6 new security tools: critical vulnerabilities now auto-detected
Starting today, DevOpsNL detects 6 additional vulnerability types, including subdomain takeover, SSRF and open redirects. The Quick audit grows from 35+ to 40+ detectors, and Deep/Deepest get advanced infrastructure security checks.
Lees deze pagina in het Nederlands
Run free auditWhat's new?
The audit engine grows with 6 new security tools that address critical attack surfaces:
Subdomain takeover detection: checks 17 cloud platforms (Heroku, Vercel, AWS, Azure, and more) for dangling CNAMEs that attackers can hijack.
SSRF scanning: detects Server-Side Request Forgery via URL parameters that can scan internal networks, including AWS metadata endpoints.
Host header injection: finds password reset and cache poisoning vectors via unvalidated Host headers.
Open redirect detection: analyzes 30+ redirect parameters (redirect, return_to, next, etc.) for phishing vulnerabilities.
JavaScript security: scans for vulnerable libraries (jQuery, Bootstrap, Lodash) and unsafe patterns (eval, new Function).
WebSocket security: checks for plaintext ws:// connections and missing authentication.
- Quick: +5 detectors (JavaScript + WebSocket security)
- Deep: +1 detector (open redirects)
- Deepest: +4 detectors (subdomain takeover, SSRF, host header, infrastructure)
Why add these tools?
These 6 tools fill gaps in existing coverage. Subdomain takeover is a critical but often overlooked issue: when a CNAME points to a deactivated Heroku or Vercel app, any attacker can claim that subdomain and serve phishing content under your domain.
SSRF is the #1 vulnerability according to OWASP: URL parameters that trigger internal requests can steal AWS metadata (IAM credentials) or reach internal admin panels.
Open redirects are rarely considered 'security issues', but are the perfect phishing vector: a link like yoursite.com?redirect=evil.com/login looks trustworthy.
JavaScript vulnerabilities remain the largest attack surface: 90% of sites use vulnerable libraries, and eval/new Function are still common in legacy code.
How do the new tools work?
The tools run fully automatically, just like all other checks. No configuration, no installation:
Subdomain takeover: DNS CNAME lookup + response analysis (2-5 seconds per subdomain)
SSRF: URL parameter discovery + safe internal IP testing (no production impact)
Host header: active test with malicious Host headers + response pattern matching
Open redirects: redirect parameter extraction + phishing URL testing
JavaScript: library version detection + unsafe pattern scanning in inline scripts
WebSocket: protocol analysis + authentication check
Updates across all tiers
Every audit tier grows with new capabilities:
Quick (free): Now 40+ detectors instead of 35+. JavaScript library scanning and WebSocket security are now standard.
Deep (€9.99/5 scans): Crawls up to 50 pages and adds open redirect detection.
Deepest (€19.99/5 scans): All previous checks plus subdomain takeover, SSRF scanning, host header injection and full infrastructure analysis.
SEO & Performance impact
The new tools are designed for minimal performance impact. All checks have timeouts (5-8 seconds) and limits (3-5 items) to keep scans under 30 minutes for Deepest audits.
SEO optimization: all new tools produce specific findings with standards (OWASP ASVS 5.0.0, RFC 9116) and concrete improvements, perfect for developer teams who want to get started immediately.
Technical details
All new tools are implemented as TypeScript modules in src/lib/audit/:
subdomain-takeover.ts: 17 cloud platform patterns + takeover error detection
ssrf.ts: 18 SSRF keywords + AWS metadata protection
host-header-injection.ts: Password reset + cache poisoning vectors
open-redirects.ts: 30+ redirect parameters + active testing
javascript-security.ts: 6 known vulnerable libraries + 7 unsafe patterns + SRI checks
websocket-security.ts: Plaintext detection + authentication validation
Full test coverage: 78 unit tests + integration tests
Available immediately
All new tools are now running in production. No waiting period, no configuration. Start a Quick audit and you'll see the new findings in your report immediately.
Enterprise customers can add custom scopes: internal IP ranges, own cloud platforms, or specific redirect parameters that need extra monitoring.
Frequently asked questions
- Will the new tools slow down my site?
- No. All checks have timeouts and limits. A Quick audit stays ~60 seconds, Deep ~5-10 minutes, Deepest ~15-30 minutes.
- Are the tools available on all tiers?
- Quick gets JavaScript + WebSocket security. Deep adds open redirects on top. Deepest gets all 6 new tools plus infrastructure checks.
- Can I remove false positives?
- Yes. Each finding has an evidence section with the exact proof. You can mark false positives as 'ignored' in your dashboard.
- Do the tools work if I'm not the site owner?
- Quick works on any public URL. Deep and Deepest require owner consent (via token, allowlisted IP, or database credits).
- How does this differ from other security scanners?
- We scan read-only only, crash nothing, and report with evidence (DOM selectors, request logs, screenshots). No vague 'high severity' without context.
Curious what is on your own site? Paste a URL and you have a report within a minute.
Run free audit