What Pallos checks.
Focused static checks for source files at one commit. A check is evaluated only when the relevant files or technology are available; unsupported or missing evidence stays unverified.
Supported source checks
| Check | Category | Supported stack | Result type |
|---|---|---|---|
| Committed credential patternsCredential-shaped strings in selected source files. Limit: Does not verify whether a credential is active. | Secrets | Selected source files | Pass / finding / review / unverified |
| Privileged values in client codeService-role keys and sensitive public environment variables. Limit: Deployed bundling and environment are not executed. | Client/server boundaries | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| Admin-route authorizationSupported admin API routes and visible access checks. Limit: Cannot prove every business permission or runtime behavior. | Authorization | Next.js / JavaScript / TypeScript | Pass / finding / review / unverified |
| Session cookie configurationVisible HttpOnly, Secure, and SameSite settings. Limit: Only source-configured cookies can be assessed. | Authorization | Next.js / JavaScript / TypeScript | Pass / finding / review / unverified |
| CORS and webhook handlingCredentialed wildcard CORS and Stripe webhook verification patterns. Limit: Does not send live requests or forge webhooks. | API routes | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| AI endpoint controlsVisible authentication, rate limits, and output caps. Limit: Cannot establish actual spend or provider-side limits. | API routes | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| External request timeoutsVisible timeout or abort handling around server requests. Limit: Does not simulate outages. | API routes | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| Supabase policiesPermissive policies, disabled RLS, and broad anonymous grants in source. Limit: The live database policy is not queried. | Database access | Supabase SQL | Pass / finding / review / unverified |
| Destructive migration recoveryDestructive SQL operations that need a recovery plan. Limit: Cannot verify backups or restoration tests. | Database access | Supabase SQL | Pass / finding / review / unverified |
| Dynamic code executioneval-like execution and visible user-data flow. Limit: Impact depends on runtime path and input trust boundary. | Project configuration | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| AI data minimizationVisible request-body forwarding to model providers. Limit: Cannot determine every privacy obligation. | Project configuration | JavaScript / TypeScript / Next.js | Pass / finding / review / unverified |
| Installed dependency advisoriesLocked versions when advisory data is available. Limit: Public scans may mark this unverified; reachability is not proven. | Dependencies | npm lockfile | Pass / finding / unverified |
Result labels
- Needs attention
- A supported pattern matched. Read the evidence and confirm the real-world context.
- Passed
- No matching supported pattern in reviewed source. Not a security guarantee.
- Unverified
- Evidence was missing, the source was inconclusive, or the check could not run. Never counted as passed.
- Severity / confidence
- Potential impact and strength of evidence are separate. Neither proves exploitation.
CRSPR labels
Findings may relate to Cost, Reliability, Safety, Privacy, or Recovery. These are review dimensions, not five scanners or an overall risk score.
Scan limits
Pallos selects eligible source files up to the public scan cap. It does not run the app, inspect deployed settings, test every authorization rule, or replace manual review. The report states files reviewed, selection limits, and checks it could not verify.