Skip to main content

6 new security tools: critical vulnerabilities now auto-detected

Starting today, DevOpsNL detects 6 additional vulnerability types, including subdomain takeover, SSRF and open redirects. The Quick audit grows from 35+ to 40+ detectors, and Deep/Deepest get advanced infrastructure security checks.

Lees deze pagina in het Nederlands

Run free audit

What's new?

The audit engine grows with 6 new security tools that address critical attack surfaces:

Subdomain takeover detection: checks 17 cloud platforms (Heroku, Vercel, AWS, Azure, and more) for dangling CNAMEs that attackers can hijack.

SSRF scanning: detects Server-Side Request Forgery via URL parameters that can scan internal networks, including AWS metadata endpoints.

Host header injection: finds password reset and cache poisoning vectors via unvalidated Host headers.

Open redirect detection: analyzes 30+ redirect parameters (redirect, return_to, next, etc.) for phishing vulnerabilities.

JavaScript security: scans for vulnerable libraries (jQuery, Bootstrap, Lodash) and unsafe patterns (eval, new Function).

WebSocket security: checks for plaintext ws:// connections and missing authentication.

  • Quick: +5 detectors (JavaScript + WebSocket security)
  • Deep: +1 detector (open redirects)
  • Deepest: +4 detectors (subdomain takeover, SSRF, host header, infrastructure)

Why add these tools?

These 6 tools fill gaps in existing coverage. Subdomain takeover is a critical but often overlooked issue: when a CNAME points to a deactivated Heroku or Vercel app, any attacker can claim that subdomain and serve phishing content under your domain.

SSRF is the #1 vulnerability according to OWASP: URL parameters that trigger internal requests can steal AWS metadata (IAM credentials) or reach internal admin panels.

Open redirects are rarely considered 'security issues', but are the perfect phishing vector: a link like yoursite.com?redirect=evil.com/login looks trustworthy.

JavaScript vulnerabilities remain the largest attack surface: 90% of sites use vulnerable libraries, and eval/new Function are still common in legacy code.

How do the new tools work?

The tools run fully automatically, just like all other checks. No configuration, no installation:

Subdomain takeover: DNS CNAME lookup + response analysis (2-5 seconds per subdomain)

SSRF: URL parameter discovery + safe internal IP testing (no production impact)

Host header: active test with malicious Host headers + response pattern matching

Open redirects: redirect parameter extraction + phishing URL testing

JavaScript: library version detection + unsafe pattern scanning in inline scripts

WebSocket: protocol analysis + authentication check

Updates across all tiers

Every audit tier grows with new capabilities:

Quick (free): Now 40+ detectors instead of 35+. JavaScript library scanning and WebSocket security are now standard.

Deep (€9.99/5 scans): Crawls up to 50 pages and adds open redirect detection.

Deepest (€19.99/5 scans): All previous checks plus subdomain takeover, SSRF scanning, host header injection and full infrastructure analysis.

SEO & Performance impact

The new tools are designed for minimal performance impact. All checks have timeouts (5-8 seconds) and limits (3-5 items) to keep scans under 30 minutes for Deepest audits.

SEO optimization: all new tools produce specific findings with standards (OWASP ASVS 5.0.0, RFC 9116) and concrete improvements, perfect for developer teams who want to get started immediately.

Technical details

All new tools are implemented as TypeScript modules in src/lib/audit/:

subdomain-takeover.ts: 17 cloud platform patterns + takeover error detection

ssrf.ts: 18 SSRF keywords + AWS metadata protection

host-header-injection.ts: Password reset + cache poisoning vectors

open-redirects.ts: 30+ redirect parameters + active testing

javascript-security.ts: 6 known vulnerable libraries + 7 unsafe patterns + SRI checks

websocket-security.ts: Plaintext detection + authentication validation

Full test coverage: 78 unit tests + integration tests

Available immediately

All new tools are now running in production. No waiting period, no configuration. Start a Quick audit and you'll see the new findings in your report immediately.

Enterprise customers can add custom scopes: internal IP ranges, own cloud platforms, or specific redirect parameters that need extra monitoring.

Frequently asked questions

Will the new tools slow down my site?
No. All checks have timeouts and limits. A Quick audit stays ~60 seconds, Deep ~5-10 minutes, Deepest ~15-30 minutes.
Are the tools available on all tiers?
Quick gets JavaScript + WebSocket security. Deep adds open redirects on top. Deepest gets all 6 new tools plus infrastructure checks.
Can I remove false positives?
Yes. Each finding has an evidence section with the exact proof. You can mark false positives as 'ignored' in your dashboard.
Do the tools work if I'm not the site owner?
Quick works on any public URL. Deep and Deepest require owner consent (via token, allowlisted IP, or database credits).
How does this differ from other security scanners?
We scan read-only only, crash nothing, and report with evidence (DOM selectors, request logs, screenshots). No vague 'high severity' without context.

Curious what is on your own site? Paste a URL and you have a report within a minute.

Run free audit