What we check
Coverage
Each category maps to a real module in the scanner, not a marketing promise.
Security headers
TLS / certificate
Cookies
CORS
HTTP methods
Exposed sensitive files
Open redirects
Injection (XSS / SQLi in GET)
Login rate limiting
Secrets in JS (JWT, keys)
Exposed source maps
Vulnerable JS libraries
CDN / WAF
Supabase RLS
example
AUDITLY
SECURITY AUDIT REPORT
3 critical or high findingsSee the full detail in the PDF
Security headers
TLS / certificate
Cookies