What can a stranger see on your site?
Real explanations of what you expose without meaning to, what an attacker does with it, and the one-line fix for each. No jargon for its own sake, no scare tactics, just what's actually reachable from outside.
Recently updated
- API security testing: what it covers, and what a scan sees from outsideWhat an attacker sees before they touch your site
- Penetration testing cost: what a pentest runs, and what runs free firstWhat an attacker sees before they touch your site
- Supabase security: what a stranger can reach with your public keyWhat an attacker sees before they touch your site
Browse by topic
The secrets hiding in your JavaScript
API keys, tokens, and credentials that shipped to the browser by accident.
17 articles→The files you forgot you deployed
The .env, the backup, the .git folder anyone can download with a URL.
23 articles→What an attacker sees before they touch your site
Everything an outsider learns about you without sending a single malicious request.
23 articles→The admin panel you left unlocked
phpMyAdmin, Grafana, debug toolbars, and error pages open to the world.
22 articles→HTTPS, TLS, and the headers that protect your visitors
Redirects, certificates, CSP, cookies, and CORS done right.
19 articles→Email spoofing and DNS you never configured
SPF, DMARC, CAA, and the dangling subdomain someone can claim.
13 articles→Outdated and unverified code on your pages
Old libraries with public exploits, and third-party scripts with no integrity check.
10 articles→Shipping fast without shipping holes
A founder's playbook for catching this before your first user does.
9 articles→Reading about it is step one. Seeing your own is step two.
Run a passive scan and find out which of these your site is doing right now. The grade costs nothing.
Scan my site