One problem at a time, explained properly
These are reference pages, not sales pages. Each one covers a single failure that turns up often in software built quickly: what it is, how to check for it without buying anything, and which kind of evidence actually settles it.
How to check a website for exposed API keys
Not every key in a browser bundle is a leak. How to tell a publishable identifier from a privileged credential, why a build-time prefix decides exposure, why rotation comes before removal, and what a validation run can establish about either.
How to test your app for broken access control
Authentication is not authorisation, and hiding a control in the interface is not access control. What to test with two accounts, what an identifier in a request must never imply, and which of these a reader of your source can establish and which needs a run.
Check whether your webhook endpoint trusts whatever posts to it
A webhook handler works in testing without any of the things that make it safe: a verified signature, a replay window, an event id you have seen before, and an ownership check the payload does not get to make. What to look for, and what a validation run can establish about the endpoint you deployed.
Check whether you are shipping packages with known vulnerabilities
A generated project acquires a large dependency tree in one step. What a known vulnerability actually means, why reachability decides how much any of them matter, how direct and transitive dependencies differ, and what a lockfile has to do with all of it.
How to rate limit an API, and which endpoints to do first
Not every endpoint needs a ceiling, and the ones that do need two. Which endpoints to protect first, how to choose the identity a limit counts against, what to return to a caller you are refusing, and why a quiet probe is not proof that no limit exists.
What a security headers check tells you, and what it does not
The five response headers we test, what each one actually prevents, and the honest ranking: a content security policy is the one that takes work and pays for it, and the other four are close to free. Plus where headers are set, because that decides how a missing one gets fixed.
Row level security in Postgres, and when a policy protects nothing
What row level security is in Postgres, the difference between enabled and forced, how a policy is evaluated per command, why a rule that only asks whether somebody is signed in scopes nothing, and why an application connecting as the owner bypasses all of it.
Checking one of these on your own app
The free check tests a deployed application from outside and needs no account. It names the controls a URL cannot reach as uncovered rather than passing them, which is the part most free scanners leave out.