GUARDSCAN/ SAMPLEDEMO DATA
This is a static sample report. Real scans show the same layout with findings from your actual repository.

Security Report

Scanned 10/4/2026, 11:32:14 AM · 29/141 files · 15 findings

TOTAL
15
HIGH
9
MEDIUM
3
LOW
3
COVERAGE
✓ 29 scanned● 1 partial✗ 1 failed
"No findings" does not mean safe for partial or failed files.
NOTE
PATTERNFinding surfaced by deterministic regex rules (100% reproducible)
LLMFinding surfaced by AI analysis (contextual, may vary between runs)
VERIFIEDLLM finding whose claimed line and snippet matched the actual file
CORROB.Both pattern and LLM layers flagged the same issue independently
HIGH
Path TraversalCWE-22
lib/response.js:480
DESCRIPTION
The res.download implementation resolves a user-controlled 'path' with resolve(path) without validating that it stays within opts.root, allowing an attacker to request arbitrary files on the server filesystem.
CODE
path = resolve(path);
FIX
Validate that the resolved path is within the configured root directory before serving. Use path.relative() and reject any result starting with '..'.
SOURCE: LLM✓ VERIFIEDA01:2025
HIGH
Host Header InjectionCWE-644
lib/request.js:418
DESCRIPTION
The 'host' getter trusts the X-Forwarded-Host header when 'trust proxy' is enabled, which can be manipulated to control the perceived host and lead to open redirects, SSRF, or cache poisoning.
CODE
return this.get("X-Forwarded-Host") || undefined;
FIX
Only trust X-Forwarded-Host when explicitly configured with a known allowlist. Document the security implications of enabling trust proxy.
SOURCE: LLM✓ VERIFIEDA01:2025
HIGH
Cross-Site Scripting (XSS)CWE-79CORROBORATED
lib/response.js:290
DESCRIPTION
The JSONP callback name is taken from a query parameter and only loosely sanitized with a regex, allowing crafted callback values that can execute arbitrary JavaScript when the response is interpreted.
CODE
callback = callback.replace(/[^\[\]\w$.]/g, '');
FIX
Validate the callback name against a strict allowlist of characters (alphanumeric, underscore, dot). Reject anything else with a 400 error.
SOURCE: BOTH✓ VERIFIEDA05:2025
MEDIUM
Prototype PollutionCWE-1321
lib/application.js:536
DESCRIPTION
Object spread merges 'opts._locals' into 'renderOptions' without sanitization. If an attacker supplies a property named '__proto__', it can modify the prototype of renderOptions.
CODE
renderOptions = Object.assign({}, opts._locals, renderOptions);
FIX
Use a safe merge function that skips __proto__, constructor, and prototype keys. Consider Object.create(null) for the target object.
SOURCE: LLM✓ VERIFIEDA03:2025
LOW
Insecure TransportCWE-319
lib/response.js:85 · seen in 10 files
DESCRIPTION
Plain HTTP URL detected in a response helper — data could be transmitted unencrypted if called from a non-HTTPS context.
CODE
"http://expressjs.com/en/4x/api.html#res"
FIX
Use HTTPS URLs in documentation and code samples. This finding is likely informational for a library, but flagged for awareness.
OCCURRENCES (5)
  • · lib/response.js:85
  • · lib/response.js:86
  • · lib/response.js:88
  • · lib/response.js:89
  • · lib/response.js:788
SOURCE: PATTERNA04:2025
Run this against your own repo
Free. No signup. 30 seconds.
SCAN A REPO →