NEXT.JS SECURITY SCANNER

Review a Next.js repository before you launch.

Pallos prioritizes App Router and API code, authentication checks, configuration, webhooks, and browser-facing files, then explains each signal in plain English.

Read-onlyNo account requiredSecret values stay hidden
WHAT IT LOOKS FOR

Focused signals with file-level evidence.

  • Sensitive API routes that appear to check login without checking role or ownership
  • Server-only operations or private values placed in client components
  • Webhook handlers missing recognizable signature-verification evidence
  • Dynamic code execution and credentialed cross-origin access patterns
WHAT IT CANNOT PROVE

Unknown stays unknown.

  • The public scan is capped and prioritizes security-sensitive files.
  • Static analysis cannot observe production configuration, traffic, or runtime behavior.
  • Framework conventions and custom authorization code can require a manual review.
HOW THE FREE SCAN WORKS

Paste. Review. Fix.

  1. 01

    Paste a public GitHub URL

    Use code you own or are authorized to review.

  2. 02

    Read the evidence

    See the affected file, risk, explanation, and practical fix direction.

  3. 03

    Make the change yourself

    Pallos never pushes or edits your repository.

COMMON QUESTIONS

What this check means.

Does Pallos change my code?

No. The scanner is read-only. It gives evidence and fix directions while you control every change.

Does it support the App Router?

Yes. Pallos reviews common App Router, route-handler, server/client boundary, and environment-variable patterns.

Is a high score proof that the app is secure?

No. The score summarizes completed checks. Untested areas stay visible and are not silently counted as passes.

FREE · PUBLIC REPOSITORIES

Check the code before users find the mistake.

No payment, account, or installation. The repository stays unchanged.

Start the scan