{"id":51118715,"url":"https://github.com/perufitlife/awesome-backend-security","last_synced_at":"2026-06-25T00:01:24.610Z","repository":{"id":366966144,"uuid":"1276010620","full_name":"Perufitlife/awesome-backend-security","owner":"Perufitlife","description":"Curated security auditors for the backend stack — Supabase, Firebase, Hasura, Strapi, Directus, Payload, Convex, n8n, Ollama \u0026 more. Keyless, active-probe, MIT.","archived":false,"fork":false,"pushed_at":"2026-06-24T02:36:32.000Z","size":20,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":0,"default_branch":"master","last_synced_at":"2026-06-24T04:26:27.446Z","etag":null,"topics":["awesome","awesome-list","baas","backend","devsecops","graphql","headless-cms","security","security-audit","vulnerability-scanner"],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Perufitlife.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-06-21T12:32:38.000Z","updated_at":"2026-06-24T02:36:36.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/Perufitlife/awesome-backend-security","commit_stats":null,"previous_names":["perufitlife/awesome-backend-security"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/Perufitlife/awesome-backend-security","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Perufitlife%2Fawesome-backend-security","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Perufitlife%2Fawesome-backend-security/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Perufitlife%2Fawesome-backend-security/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Perufitlife%2Fawesome-backend-security/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Perufitlife","download_url":"https://codeload.github.com/Perufitlife/awesome-backend-security/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Perufitlife%2Fawesome-backend-security/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34753781,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-24T02:00:07.484Z","response_time":106,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome","awesome-list","baas","backend","devsecops","graphql","headless-cms","security","security-audit","vulnerability-scanner"],"created_at":"2026-06-25T00:01:23.534Z","updated_at":"2026-06-25T00:01:24.601Z","avatar_url":"https://github.com/Perufitlife.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Awesome Backend Security Auditors [![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\n\u003e Curated, keyless **security auditors** for the modern backend stack — BaaS platforms, headless CMSs, GraphQL engines, workflow runners and local LLM servers. Every tool here runs locally and **confirms each leak with an active anonymous probe** instead of just inferring it from config.\n\nThe single most common production breach in this stack is boring and universal: a backend left readable by the **public / anonymous role**. Supabase ships RLS-disabled tables, Firebase ships `allow read: if true`, Strapi/Directus/Payload leave the Public role on `find`, Hasura sets `unauthorized-role: public`, Ollama binds `0.0.0.0` with no auth. The tools below find that — and prove it — one command at a time.\n\n## Contents\n\n- [Why active-probe](#why-active-probe)\n- [BaaS \u0026 Databases](#baas--databases)\n- [Headless CMS](#headless-cms)\n- [GraphQL](#graphql)\n- [Workflow \u0026 Automation](#workflow--automation)\n- [Local LLM / AI](#local-llm--ai)\n- [Secrets \u0026 Exposure](#secrets--exposure)\n- [MCP servers](#mcp-servers)\n- [Reference reading](#reference-reading)\n\n## 🔍 Free audit\n\nNot sure if your backend is exposed? **[Open a free-audit request](https://github.com/Perufitlife/awesome-backend-security/issues/new?template=free-audit.yml)** with your URL and I'll run the matching auditor and post the findings + exact fixes back — free, read-only, nothing downloaded or changed. If you'd rather have the fixes done for you, there's a [$99 fixed-scope audit](https://perufitlife.github.io/supabase-security-skill/).\n\n## Guides\n\n- [How to tell if your backend is leaking data (and fix it)](guides/find-backend-data-leaks.md) — a platform-by-platform checklist with a one-line command to confirm each leak.\n- [Is your Ollama server exposed?](guides/is-your-ollama-server-exposed.md) — 175,000+ instances run with no auth. Check yours in one command.\n- [Supabase is locking down public table access on Oct 30, 2026 — are you ready?](guides/supabase-public-schema-deadline-checklist.md) — pre-deadline checklist to find and fix anon-exposed tables.\n\n## Why active-probe\n\nA linter that reads your rules file tells you what *might* be exposed. An **active probe** sends the exact unauthenticated request an attacker would and shows you the bytes that actually come back. Every tool in this list is:\n\n- **Keyless** where possible — point it at a URL, no admin token needed for the public-exposure checks.\n- **Local-first** — your data and credentials never leave your machine.\n- **Zero-dependency, MIT** — auditable in one file, free forever.\n\n## BaaS \u0026 Databases\n\n- [supabase-security](https://github.com/Perufitlife/supabase-security-skill) — RLS-disabled tables, anon grants, public buckets and `SECURITY DEFINER` functions; active anon-key probe confirms each leak. [npm](https://www.npmjs.com/package/supabase-security)\n- [firebase-security](https://github.com/Perufitlife/firebase-security-skill) — the infamous `match /{document=**} { allow read, write: if true; }`, expired test-mode rules and auth-without-ownership in `firestore.rules`. [npm](https://www.npmjs.com/package/firebase-security)\n- [pocketbase-security](https://github.com/Perufitlife/pocketbase-security-skill) — empty API rules (fully public), `@request.auth.id != \"\"` over-permissive rules, dangerous `true` literals. [npm](https://www.npmjs.com/package/pocketbase-security)\n- [appwrite-security](https://github.com/Perufitlife/appwrite-security-skill) — `any` role grants, document-security misconfig and over-permissive collection permissions. [npm](https://www.npmjs.com/package/appwrite-security)\n- [nhost-security](https://github.com/Perufitlife/nhost-security-skill) — Hasura/Nhost anonymous role with open SELECT, missing row filters, public introspection. [npm](https://www.npmjs.com/package/nhost-security)\n- [convex-security](https://github.com/Perufitlife/convex-security) — public queries/mutations reachable without auth on a Convex deployment's HTTP API, CORS reflection and metadata leaks. [npm](https://www.npmjs.com/package/convex-security)\n\n## Headless CMS\n\n- [strapi-security](https://github.com/Perufitlife/strapi-security) — public-role read exposure, CORS reflection, `/api/users` enumeration, GraphQL introspection and the relational-populate admin oracle (CVE-2026-27886 class). [npm](https://www.npmjs.com/package/strapi-security)\n- [directus-security](https://github.com/Perufitlife/directus-security) — public-role data exposure, search-param field enumeration (CVE-2025-30352), unauth version/schema leak (CVE-2025-53887) and GraphQL introspection. [npm](https://www.npmjs.com/package/directus-security)\n- [payload-security](https://github.com/Perufitlife/payload-security) — collections readable without auth, field-level leaks (`apiKey`/`email`/`hash`/`salt`), user enumeration and open first-user registration. [npm](https://www.npmjs.com/package/payload-security)\n\n## GraphQL\n\n- [hasura-security](https://github.com/Perufitlife/hasura-security) — open introspection without the admin secret, the anonymous `public` unauthorized role leaking tables/rows, an unauthenticated console and a missing admin secret. [npm](https://www.npmjs.com/package/hasura-security)\n\n## Workflow \u0026 Automation\n\n- [n8n-security](https://github.com/Perufitlife/n8n-security) — unauthenticated `/rest/settings` config+version leak, open owner-setup takeover, version vs known critical CVEs (CVE-2026-21858 \"Ni8mare\", CVSS 10.0) and no-auth editor/REST API. [npm](https://www.npmjs.com/package/n8n-security)\n\n## Local LLM / AI\n\n- [ollama-security](https://github.com/Perufitlife/ollama-security) — a publicly bound, unauthenticated Ollama API (175k+ found exposed) proven via anonymous probes of `/api/tags`, `/api/ps`, `/api/version` and CORS reflection — without downloading a model or running a workload. [npm](https://www.npmjs.com/package/ollama-security)\n- [dotclaude-security](https://github.com/Perufitlife/dotclaude-security) — scans a repo's `.claude/` config (hooks, MCP servers, env, permissions) for the RCE (CVE-2025-59536) and API-key-exfiltration (CVE-2026-21852) footguns that fire when you open an untrusted repo. [npm](https://www.npmjs.com/package/dotclaude-security)\n\n## Secrets \u0026 Exposure\n\n- [dotenv-exposure-check](https://github.com/Perufitlife/dotenv-exposure-check) — probes a live URL for accidentally-served secret artifacts (`.env`, `.git/`, `.js.map` source maps, `.DS_Store`, backups) and confirms each by fetching and fingerprinting the bytes. [npm](https://www.npmjs.com/package/dotenv-exposure-check)\n\n## MCP servers\n\n- [web-exposure-mcp](https://github.com/Perufitlife/web-exposure-mcp) — an MCP server that points an AI agent at a deployed URL and confirms which secret files are actually being served, by fetching the bytes and fingerprinting content (not trusting status codes). [npm](https://www.npmjs.com/package/web-exposure-mcp)\n\n## Reference reading\n\n- [OWASP API Security Top 10](https://owasp.org/API-Security/editions/2023/en/0x11-t10/)\n- [Supabase: securing your data with RLS](https://supabase.com/docs/guides/database/postgres/row-level-security)\n- [Firebase Security Rules](https://firebase.google.com/docs/rules)\n- [Strapi: Users \u0026 Permissions](https://docs.strapi.io/dev-docs/plugins/users-permissions)\n- [Hasura: the `HASURA_GRAPHQL_UNAUTHORIZED_ROLE` footgun](https://github.com/hasura/graphql-engine/issues/5501)\n- [Ollama has no authentication by default (CNVD-2025-04094)](https://github.com/ollama/ollama/issues/849)\n\n## Contributing\n\nFound a tool that fits — keyless, local-first, actively probes to confirm? PRs welcome. Keep entries one line, alphabetical within a section, with a `[npm]` link where published.\n\n## License\n\n[![CC0](https://licensebuttons.net/p/zero/1.0/88x31.png)](https://creativecommons.org/publicdomain/zero/1.0/)\n\nTo the extent possible under law, the contributors have waived all copyright and related rights to this work.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fperufitlife%2Fawesome-backend-security","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fperufitlife%2Fawesome-backend-security","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fperufitlife%2Fawesome-backend-security/lists"}