TRANSPARENT BY DESIGN
What we check.
What it means.
An automated finding is a starting point for a decision. Here’s how our checks work, where they stop and how we handle your data.
Website checks
We request one public page and follow up to four redirects. We check HTTPS certificate validation, selected security headers, cookie attributes, static references to insecure resources and provenance signals. Response content is limited to 512 KB. Query strings and fragments are removed. Error pages, blocked requests and truncated responses reduce coverage and are disclosed in the report.
We do not log in, crawl the site, send attack payloads or test injection, authorization or business logic. We do not infer a vulnerable software version from a site’s appearance. A header observation does not establish whether a configuration is appropriate for every page.
Source-code checks
Upload a source-only ZIP up to 10 MB compressed and 20 MB uncompressed. We read at most 300 supported UTF-8 source files, each at most 512 KB, from an archive of at most 1,500 entries. Generated output, dependency directories, binaries and unsupported files are skipped and counted. Archives are read in memory; they are never extracted or executed.
Checks flag potential credentials, disabled certificate validation, dynamic execution, shell execution, unsafe deserialization, raw HTML insertion and debug settings. Python syntax-tree checks additionally inspect dynamic query construction. Other languages receive text-pattern checks, not full semantic analysis. Rule matches may include tests, comments or safe code; each candidate needs contextual review. Results are capped and report when that affects coverage.
Dependency advisories
This optional check sends exact package names and versions to OSV, a public vulnerability database. It supports pinned requirements*.txt entries, exact package.json entries and npm v2/v3 package-lock.json packages, with at most 100 unique versions per review. Version ranges and unsupported formats are disclosed as gaps. Lockfiles determine transitive coverage.
A version match does not prove your application can be exploited. Dependency findings use a review priority, not an inferred CVSS score. Follow the advisory references to determine applicability and patched versions. If the external service is unavailable or results are incomplete, the report says so.
AI provenance
We search for explicit AI attribution, known builder integrations and HTML generator metadata. These can be incomplete, misleading or deliberately modified. Their presence does not prove that an entire site is AI-generated; their absence does not prove human authorship. We report evidence and uncertainty, never an invented AI percentage. No language model or third-party “AI detector” is used for these checks.
Data handling
Website addresses and source uploads are processed to produce the requested report. Source archives, page bodies and reports are not written to application storage. They remain in process memory while the request runs, then are released. Memory may remain allocated until reused by the runtime; this is not a cryptographic secure-erasure guarantee. Do not upload live credentials or information you are not authorized to share.
Your report is returned to the browser and kept in page memory until you close or reload it. Save a JSON copy or use Print / save PDF before leaving. Downloaded copies are under your control. We do not offer public report links or server-side report history.
We use an essential, HttpOnly session cookie valid for one hour to protect scan submissions. Abuse controls store HMAC-derived client/session identifiers and hourly counters for up to two hours, with cleanup on subsequent scan requests. Raw IP addresses are not stored by the application rate limiter. Hosting providers may process connection metadata and operational logs under their own policies; this application disables HTTP access logging. No analytics or advertising scripts are installed.
OSV receives package names and versions only if you select dependency lookup. No source files are sent to an AI provider. Website checks necessarily send HTTP requests to the target and DNS queries through the hosting resolver. The hosting platform processes requests to this service.
Authorized use and limits
Submit only websites and code you own or have permission to assess. Scan requests are limited per browser, client address and service, with two simultaneous scan slots. These checks are not certification, continuous monitoring or a guarantee of security. Findings have not been reviewed by a human unless you arrange that separately.
Manual review & remediation
For authentication, access control, data flow, infrastructure or business-logic reviews, contact info@leaguesoftwares.com. We’ll agree on scope, access, deliverables and pricing before starting.
Start your check ↗