StackAttestTechnical Trust
Replit security audit

Audit what your Replit project exposes once it is running

On Replit the thing you are building and the thing other people can reach are often the same address, so configuration is part of your security posture rather than a step after it. Most of what goes wrong here is a setting rather than a mistake in your code, and that is the good news: settings are quick to check and quick to change.

Scan a live appSee pricingSee an example Passport

Three layers, weighted toward what is deployed

Deployment questions are answered from outside and by probing the running service, so those two layers carry the most weight here. Reading the source adds where credentials live and what each endpoint asks for before it answers.

Deployed address scan

E1
URL scan

Tests the running deployment the way anyone holding the link reaches it: whether transport security is enforced, which security response headers are set, what the service discloses about itself when it errors, and which paths answer without asking who is calling. It needs only the address, and it is the weakest evidence the platform produces, so it is graded that way.

Runtime validation

E4
Runtime

Builds and runs the application in an isolated environment and probes it. This is the layer that settles configuration questions instead of inferring them: whether an unauthenticated request is genuinely refused, whether one account's records stay out of another account's response, and what an error returns when something actually breaks.

Source and configuration review

E2
Repository

Reads the code and the configuration around it: where credentials are read from, whether any of them reach files delivered to the browser, which endpoints check a session and which never do, how data access is written, and which dependencies carry known critical advisories. Findings cite the file they came from, so a result is checkable rather than asserted.

What tends to be exposed once a project is live

These are the failure modes that recur once something is reachable, not a claim about your application. The audit establishes which of them are actually present.

An address is not a permission

A deployed project answers anyone holding the URL. Something built for you, or for one team, is open to everyone unless a sign-in stands in front of it. Nothing announces this, because the app behaves in public exactly as it behaved while you were building it.

Secrets that end up on the client side

A value kept in the secrets store is safe there. The same value read from client-side code, or written into a build, is delivered to every visitor and stays in whatever they cached. The variable looks identical in both cases, which is why this is worth testing rather than recalling.

Endpoints added because they were convenient

A route that dumps a table while you are debugging, an admin action, an export link. They were for you, so they rarely ask who is calling, and they usually outlive the reason they were added. They are also the easiest thing on this list to find from outside.

Development settings that shipped

Errors that print internals, an origin policy that accepts everyone, registration left open, a datastore that accepts a connection from anywhere. Each one made building easier, and each one means something different once the project is public.

Data that outlives the run

A database, an object store or a file the app writes keeps whatever earlier runs put there: test records, a sample import, real user data. Who can read it afterwards is a configuration question, and it is rarely the question anyone was asking while building.

Credentials pasted before there was a better place for them

A token typed into a file during setup and later moved into the secrets store is still sitting in that file's history. Rotating it takes a few minutes and closes the exposure completely, which makes it the cheapest finding on any report.

What the result looks like

An illustrative extract, not a real customer result. Every row carries the evidence grade behind it, and a control nobody could establish says so.

ControlStatusEvidenceNote
Authentication required on non-public endpointsFailedE4Two routes answer an unauthenticated request
Secrets absent from client-delivered codeVerifiedE2No stored secret is read outside server code
Transport security on the deployed addressVerifiedE1Enforced on the address that was scanned
Stored records scoped to the account that owns themPartialE4Scoped on read, not on one delete path
Backup and restore of persisted dataUncoveredNot gradedNot determinable from the layers that ran

Mapped to published standards

Each control is tested against a named clause, so a result means something outside our own vocabulary. Mapping is not certification, and none of these bodies endorse StackAttest.

OWASP ASVS 5OWASP WSTGOWASP API Security Top 10CWENIST SSDF

What this audit is not

  • It is not a penetration test. A deterministic check and a runtime probe are not an adversarial human engagement, and there are classes of weakness only a person hunting for them will find.
  • It is not SOC 2 and does not replace it. SOC 2 attests to organisational controls over time; this validates technical controls in the software. They answer different questions for different buyers.
  • It does not replace human due diligence. It gives a reviewer repeatable evidence to start from, which is a different thing from being the reviewer.
  • Controls the run could not reach are reported as uncovered rather than passed. A result you did not earn is worse than no result.
  • It is not affiliated with Replit and does not integrate with it. The audit examines the application you deployed, not the platform hosting it, and no result here is a statement about Replit's own security.

Questions

What does a Replit security audit cover?

What the deployed address exposes, whether endpoints require authentication, where credentials live and whether any reach the browser, how the running service answers a request it should refuse, and what persists between runs. Each result carries its evidence grade, and controls the run could not reach are listed rather than assumed.

Do you connect to my Replit account?

No. StackAttest is not affiliated with Replit and does not integrate with it, sign in to it, or read your workspace. A scan needs the address of the deployed application, and source-level evidence needs a read-only connection to the code.

I am not a security engineer. Will the result mean anything to me?

That is who it is written for. Each finding says what was tested, what happened, and what to change, ordered by what is worth doing first. Nothing in it assumes you already have the vocabulary, and the controls that could not be reached are named plainly instead of being dressed up as passes.

Only a few people use my app. Is this worth doing?

How many people use it and how many people can reach it are different numbers. A deployed address answers anyone who finds it, including automated traffic that neither knows nor cares what the application is for. A scan is the cheap way to learn which of those two numbers you are actually running.

Can you tell whether my secrets are exposed?

The source layer looks for credentials in code and in anything delivered to the browser, and the deployed scan checks what the running application discloses about itself. If a value that should have stayed on the server is reachable, the finding cites the file or the response it came from.

Is a URL scan enough on its own?

It answers the deployment questions and nothing else, at the weakest evidence grade the platform records. It cannot tell you whether one account can reach another account's data, which needs the source or the running system. A scan is never presented in the report as though the code had been read.

Related

Vibe code auditBolt security auditAI app security auditFree vibe coding checklistSecurity and data handling

Find out what is actually true of your application

Start with the layer you can run today. The report says which layers ran and what they could not reach, so the result is honest about its own limits.

Scan a live appSee pricing