One choice among a fewA row of options shows one ink chip that slides to your choice.
    • Cards with visible partsAn icon tile, facts beside the name and a metric row instead of an explaining sentence.
    • Exact values in every graphPoint at a line, a day, a bar or a score, or move there with the keyboard, and a small bubble shows the value.

    Improved

    • app.vallit.net opens the appThe front page with the free check is gone. Signed in you land on your apps, otherwise on sign-up.
    • Page titles in a serif faceEvery screen opens with a calm serif title and no grey line beneath it.
    • Buttons show they are workingThe icon turns and the label changes in place, and the keyboard stays on the button.
    • Copying shows it workedThe button gives, a check draws and a small Copied bubble appears next to it.
    • Newer screens match the restThe DNS panel and the update log use the same buttons, ticks and titles.
    • Every app state keeps its colourAn app that needs you is orange, one waiting for its domain amber, everywhere it is named.
    • Home rows lead with the stateThe address follows in its own face and shortens first on a phone.
    • Numbers roll into placeScores count up when you arrive from Home.
    • The address field says what it isThe scheme is a fixed part and a mark appears once it reads as an address.
    • Alerts say one lineBilling, Connect and the DNS panel lead with the fact and one button.
    • Empty states are drawnA mark, a short title and one action.
    • The first week lives in the inboxGetting started lists the open steps; the floating setup guide is gone.
    • Incidents say what was measuredEach open incident shows the answer the check got and when it last passed, right under the app's name.
    • The alerts switch saves when you flip itNo separate Save press, and a refused address puts the switch back.
    • The inbox opens the reportSee the report leads to the report itself, not to the app page.

    Fixed

    • Scroll bars stay inside their boxThe thumb shows how much is left.
    • Disabled boxes look disabledThe box and its label fade together and no longer react to a press.
    • Status dots are easy to seeEach has a fine rim in its own colour.
    • Empty boxes and off switches stand outBoth have a clear grey edge.
    • Menus line up with their fieldA select's options start where the field's text starts.
    • Dialogs keep the keyboard insideTab stays in the dialog, and a double click no longer closes it again.
    • Back returns to the previous sign-in stepThe address you typed stays.
    • Pressed toggles fill their cornersNo sliver of the page shows between the fill and the rounded edge.
    • Values stay inside their barsA number that does not fit a short bar sits beside it instead of spilling out.
    • Copy buttons are easy to tapOn a phone they grow to a full finger size.
    • A skipped check is not a fixA finding whose check did not run today no longer shows up as fixed, in the app or by email.
    • Promises match your planWithout a plan, no screen promises the five minute watch that only a plan brings.
    • Companies on Free see the plansA report no longer offers a fix request that a company on Free cannot send.
    • Back returns where you wereAfter a jump within a page, the browser's Back button leads to the page you came from.
    • Addresses that are not apps are refusedAn email address or a private network address gets a clear message instead of a failed check.
  4. 1.15.80

    The free check starts on vallit.net

    Added

    • A check without an account, from vallit.netEnter the address on the homepage, tick that the app is yours, and the report opens straight away.
    • A plan step after sign-upFree sits beside Starter and Standard, and Continue free opens your first app.
    • A page for a refused checkapp.vallit.net/check keeps the address you typed and names the reason.

    Improved

    • Unclaimed reports show their shape, not their detailsScore, verdict, severity and kind stay; titles, evidence and fixes open after you take the report over.
    • Take over only where it can workReports that already belong to a company no longer offer it.
  5. 1.15.81

    Copying you can see

    Improved

    • The copy mark acts out the copyUnder every press its front sheet slides off the one behind it, then it turns into a check once the copy landed.
    • The copied record value lights upIn the DNS record table the value you copied washes green, and no bubble covers it anymore.
    • Pop-ups share the app's warm coloursMenus, hints, the update popup and the phone menu now sit on the same ivory as the pages.
    • One way to the full update logThe update popup keeps its expand button, and a big update shows one Open in full cue.

    Fixed

    • Copying works where the browser blocks itVallit then copies another way. If nothing works, you see Not copied, and a DNS value is selected for your keyboard.
    • The button's name stays until Copied replaces itPressing a copy button no longer blinks its hint away first.
    • Escape closes the update popup at onceOne press is enough, also after tabbing onto its expand button.
    • The update popup fits the phone menuIt no longer spills past the menu onto the page behind it.
  6. 1.15.82

    Form hints in Vallit's own look

    Improved

    • Missing answers get a Vallit hintA card in the app's colours replaces the browser's grey bubble and leaves once you answer.
  7. 1.15.91

    A report you can follow, and a page you can show

    Added

    • A trust page for each appPublish a record of what Vallit tested and passed, grouped by area, with the daily checks behind it, and send its link to buyers.
    • A badge for your own siteIt shows the date of the record and links to the trust page.
    • A picture in every findingWhere we saw it, drawn as the place itself, and what it lets someone do in three steps.
    • What happens from hereThe end of your report shows what you have, what a plan and connected code add, and how a fix reaches your code.

    Improved

    • Reading your code is part of a planThe free check looks at your website only; on a plan, a connected repository is read at every check.
    • The report lives in your appThe findings are the app page's main column, in the app's own look; the share link still opens a document for others.
    • The app page on one screenA band shows score, findings, uptime and the guardian; findings fill the left, with trust page, reports and settings beside them. No tabs.
    • Every page in the app uses the widthHome, Inbox, Settings and Billing now have the work on the left and short cards on the right.
    • Less textThe lines under titles are gone; explanations live in the docs.
    • How we fix it, in three tilesWhat you have, what a plan adds and what GitHub adds, each with its button.
    • A finding glides into viewOpening one, or clicking a count at the top, scrolls smoothly to its details; the fix steps open on request.
    • A calmer findingOne line on what it is, the pictures side by side, what could happen, then one fix card: Fix it yourself or We fix it.
    • What a plan would also checkWithout a plan, four code questions show as Not checked, the rest blurred below, with the reason at the end.
    • The report starts in plain wordsThree lines say what we checked, what to do now and who can read the page.
    • Severity reads as a timeCritical means today, high this week, medium this month, low when convenient.
    • Fix it yourself, free on every planThe fix kit says so, and without a plan the finding offers to have us do it.
    • Free and paid, side by sideA report still locked names what signing up, a plan and connected code each add.
  8. 1.15.92

    The right password length

    Fixed

    • Sign-up names the real password lengthA password that is too short now tells you the minimum Vallit actually asks for, instead of always saying eight characters.
    • A very long password gets a clear answerYou now read that it is too long and should be shorter.
  9. 1.15.94

    Big releases stay big

    Fixed

    • 1.16 is an ordinary update againThe report and trust page updates now read 1.15.91 and 1.15.92; the next big release gets its own name and page.
  10. 1.15.96

    The app fills big screens

    Improved

    • The app grows with big screensOn monitors wider than 1680 px, like 4K at 100 %, text and spacing grow up to twice their size; smaller screens stay unchanged.
  11. 1.15.97

    Your account and your company, in Vallit

    Added

    • An Account pageChange your name and photo, add and confirm email addresses, set your password, connect Google and sign out other devices, all in Vallit's own look.
    • A page for your companyRename it, invite people as Member or Admin, change roles, and withdraw or resend invitations that are still waiting.
    • Leaving and deleting, with careDeleting your account or a company asks you to press and hold, and a company also asks for its name first.

    Improved

    • One account menuThe row with your name opens Account, your company and Alerts, lists your other companies and invitations, and signs you out.
    • Settings shows who and whereBeside the alerts, two cards name the company, your role, its people and your sign-in address, each with the way to its page.
    • A company always keeps an adminThe last admin cannot be made a member, removed, leave or delete their account until someone else is an admin.
    • Everything in Vallit's own lookCreating a company and confirming it is you before a sensitive change open Vallit's own windows.
    • A paid plan is ended firstA company whose plan still charges cannot be deleted until the plan is ended on Billing.
  12. 1.15.99

    Sign-in buttons in full colour

    Fixed

    • Sign-in buttons keep their colour while loadingThe Google, Apple and email buttons no longer look greyed out for a moment before sign-in is ready.
  13. 1.15.100

    Twenty new security checks

    Added

    • Nine new checks on your websiteDevelopment servers left running, hijacked script hosts, http without a switch to https, forms that leak passwords, and keys written into links.
    • More of them look deeperA Content Security Policy that lets scripts run, sign-ins a shared cache may keep, GraphQL that describes itself, and open Firebase databases.
    • Three new checks on your repositoryPrivate keys with a browser prefix, Firebase rules open to everyone, and GitHub workflows outsiders can steer.
    • Eight new checks on your codeUnguarded scheduled jobs, weak sign-in token keys, endpoints that send back your keys, and APIs any website can use as your users.
    • And four more in your codeReadable passwords, leaky signature checks, guessable access codes, and outside text shown as HTML. A model reads each finding first.
    • A fix kit for every new findingEach one says what to change and how to check it worked.
    • The trust page lists the new checksEach area shows one line for what passed.

    Improved

    • Fewer false alarms on your websiteA missing Referrer-Policy, placeholder keys, a library's source map on a CDN and cookies merely containing "sid" are no longer reported.
    • More found on your websiteThe API check also asks your subdomains and versioned paths, and stylesheet links count in any attribute order.
    • Request checks follow more of your codeClasses, helpers, HTTP clients made with axios.create, URLs on a fixed base, and shell commands run through sh -c or execa.
    • Code reviews are asked onceA model's verdict on unchanged code is kept for 30 days instead of being asked for again every day.

    Fixed

    • No policy is not a strong policyThe report no longer marks the Content Security Policy check as passed when there is no policy at all.
  14. 1.15.102

    Every check finishes or says why

    Improved

    • Waiting, not failedBefore the domain is confirmed, the targeted checks read Waiting, sit together at the end of the list and no longer count as checks that ran.
    • One click to confirmSigned in, Confirm the domain sits right under the waiting checks and opens the app page where you confirm it.
    • The same word while a check runsIn the progress list, a check held for the domain reads waiting, not could not complete; one still to come reads queued.
    • Code checks read deep code to the endLong chains of helpers and functions that call themselves no longer leave a check incomplete.

    Fixed

    • A stopped check no longer looks busyWhen a check is stopped, its unfinished parts are closed too instead of showing as running.
    • Report links show their preview againA finished report's link shows its score and verdict when you paste it into a chat; the picture had failed to load.
    • No clean verdict for an unfinished checkA report nobody has taken over no longer says every check came back clean when some did not finish.
    • The running check keeps its row shortWhile a check runs, its row in the progress list is as tall as the others.
  15. 1.15.103

    The top of a report agrees with the rest

    Fixed

    • One count of code checksThe top of a report, its next steps and the sign-up box now count the code checks as What we checked lists them.
    • Reading code, said the same wayWhere reading code is off, or your plan still needs your repository, the top of a report now says what the list below says.
    • A shared report with nothing openIts next step says nothing needs fixing, and it asks to keep the link among the people who look after the app.
    • Unfinished checks are not called doneWhen some checks did not finish, the top of a report now says so instead of calling the report done.
  16. 1.15.104

    Partial until every check has run

    Improved

    • Partial, not GoodWhile some checks wait for the domain or did not finish, the score reads Partial in grey instead of Good. Fair, Poor and Critical stay.
    • Partly checked, not HealthyHome, the sidebar and the app page say Partly checked until a report with every check scores well.
    • The reason stays in viewWith a small finding too, the verdict under the score says why some checks are missing.
    • Not all quietWhile an app is partly checked, the next step on Home opens its report instead of saying all quiet.
    • No second request to confirmOnce the domain is confirmed, a report's waiting checks say the next check runs them.

    Fixed

    • The picture of an unfinished checkA shared link to a check that did not finish says so instead of showing a score.
  17. 1.15.105

    Healthy means good

    Improved

    • Healthy from 85An app is Healthy only from the score its report calls Good. From 80 to 84 it needs attention and shows in the inbox.
  18. 1.15.106

    Your app at a glance

    Added

    • Every check in one tableThe app page lists recent checks with who ran them, the score, how it moved and what each left open. A row opens its report.
    • How the score movedFrom three checks on, a line shows the score over time, with what each check left open when you point at it.
    • Who looked at your trust pageThe trust page card shows the last visit and the visits of the week and the month, counted without anything personal.
    • Trust pages in SettingsEvery app's trust page in one place, with its visits, the link, the badge and whether search engines may list it.

    Improved

    • What needs you comes firstIncidents, confirming your domain and the worst findings sit in one list under the score; the domain step opens when you ask for it.
    • Reports open as a listNo finding is unfolded until you open it, or follow a link to one.
    • One score everywhereThe app page, the table and the chart show the score the report itself shows.
    • An open incident is said firstWhile one is open, the score stays grey and the sentence under it points to the incident.

    Fixed

    • Only admins change a trust pagePublishing, taking it down and the search setting are refused for members, also on the server.
  19. 1.15.107

    No alarms from development tools

    Improved

    • Development routes stay quietA route that answers 404 in production, such as a design preview, is no longer read by the code checks.
  20. 1.15.108

    A finding says it once

    Improved

    • One picture per findingAn opened finding shows where we saw it and then what could happen, once; the three steps of what someone could do with it are gone.
    • No certainty labelsFindings no longer carry a Likely or Possible label. What we saw and the evidence stay as they were.
  21. 1.15.109

    Vallit passes its own check

    Fixed

    • The app now blocks injected scriptsEvery page sends a Content Security Policy, so a script slipped into a page does not run. Vallit's own check found it missing.
  22. 1.15.110

    We read the code behind a finding

    Improved

    • Fixes start from your codeWhen you ask us to fix a finding in your code, we read the lines around it in your repository, as the check read them.
    • You see when we read itYour activity says when a person at Vallit read the code behind a finding. Committed keys and environment files are never opened.
  23. 1.15.111

    See whether we can open a pull request

    Added

    • Pull requests, as GitHub allows themThe code page says whether Vallit may open pull requests on your repository, and leads to GitHub when a permission is still missing.
    • Asked when you ask usOnce fixes arrive as pull requests, asking for a fix in your code says where it will land, or what is missing.
  24. 1.15.112

    Fewer false alarms from the code check

    Fixed

    • Guarded outgoing requests are no longer reportedA request that checks every address it connects to no longer counts as one that could reach your internal network.
    • Actions are no longer taken for sign-in webhooksCode that builds a sign-in event itself from your sign-in provider no longer shows up as accepting fake sign-in events.
    • Checks never reach inside our networkAn internal address written as IPv6, such as [::ffff:7f00:1], is refused like any other.
  25. 1.15.113

    Fixes as pull requests

    Added

    • Fixes arrive as pull requestsWhen we fix a finding in your code, it comes as a pull request from Vallit, checked by the same check that found it.
    • You follow every fixYour activity says when we opened the pull request, and again when you merged or closed it.
  26. 1.15.114

    A tighter database

    Fixed

    • Database helpers look only where they shouldEvery function in our database now names exactly where it looks things up, so it cannot be led to look elsewhere.
  27. 1.15.115

    Checked again before we act

    Added

    • We check again before working on a findingWhen we open a finding, the same check runs again on your code or live app first.
    • Told as soon as it is goneIf that check no longer finds it, the finding closes as fixed and you hear so in your activity and by email.

    Improved

    • A fix you asked for closes by itselfWhen the daily check no longer finds it, your fix request closes and you get an email, whatever its severity.
  28. 1.15.117

    One sky for every email

    Added

    • Every email opens with a skyEach kind has its own: dawn for reports, a storm for an incident, light breaking through when fixed, the moon for your account.
    • Sign-in and account emails in the same designCodes, sign-in links, invitations, new device, password, passkey and locked account emails now look and read like every other Vallit email.
    • The incident email links to your appA button opens the app's page in Vallit.

    Improved

    • You can see where a link goesUnder every button sits its full address.
    • Every email says what Vallit never asks forThe last line: never your password, a sign-in code or payment details.
    • New findings read at a glanceThe daily email lists each finding in its own row, severity first, and calls it a finding, not an incident.
    • A report that needs attention says soIts label reads Needs attention instead of Notice.
  29. 1.15.121

    28 new checks, and fixes we write without AI

    Added

    • 28 new checksYour website is now also checked for outdated encryption, unpinned library files, flawed framework versions, open admin tools and password files, listable storage and claimable subdomains.
    • More code checksWe look for AI tools a prompt can steer, unlimited password guessing, request text run as code, weak encryption, secrets in logs and weak session cookies.
    • Your database and settings, deeperSupabase views, functions and upload rules, Next.js image and action settings, keys in published folders, infrastructure state and workflow actions known to be malicious.
    • 29 more kinds of keysKeys from Groq, Hugging Face, OpenRouter, Resend, Supabase, Sentry, Shopify, GitLab and more, and database addresses with a password, are now recognised.
    • Fixes we write without AIFor mechanical fixes, we write the change ourselves and open the pull request only after the same check passes and nothing new turns up.
    • What could happen, in four answersEvery finding now says who can do it, how far it reaches, what it takes and what is at stake.

    Improved

    • Fewer blind spots in your codeData passed on with .then, Auth.js credential sign-in and AI tools on raw OpenAI, Anthropic or Gemini replies are now followed.
    • Storage in every regionBuckets outside the United States are now asked in their own region, so an open one is not missed.

    Fixed

    • Fixes to workflows and migrations are checked tooBefore its pull request opens, a fix to a workflow, migration or settings file is checked by running its check again.
  30. 1.15.123

    Six checks for attacks that ride on your signed-in users

    Added

    • Links that change dataYour code is checked for addresses that change or delete a signed-in user's data when they only follow a link from another site.
    • Search commands in MongoDB queriesRequests that send your database a search command instead of a value, such as signing in without the password, are now found.
    • Sign-in with other servicesYour own "Sign in with" and "Connect your account" callbacks are checked for the state check that stops another site finishing them.
    • Webhooks that trust anyoneWebhooks from GitHub, Shopify, Resend, Twilio and others that act without checking the sender's signature are now found.
    • Search patterns from search boxesText someone types that becomes a pattern your server runs, which one request can use to stall it, is now found.
    • Links that forward anywhereYour live site is checked for links that send visitors on to any other website, proven by your app's own answer.

    Improved

    • More MongoDB queries are followedQueries built with the MongoDB driver and then sorted or limited, and request bodies read with a fallback, are now read like any other.

    Fixed

    • Code findings are reviewed against their ruleFindings of eight code checks from 1.15.121 were read again without the rule's description. The reviewer now has it for every check.
  31. 1.15.124

    Fewer false alarms on real apps

    Fixed

    • Example apps and command-line tools are left outNo more findings from example apps, test scripts or commands that print a password they just created for whoever runs them.
    • Choices your team made on purpose stay quietA setting that allows your own server's self-signed certificate, or a cookie that only remembers the theme, is no longer reported.
    • Changing your own password is not a sign-inConfirming your current password before changing it no longer counts as unlimited password guessing.
    • Sign-in libraries are recognisedA token request inside your Auth.js or Better Auth setup no longer looks like a sign-in callback of your own.
  32. 1.15.126

    Priced per app: Watch, Care and the Fix

    Added

    • Watch, €29 an app a monthEvery check on site, repository and code, uptime every five minutes on a confirmed domain, and the trust page and badge.
    • Care, €99 an app a monthEverything in Watch, and a person at Vallit fixes what we find, five fixes a month per app.
    • Mix plans per appA company can put some apps on Watch and others on Care, and choose on Billing which app is on Care.
    • Ten apps and more cost lessFrom ten apps in a company every app costs 30 % less: Watch €19, Care €69.
    • Pay yearly, two months freeEvery plan can be paid by the year for the price of ten months.
    • Try Watch for 14 daysA first Watch plan starts with 14 free days; the card is taken at the start and charged when they end.
    • Fix it for €99On any plan, a person at Vallit fixes one finding for €99, paid on its own. The request is filed once the payment arrives.

    Improved

    • Billing shows what you pay forThe plan reads as the apps on it, with the price per month or year, the trial end and how many fixes are included.
    • Your plan covers every appAn order has to cover all the apps in the company, so no app is watched without being paid for.
  33. 1.15.128

    Every code finding gets the full review

    Fixed

    • Every code finding gets the full reviewA fast first pass that set some findings aside had missed real ones in our tests. It now only takes notes.
  34. 1.15.129

    Payments that cannot get lost or charged twice

    Fixed

    • A payment always reaches your planIf saving a Stripe payment fails, Stripe sends it again until it is saved, so no paid plan or Fix goes missing.
    • A renewal or cancellation always finds your companyThis holds even if the first confirmation from Stripe never arrived.
    • No Fix is paid twicePaying €99 for a finding that was already asked about, or paying twice for the same one, is refunded automatically.
    • One payment page per companyOpening a plan order in a second tab closes the older page, so two subscriptions can never run at once.
    • Care's included fixes are never soldWhile your app has included fixes left this month, the €99 Fix cannot be charged.
  35. 1.15.130

    Sign-in emails from Vallit

    Fixed

    • Sign-in and account emails arrive in our designCodes, links, invitations and account notices now come from Vallit itself, like every other email.

    Improved

    • Failed sign-in emails are sent againIf sending a sign-in email fails, it is retried instead of lost.
  36. 1.15.131

    A protocol probe is not a forged certificate

    Fixed

    • A protocol probe is not reportedThe certificate check leaves alone a TLS socket that only learns how the handshake went, then closes without sending or reading.
  37. 1.15.132

    Our own status page

    Added

    • A status page of our ownapp.vallit.net/status shows whether every part of Vallit works right now, each part with ninety days behind it.
    • Every part checked once a minuteFrom our own servers every minute, and from outside every five minutes, so even a Vallit that is down entirely is noticed.
    • Errors seen the moment they happenA page or request that fails is recorded right away and becomes an incident within a minute.
    • We hear of it at onceA new incident alerts us right away, and the page says so while the work is under way.
  38. 1.15.133

    Calmer emails

    Improved

    • Every email reads like a letterA white page, the sky fading into it, one column of text and a sign-off.
    • No more status labelsThe sky and the heading say what kind of email it is.
    • A new sky for account emailsSign-in codes and account notices open under a calm blue-hour sky.

    Fixed

    • The code email says how long it lastsWhen the minutes are not known it says the code expires soon, instead of leaving a gap.
  39. 1.15.134

    Fresh pictures in every inbox

    Fixed

    • New email pictures show up everywhereMail apps kept the old pictures under their old addresses; every picture now carries a version.
  40. 1.15.135

    Plan changes charged fairly, and a billing page that says so

    Fixed

    • A bigger plan is charged at onceMore apps, Care or yearly are invoiced right away; a smaller plan leaves the unused part as a credit on your next invoice.
    • Switching to yearly starts the year todayThe year is charged now, with the unused part of the month taken off.
    • Cancelling in the billing portal showsYour plan card says the day the plan ends instead of when it renews, and choosing a plan withdraws the cancellation.
    • A report names the app's own planA Watch app in a company that also pays for Care reads Watch, not Care.
    • Portfolio prices said as pricesFrom 10 apps Watch costs €19 and Care €69 per app, instead of one percentage that was wrong for Watch.
    • Included fixes count across the company tooFive a month per Care app paid for, however the Care place moves between apps.
    • App counts take whole numbers onlyA minus sign or a decimal is refused with a reason, and an order stays within 500 apps in total.
    • A new payment page after a finished oneBuying the same plan again within a day opens a fresh page, never a finished one.
    • A finding keeps its placeAsking for a fix no longer moves it within the list.

    Improved

    • What is charged today, before you confirmStripe's own figure, with any credit on your account spent first, and a trial that Care ends now said too.
    • Keep a plan you cancelledWhile a cancellation is pending, Keep my plan withdraws it from the billing page.
    • Payment for a Fix confirmedBack from paying, the report says the payment arrived, only for a payment that is really yours.
    • Care apps are chosen with ticksNothing moves until you save, each box is named for screen readers, and a newer app never takes a Care place.
    • Paid for and in useYour plan card shows both counts of apps, on the free check too, and on a phone it comes first.
    • The free check after a planOnce a plan has ended, the card shows the free check as current and says when the plan ended.
    • Credits read as creditsA credit from a smaller plan is listed as a credit, not as a negative payment.
  41. 1.15.136

    The way to our status page

    Improved

    • The Vallit mark leads homeOn the status page, the update log and every other public page, the mark opens vallit.net.
    • Vallit status in your account menuThe menu at the bottom of the sidebar opens our status page in a new tab.

    Fixed

    • Every background job shows on the status pageA job run that has nothing to do now counts as a run, so it no longer waits forever.
  42. 1.15.137

    No alarm for pages that only look the part

    Fixed

    • Pages that quote a key are not keysPrivate keys, WordPress configuration copies and the Subversion folder count only as the raw file, not as an HTML page quoting one.
    • Placeholder passwords are not reportedSaved Git logins, WordPress configuration copies and appsettings.json that hold only a value such as changeme or your_password no longer raise an alarm.
    • pgAdmin and phpinfo() need their own pageA page only titled like either tool is not reported; it takes pgAdmin’s login page or the settings table phpinfo() prints.
  43. 1.15.138

    Large apps are read to the end

    Improved

    • Large apps are read to the endCode too large to follow is skipped, the rest of the route is read, and only checks that code concerns stay unfinished.

    Fixed

    • Skipped code hides no problem after itThe code read afterwards counts on the skipped part having put your request's data anywhere it could reach.
    • A database handed to skipped code countsA client or function passed into the skipped part marks the checks it concerns as unfinished.
  44. 1.15.139

    A site with no server is not "Partial"

    Fixed

    • A front-end-only repository reads as checkedWith no server code, the request checks have nothing to follow, so they count as run and the report is not Partial.
    • Unread servers say whyWhen the server is written in another language, such as Python, the code checks say that language is not read yet.
  45. 1.15.140

    A billing page that tells the order, Free per app, and every fix on Care

    Added

    • Free for any app, beside paid onesEach app goes on Free, Watch or Care. A Free app keeps its daily check; up to 10 stay Free beside a plan.
    • The order told as it is madeThree steps on a rail: a plan per app, monthly or yearly as twelve months, then a receipt with what is charged today.
    • Compare plans on the lanesUnder your apps, one row per feature shows what Free, Watch and Care give each app, in the lanes themselves.

    Improved

    • Care includes every fixWe fix every problem our checks find, with no monthly number. A job over two hours we agree with you first.
    • Places for apps you add laterBuy Watch or Care places ahead; the next apps you add take them.

    Fixed

    • A Free app is treated as Free everywhereThe five-minute watch, reading the code and included fixes follow each app's own plan, not the company's.
  46. 1.15.141

    No verdict on a challenge page

    Fixed

    • Bot protection is not judged as your appWhen a firewall answers with a challenge, the page checks show Not run and the report reads Partial, with no false findings.
    • Vercel's firewall is recognisedIts challenge answer names itself, so the checks now know it is not your app.
  47. 1.15.145

    Tear off your copy

    Added

    • Tear off your copyOnce Stripe confirms the payment, drag the receipt's Today part down, or press Enter. It comes off stamped Paid or Started.
    • A tap tears it tooA click, a tap or a screen reader takes the copy off whole; before the payment the page scrolls over it as usual.

    Improved

    • The plan shows up by itselfBack from Stripe, or after a plan change, the page keeps asking until Stripe confirms, and says so after a minute.
    • Nothing to pay twiceWhile Stripe confirms a payment, the order shows no pay button, only that the page updates by itself.
  48. 1.15.146

    A free check promises only what it found

    Fixed

    • No fix promised for nothingA free check with nothing to fix no longer says each finding opens or that we fix them. It says what taking over brings.
    • Noted is not brokenWhen the check only noted things, the page says what we noted, not what we found.
    • No next check where none runsA check nobody has taken over reads "Nothing needs attention right now." without "We will keep checking".
    • Unfinished checks are not called cleanThe page says some checks did not finish and that you then see which ones.
  49. 1.15.147

    What runs on its own

    Added

    • See what runs on its ownA card on the app page names the checks that run daily, those that wait for Run a check, and those needing a plan.
    • Manual and Automatic in the report listEach check in an app's list now says whether you started it (Manual) or the daily guardian did (Automatic).

    Improved

    • Waiting checks say how to run them nowIn your own report, the checks held until the domain is confirmed tell you that Run a check runs them at once.

    Fixed

    • A busy run no longer skips a dayA full check that finds no time left is due again at the next pass, not a day later.
  50. 1.15.148

    Your fix request shows when we start

    Improved

    • Your fix request shows when we startWhen we start on your fix, your Inbox says it is picked up and being fixed.
  51. 1.15.149

    Where and how to fix wait for your domain

    Improved

    • Details of targeted checks wait for the domainTitle and severity show; the place and fix steps open once a DNS record proves the app is yours.
    • Confirming opens everythingThe card gives way to the picture, steps and fix kit on every report of the app, old ones too, with no new check.

    Fixed

    • No fix for what you cannot seeRequesting or paying for a hidden finding's fix asks you to confirm the domain first. Nothing is charged.
    • The scanner only readsA check's request is refused unless it is a GET, HEAD or OPTIONS.
  52. 1.15.151

    The whole daily check, before the DNS record

    Added

    • Every check from the first dayApps on Watch and Care run all 34 checks daily, before the DNS record is confirmed.

    Improved

    • Alerts say where details openA message about a hidden finding tells you to confirm the domain to see where it is.
    • The report stays lightThe card that stands in for hidden details no longer adds to the script every report loads.
    • One probe a day per domainHowever many companies add a domain, its unconfirmed apps are probed once a day.
  53. 1.15.152

    Every fix to your code is signed by one person

    Fixed

    • Each fix names the person behind itEvery read of your code and every pull request we open is recorded under the Vallit person who did it.
  54. 1.15.153

    Fewer false alarms about raw HTML

    Fixed

    • Sanitised HTML is no longer reported as rawThe raw HTML check follows sanitising helpers into your other packages and through React state.
    • Escaped and own text is left aloneCode highlighted by shiki or sugar-high, NodeBB templates that print values escaped, your own translations, bundled stylesheets and what visitors type themselves.
    • Style and template elements left aloneCSS your script writes into a style element, and markup kept in a template that never reaches the page, are not reported.
    • Real problems are still foundA template that prints a stored value raw, and a style block React renders on the server from outside text, are still reported.
  55. 1.15.154

    One finding for a webhook that trusts anyone

    Fixed

    • An unchecked webhook is reported onceA webhook router mounted elsewhere, such as Shopify's at /webhooks/shopify, was also reported as data anyone can change. Now it is one finding.
  56. 1.15.156

    Emails get through a hanging connection

    Fixed

    • One slow answer is not an outageWhen email, payments, sign-in or GitHub answers too slowly, the status check asks again before it reports the service down.
    • Emails go out when the first try hangsAlerts, reports and sign-in codes are sent once more if the first try gets no answer, and arrive only once.
  57. 1.15.159

    A busy host no longer costs a day

    Fixed

    • A skipped daily check tries againIf another check of the same address ran in the last hour, your daily check runs minutes later, not a day later.
  58. 1.15.164

    Files that miss the header your homepage has

    Added

    • Files that lack your homepage's headerA new check names the first upload, download or script sent without the header your homepage has. It stays off until released.

    Improved

    • Where we saw it names the fileFor this check the report shows the address of the file without the header, not your homepage, which already has it.
    • Long addresses wrap on a phoneA finding that names a long address now wraps it instead of cutting it off.

    Fixed

    • Fix steps are easy to tapOn a phone or tablet, Show the steps and Read the reference are now full size touch targets.
  59. 1.15.165

    Code checks survive a heavy repository

    Fixed

    • A big repository keeps its code checksThe archive is unpacked as it arrives and only code is kept, so screenshots cannot push it over a limit.
    • A busy GitHub is asked againA server error, rate limit or dropped connection is tried up to three times, with a pause, before the code checks fail.
  60. 1.15.167

    A hardened workflow is no longer a false alarm

    Fixed

    • Code kept as data is left aloneA workflow that checks a pull request into its own folder and passes it only to trusted tools is no longer reported.
    • Running that folder is still reportedA step that works inside it, runs a file from it, builds it or uses it as a local action keeps the finding.
  61. 1.15.169

    Every app gets the same daily check

    Fixed

    • The daily check no longer depends on othersAn unconfirmed Watch or Care app on a shared domain always runs all 34 checks, whoever was checked first.

    Improved

    • No more waiting notice in the activityThe line that said the targeted checks wait until tomorrow is gone, since nothing waits any more.
  62. 1.15.170

    A dark look for the whole app

    Added

    • Dark mode, for every screenThe app, the report, the status page and sign in have a warm charcoal look beside the ivory one. Every colour keeps its meaning.
    • A choice of look in SettingsUnder Appearance, pick Light, Dark or Match device. It applies at once and is kept per browser.

    Improved

    • No flash on loadThe look is written on the page before it is drawn, so a dark page never starts light.
    • Shadows and layers follow the lookCards, menus and dialogs separate by lighter layers and soft edges in the dark, and the dimming behind a dialog is stronger.
  63. 1.15.171

    Our own files carry the header too

    Fixed

    • Files send the same header as pagesOur own scan found X-Content-Type-Options: nosniff on the homepage but not on the files under it. Every file now sends it.
  64. 1.15.172

    A passing hiccup no longer leaves a check unrun

    Fixed

    • A slow first answer is asked againWhen your homepage times out or a gateway answers for a moment, we ask once more before the page checks are skipped.
    • A silent lookup gets a second tryThe domain registry, DNS, certificate logs and the vulnerability database each get a second try before their check counts as not run.

    Improved

    • A check that did not run says whyOn a paid app with a confirmed domain, the report names the reason and what you do next.
  65. 1.15.173

    An incomplete check is run again

    Fixed

    • A partial check no longer waits a dayWhen checks did not run for a reason that can pass, the next pass runs them again, up to three times.
  66. 1.15.174

    A fix done another way still counts

    Fixed

    • A fix you made yourself countsIf you fixed it another way instead of merging our pull request, the app counts as fixed once a check no longer finds it.
  67. 1.15.175

    Automatic fixes for new kinds of findings

    Added

    • New kinds of findings get an automatic fixA finding from a check we built after sampling can now get its fix as a pull request on your repository.
  68. 1.15.179

    A work plan for your findings, for selected companies

    Added

    • A work plan keeps who owns a findingA person takes it on with a date, or accepts it for now. Only a finished check counts as fixed.
  69. 1.15.180

    Page health looks at your pages once a day

    Added

    • A Page health card on the app pageOn Watch and Care, a browser opens up to 15 pages once a day and reports what does not work as Hints.
    • A problem becomes a Hint after two looksOne look can catch a deploy in progress, so the first sighting stays quiet.
    • Each Hint has two answersYou say whether it is a problem or meant to be that way.
    • Hints stay out of your scoreThey open no incident and send no email.
    • It reads politelyOnly your confirmed address, only reads, as VallitBot. It ignores robots.txt there, because confirming the domain is your permission.
    • Switched off for nowWe turn it on app by app, and it switches itself off if too few owners find it useful.
  70. 1.15.182

    A finding can become a ticket in your own tracker, for selected companies

    Added

    • A finding can become one GitHub ticketThe person who took it on makes it in the app's private repository, with title, app name and a link back.
    • A closed ticket is not a fixIf your team closes it, we check again, and only a finished check counts as fixed. Then we close the ticket.
  71. 1.15.184

    Monthly reports for your clients, for selected companies

    Added

    • A dated report for each clientGroup a client's apps, and each month Vallit prepares what was checked, fixed and left open.
    • Send it to one confirmed personYou approve the report first. The mail holds a link and no finding.

    Improved

    • A fix counts after a later checkA check that did not finish shows as not known.
    • A report holds only the client's own appsChanging a client's apps builds its open draft again, and a draft built before the change cannot be approved.
    • A late mark is not called a clashIt reads as marked as done, not checked yet.
    • The open count names what it leaves outFindings that are not known or not checked yet are named beside it.
    • One confirmation mail an hour, at mostA person who said no is never asked again, and the stop link in a report mail keeps working.
    • One failing client stops no other draftThe other drafts are still prepared that night.
  72. 1.15.185

    Follow verification through to the action

    Added

    • Five checks for ineffective security boundariesConnected code checks follow webhook verification bypasses, caller-chosen token keys, prototype writes, escaping archive paths and private data in shared caches.
    • A fix kit for each new findingEach explains the supported pattern, the change to make and the adversarial test to run afterwards.

    Fixed

    • A verification call must actually protect the actionIgnored boolean results, truthy promises, swallowed errors and writes in finally no longer count as successful verification.
    • Cache keys must distinguish the full ownerAnother session property, an identity prefix or a shared bucket cannot stand in for the caller's complete scope.
  73. 1.15.186

    Follow a finding through your code

    Added

    • Recorded paths in critical code findingsFollow the recorded entry and calls to each affected location, switch between locations and copy the file and line from your report.

    Improved

    • Webhook checks include paid AI actionsA webhook that reads verification headers but reaches a paid AI call without verified permission now produces a finding.

    Fixed

    • Guards follow the actual variableA prototype guard on another variable with the same name no longer hides a dangerous nested write.
    • More precise cache and archive findingsComplete identity aliases can partition cache keys, and archive checks distinguish the unsafe filesystem path from a contained archive destination.
    • Readable reports in smaller app windowsThe score moves above the findings when the available space would squeeze their titles and code.
  74. 1.15.187

    Reports explain their limits

    Fixed

    • Waiting checks keep reports incompleteReports with no findings now name checks awaiting authorization and give the next step before suggesting that nothing needs attention.
    • Results describe the recorded checksReports no longer suggest that monitoring guarantees a future result without vulnerabilities.
    • Handled findings retain their status on phonesAccepted risks stay labeled so they cannot be mistaken for repaired issues.
  75. 1.15.189

    Read the settings behind your deployment

    Added

    • Thirty checks for explicit deployment settingsConnected repositories now expose container privileges, cloud grants, encryption settings and build permissions, with a fix kit for each finding.

    Improved

    • Reports load less at firstThe list of checks loads only what its rows show and leaves the full fix steps for later.

    Fixed

    • Unread configuration cannot count as clearSkipped files, unresolved links and unsupported configuration preserve incomplete coverage instead of hiding a possible issue.
    • Configuration findings explain their limitsReports distinguish committed settings from deployed access, and copy no registry addresses, credentials or raw configuration into the finding.
    • Partial coverage has no perfect scoreA report marked Partial shows an unavailable score, while explaining which checks could not be evaluated.
    • Unfinished checks cannot confirm a fixReport comparisons require the same check to finish successfully and stop reporting the finding; manual dispositions remain in Handled.
  76. 1.15.190

    Preserve the fix you review

    Fixed

    • Proposed fixes keep their checked revisionA changed repository or default branch stops a prepared proposal so it can be checked again before a pull request opens.
    • Retries preserve your review branchThe same proposal reuses its pull request; a different change or your own edit is never overwritten.
    • Incomplete verification holds the proposalA known check that cannot complete prevents a pull request, and applying a proposed patch preserves unread-file coverage.
    • Proposals state how they were checkedUnverified changes ask for review and testing; merging a pull request alone does not mark a finding fixed.
    • Sign-in explains the service preciselyDaily checks, paid reachability checks after domain confirmation and Care fixes are distinct, with readable Terms and Privacy links.
  77. 1.15.191

    One finding per weak token

    Fixed

    • One weak token, one findingSeveral weak random values inside one token give one finding, while separate tokens stay separate.
  78. 1.15.192

    Limit credentials in AI reviews

    Improved

    • Known keys are masked for AI reviewsKnown key formats and private keys in your code are replaced with markers before an AI model reviews it.
    • A hidden key never clears a findingA masked value alone is no reason to call code safe, and a review that needed more code is done again.
    • Deletion guidance states what remainsRemoving a company clears its account and contact fields; shared report targets and results follow the unclaimed-report retention rule.
  79. 1.15.193

    Clarify repairs on Watch and Care

    Fixed

    • Reports explain which repairs are includedLocked reports now distinguish included Care repairs from separately paid Watch repairs, and state that five minute availability checks require a confirmed domain.
  80. 1.15.194

    Keep credentials out of report records

    Fixed

    • Reports hide credentials in addressesPasswords, tokens and known key formats in an address are removed before a new report is saved, and whenever one is shown.
    • Older records are masked tooSaved review reasons and code lines are shown without credentials, also those from before this change.
  81. 1.15.195

    Staff access ends when it is removed

    Fixed

    • Removed staff access ends at onceWhen a person at Vallit loses access to our internal tools, their next request is refused, not five minutes later.
  82. 1.15.196

    Track and confirm fix pull requests

    Fixed

    • Earlier fix pull requests keep their repositoryReconnecting preserves each earlier pull request’s repository. Delayed GitHub replies cannot settle a replacement pull request.
    • Merged repairs remain in progress until confirmedA merge records the pull request status. A successful recheck closes the repair and removes it from the Inbox.
  83. 1.15.197

    One unread file no longer fails every check

    Improved

    • Larger generated reports are readJSON files up to two megabytes are scanned, and links into your own repository no longer count as unread files.

    Fixed

    • One unread file no longer stops every checkA repository check stops only for an unread file it would have read, and its reason names that file and why.
  84. 1.15.198

    Limits on confirmation mail, and steadier new features

    Added

    • Limits on confirmation mailFor client reports, a company sends at most five a day and has at most 25 clients.

    Improved

    • Page health promises nothing it cannot runWithout a browser to run the looks in, the card stays hidden instead of promising a first look.
    • Only events about tickets we made are keptOther ticket events from GitHub leave no trace, and records older than 90 days are cleared.
    • One failing app stops no one elseThe hourly work plan update skips an app it cannot measure and goes on with the rest.
    • A client with a draft reads Draft readyIt said Draft waiting before.

    Fixed

    • A removed link takes its Hint with itWhen your navigation or footer stops linking to a missing page, the next look clears the Hint.
    • An unread page keeps its HintsA look where a page timed out clears no Hint about a removed link.
    • Two presses send one mailThe second press on Ask this person is told to wait an hour.
    • A failed ask leaves no traceIf something breaks before the confirmation mail goes, the client does not read as asked.
    • A quick retry asks nothing moreAfter a send without an answer, the box about a mail that never arrived shows only after 20 hours.
    • Keyboard focus stays on your rowAfter you answer a Hint or change a work plan row, focus stays there instead of jumping to the sidebar.
    • A database fault no longer reads as offThe plan and client pages show an error, not a missing page.
    • A company without tickets is left aloneWhen our GitHub app is removed, only companies that use tickets are changed.
  85. 1.15.199

    Every paid app is checked on time

    Fixed

    • Every paid app is checked every five minutesA pass checked at most 40 apps, so some checks ran late. Now each pass checks every app that is due.
  86. 1.15.200

    A workflow fix waits for the right permission

    Fixed

    • A workflow fix no longer fails halfwayIf GitHub does not let Vallit change your workflows, no pull request is started and a person takes the fix over.
    • A refusal from GitHub reads as oneWhen GitHub refuses to write a fix to your repository, it shows as not allowed instead of an error.
  87. 1.15.201

    A failed code read says so

    Improved

    • The report says when code went unreadWhen we could not read your repository, the report says the code checks did not run this time, and we see why.
  88. 1.15.202

    The status page counts only what visitors meet

    Fixed

    • No incident from a test runErrors in a preview or a test copy of the app no longer count on the status page. Only the live app counts.
  89. 1.15.203

    One rule, one finding, one price in the score

    Improved

    • A setting in many places is one findingThirty-one mutable action references took 62 points off the score. They are now one Low finding listing the places, worth 2.
  90. 1.15.204

    An incident email goes out once

    Fixed

    • One incident, one emailIf our mail provider took an incident email but its answer got lost, a retry sent it twice. A retry now repeats the first email exactly.
    • Retries stop in timeVallit stops trying again before the provider forgets the first try, so a late retry can never become a second email.
  91. 1.15.205

    Check limits hold under quick clicks

    Fixed

    • Limits hold for clicks at the same momentSeveral checks started at once could each pass the hourly limit. Now only as many start as the limit allows.
    • The monthly allowance holds tooQuick clicks on Run a check can no longer start more checks than your plan covers this month.
  92. 1.15.206

    A request that got no answer is not a pass

    Fixed

    • No answer no longer reads as safeWhen a check's request timed out, hit a server error or was rate limited, the check now shows Not run with the reason.
    • What a check found staysA check that stopped partway keeps the findings it confirmed, and their line reads Found.
    • Every request ends on timeEach request to your app has one ten second limit, including looking up the address and waiting its turn.
  93. 1.15.207

    Four more checks no longer pass without an answer

    Fixed

    • API access is checked to the endAn API route that times out or fails without its CORS settings now leaves the check Not run.
    • The http address is checked to the endA server error or rate limit there now leaves the check Not run. Nothing listening on http still passes.
    • Supabase is checked to the endSign-in settings or a bucket list that get no usable answer now leave those checks Not run.
  94. 1.15.208

    A dot after the domain is the same domain

    Fixed

    • One domain, one hourly limitA dot after the domain, as in example.com./, no longer earns three extra checks an hour. It counts as example.com.
    • Addresses with an empty part are refusedAn address such as example..com now gets a plain answer that it is not a valid web address.
  95. 1.15.209

    An incident email that did not arrive is not counted as sent

    Fixed

    • A bounced alert no longer counts as deliveredWhen an incident email bounces, cannot be delivered or is marked as spam, Vallit records why.
    • No repeats to an address that bouncedVallit does not send that incident email to the same address again.
    • We hear of itWe learn the alert did not reach you and can contact you another way.
  96. 1.15.210

    Your team's admin tools no longer count as a leak between customers

    Fixed

    • Team-only tools are read as a role checkAn action limited to your team by a list your server holds is no longer reported as reaching other customers' records.
    • The right reason, not a lucky oneA createEnv list now counts as configuration, not as a stored record that names the caller.

    Improved

    • A company from the request is namedRow-level security set from a company the request sends is reported once, at the line that sets it.
  97. 1.15.211

    Request data kept in a Map or Set is followed

    Fixed

    • Request data in Maps and Sets is followedA request value your code stores in an empty Map or Set now reaches the checks, as it does in an object.

    Improved

    • Allowlists built entry by entry countA set of fixed hosts filled one entry at a time protects a request like one written out in full.
    • Fewer checks left unfinishedCode skipped for its size counts only for problems it can really hold. A write to list[0] is no prototype write.
    • Patterns from your code are read, not runA separator such as /[\\/]+/ is read without compiling it, and your routes are compared segment by segment.
  98. 1.15.212

    The status page says slow or down only when it is

    Fixed

    • One slow answer is not a slow serviceA part of status.vallit.net shows Degraded only after three slow checks in a row, and Down only once it keeps failing.
    • No more false alarms about GitHubThe GitHub connection no longer shows Down when a single request gets lost on the way while GitHub works fine.

    Improved

    • A speed limit for every serviceEach part has its own limit, set from its real answers over three days. Payments, accounts, email and GitHub now show a slowdown too.
    • Only the service's own time countsSetting up the connection is measured apart and does not make a service look slow.
    • What the services say about themselvesWhen GitHub, our email, payment, sign-in or database provider reports trouble on its own status page, the part shows Degraded.
  99. 1.15.213

    A middleware pattern cannot stall a scan

    Fixed

    • A middleware pattern cannot stall a scanVallit now reads config.matcher and Clerk route patterns itself, with a step limit. Common patterns give the same answer as before.
    • An unreadable pattern never hides a missing sign-inA middleware pattern Vallit cannot read counts as not protecting the route.
  100. 1.15.214

    Settings in two places: you and your company

    Added

    • Profile and Company, from the account menuSettings opens from the account menu, as Profile for you and Company for your team, and the menu opens at once.
    • Choose which alerts reach youUnder Company, Alerts, switch each message on or off and pick from which severity a new finding counts.
    • Send alerts to more peopleAdd up to four more addresses that get the same messages at the same moment.
    • Your apps in one listCompany, Apps shows each app's trust page and whether it is part of the anonymous sample.

    Improved

    • Settings that switch without waitingProfile, Company and their sections share one frame that stays in place and shows the page's shape at once.
    • The folded sidebar opens the menu directlyThe avatar no longer unfolds the sidebar first.
    • One word for the team: companyMails, billing messages and screens say company, and Settings, Company, People holds its members. Other workspaces and New workspace are gone.

    Fixed

    • The alert switch promises only what is sentIt no longer says a second message arrives when an app is back.
  101. 1.15.215

    One Settings entry, one list

    Improved

    • One Settings entry in the account menuThe menu says Settings, and Profile and Company sit in one list beside the page, kept apart in two groups.
  102. 1.15.216

    A merged fix gets a fresh check

    Fixed

    • A merged fix is checked again within minutesMerging a Vallit fix pull request starts the app's full check. Its new report closes the request or says why not.
    • Every fix pull request is followedThe hourly look at GitHub takes turns over all open fix pull requests, so none is skipped behind fifty older ones.
  103. 1.15.219

    Code checks that hold on whole apps

    Improved

    • Webhooks that check, then ignore the answerA webhook that goes on after its own signature check fails is now reported as open, and so is the write behind it.
    • Deep object writes walked by request keysA settings path walked key by key, and a deep merge through a nested value, now count as reaching a shared prototype.
    • Private caches keyed without their ownerThe owner can come from your own sign-in helper, also one wrapped in React's cache, or a row found by it.
    • Archive uploadsAn archive entry written outside its folder also counts as a file path the caller chose, reported once at the write.
    • What the checks find, measuredA new docs page shows how often each kind of check finds a problem, how often it alarms wrongly, and what it never checks.

    Fixed

    • Webhooks signed over a timestamp passA signature over a timestamp and the raw body, as Paddle and others send it, counts as a check of the raw body.
    • Webhooks verified by a private package passA verifier the repository does not contain cannot be read, so these routes are left alone.
    • Token subjects stored as data passA key the caller chose stays reported; the stored value no longer counts as whose data it is.
  104. 1.15.220

    Readable for screen readers and low vision

    Fixed

    • The price lines on Billing read correctly aloudEach line of the receipt is its own short list, so screen readers pair every plan with its price.
    • Alert choices stay readable when alerts are offThe descriptions keep full contrast, and one line says the choices are paused while email alerts are off.
  105. 1.15.221

    A nightly copy of our database

    Added

    • A nightly encrypted copy of Vallit's databaseEvery night, kept 14 days, readable only with a key held outside our systems.
  106. 1.15.222

    You accept the Terms when you order

    Added

    • Accept the Terms before you payBefore a plan, a change or a €99 fix goes to Stripe, an admin ticks a box accepting the Terms and the DPA.
    • Your copy of what you acceptedBilling shows which version of the Terms was accepted, when and by whom, and Stripe keeps the version too.
    • Legal links in every emailThe footer of every email links to the Impressum, the privacy policy and the Terms.
    • Invoices that name your companyStripe's payment page asks for the billing address and lets you add your company name and VAT number.

    Improved

    • Care says what it doesWe prepare a change for every confirmed finding, you decide to merge it, and critical findings get an answer by 18:00 the next business day.
    • Prices say how VAT is treatedThe order form says no VAT is charged, as for a small business under § 19 UStG, and fix invoices carry the note.
    • One address for questionsEmails and messages name info@vallit.net.

    Fixed

    • The payment page opens againReturning to an order whose page closed, or ordering after an update, no longer ends in "We could not open the payment page".
  107. 1.15.223

    From first check to a removed app, without getting stuck

    Added

    • Remove one appAn admin removes an app under its Settings with its checks, results and settings. Its place on the plan stays for another app.
    • Name your company when you startThe first screen asks for the company name beside the address, so an agency is not named after its client.
    • A prompt for your AI builderFix it yourself offers Copy AI prompt, ready for Lovable, Bolt, v0, Cursor or Replit.
    • What happens after Request fixThe fix card says the price, who does it, when, how the change reaches you and what is left to you.
    • Tell us a finding is not an issueA link under each finding opens an email to us with the finding named; a person marks it.
    • What connecting the code hands overThe connect page says what Vallit reads, what goes to an AI model and that pull requests need one more permission.

    Improved

    • The first code read is not a changeThe report says the app did not change when the code is read for the first time.
    • Unsure findings read PossibleA finding no second review confirmed reads Possible · Critical, and says why when you open it.
    • Clear instead of SafeA question the check found nothing for reads Clear: it is no promise the app is safe.
    • Library findings name the file and the versionThey point at the file that lists your packages and name the version that closes every listed flaw.
    • Each app on your orderYour order and the plan at Stripe name which app is on Watch and which on Care.
    • A second app leads to a planWithout a plan, Add app says a second app needs one and opens the places on Billing.
    • Home names the app that needs attentionAll quiet only shows when nothing is open.
    • Full check passed means all clearOtherwise the guardian says it ran and what it found.

    Fixed

    • Reports that read your code go with youDeleting the company or an app deletes them, and nobody can take over a report a company made.
    • Deleting your account finishesThe sign-in page says the account is gone instead of the dialog waiting on Deleting.
    • Deleting the company says it workedThe next screen says it is deleted and that nothing more is charged.
    • A failed return from GitHub says soYou land where you can start again, with a line that it did not finish.
    • Help goes to one addressGet help writes to info@vallit.net, the address the website gives.
  108. 1.15.224

    Check the file before you act

    Improved

    • Possible findings say what to check firstA Possible finding now says that old files you no longer deploy can raise it too.
    • The AI builder prompt checks old files firstFor a Possible finding it asks whether the file is still deployed before changing anything.
  109. 1.15.225

    Every promise in the Terms has a deadline we watch

    Added

    • Answers on Care come on timeA critical finding on an app on Care is answered by 18:00 Berlin time on the next business day.
    • Paid fixes are delivered or refundedEach €99 fix is due within two business days; we refund a fix we decline or deliver late.
    • New subprocessors are announced 14 days aheadWe announce a new service by email 14 days before it starts handling your data.
    • Support mail is answeredWe answer mail to our support address by the next business day; data protection requests and breaches keep their legal deadlines.

    Improved

    • Business days follow the TermsDeadlines skip weekends and the public holidays of Baden-Württemberg, as the Terms define business days.
  110. 1.15.226

    Every paid app on its own invoice line

    Improved

    • Each app on its own invoice lineYour invoices and the billing portal list every paid app on its own line, such as Vallit Care · shop.example.com.
    • Changes show per app tooA plan change credits and charges each app on its own line; places for later apps share one line per plan.
    • Plans from before switch on the next changeAn earlier plan keeps one line per plan until its next change, Save or removed app, which splits it at no charge.
  111. 1.15.227

    A paid fix within two business days

    Added

    • A delivery time for paid fixesThe Terms promise a paid fix within two business days of your order. While we wait for you, the time stands still.

    Improved

    • New Terms version 2026-10-08The order box names the new version. A plan you already have keeps the version you accepted until your next order.
  112. 1.15.228

    Vallit speaks German

    Added

    • The whole app in GermanEvery screen, report, finding title and short text, mail and error message reads in German or English; code and evidence stay as written.
    • Your language, chosen onceUnder Settings, Profile, Language you pick English or Deutsch; every device and the mails we send you follow.
    • A switch on the sign-in pagesEnglish and Deutsch sit at the top right before you sign in; the page first follows your browser.
    • German dates, figures and pricesDates read 8. Okt. 2026, figures 2.014 and prices 29 €.

    Improved

    • Company mails in the company's languageAlerts, the guardian's mails and reminders go out in the language most of your admins chose.
  113. 1.15.230

    Your data goes only where our list says

    Improved

    • Only listed services get your dataThe alerts we get about your apps travel only through services on our subprocessor list.
    • Mail to info@vallit.net is answered on timeEach one becomes a task for us to answer by the next business day; auto-replies, newsletters and spam do not.
  114. 1.15.232

    Reports with a fix kit run clean under our security policy

    Fixed

    • Fix kits without a security warningOn a report with a fix kit, the browser no longer blocks the small script that marks the open tab.
  115. 1.15.233

    The day your paid fix is due

    Added

    • Your paid fix names its dayThe finding, the payment confirmation and your Inbox say when the change is due; while we wait for you, the finding says paused.
  116. 1.15.234

    Turn on client reports yourself

    Added

    • Client reports without writing to usAn admin turns them on at Clients or under Settings, Company. Until then a member sees whom to ask.
    • Clients in the sidebarIt sits below Inbox once client reports are on, or as soon as your company has two apps.

    Improved

    • Turning them off keeps everythingYour clients, reports and sent links stay as they are, and their pages lead back to Clients until you turn them on again.
  117. 1.15.235

    No false security alert when a site refuses a request

    Fixed

    • No false alert when your site refuses usIf your site turns the header check away, the check is skipped and neither opens nor closes an incident.
    • The header check waits for your pageIt never runs in the 15 minutes after your app's full check starts, and it compares with the last time your page answered.
    • No pass shown for a refused checkThe Header drift row on your app's page then reads checked, without a green dot.
  118. 1.15.236

    The update log shows what changes for you

    Improved

    • Only changes that reach youThe update log, What's new and vallit.net/updates leave out work on our own tools, so some version numbers are skipped.
  119. The next big release · not out yet