DevMeth

12 checks in this theme

Authentication & access control, checked

Open admin pages, authless API routes, weak JWT secrets, IDOR, client-side role checks — 12 checks for the auth gaps AI tools leave behind.

The gap between having login and enforcing access

Generated apps look authenticated because they have a login page. The failures live one layer deeper: an API route with no server-side check, an admin page reachable while logged out, roles rendered from client-side state, JWTs verified against a weak or default secret, password reset tokens built from timestamps, and paid endpoints that never ask who is asking.

Why AI tools generate it

The demo path is always authenticated — the person prompting is logged in as the admin. Enforcement on every other route is invisible in a demo and never requested, so it never gets written. Roles end up checked in the client because that is where the UI lives; rate limiting and ownership checks are nobody's prompt.

How the scan detects it

Static analysis over your route handlers, middleware, and client code: which routes exist, which have server-side checks, where roles are consulted, how tokens and reset tokens are minted and verified. Deterministic, evidence-cited, and masked — and we never attempt a login or an auth bypass against your live app.

The 12 checks

IDCheckSeverity
C12Authless Route Handler Check — Does Your API Trust Anyone Who Calls?Critical
C13Open Admin Page Check — Is Your Dashboard Behind a Login?Critical
C14JWT Misuse Check — Can Your Session Tokens Be Forged or Stolen?High
C15Login Rate Limit Check — Can Your Auth Endpoints Be Sprayed?High
C16Password Reset Token Check — Are Your Reset Links Guessable?High
C17Client-Side Role Check — Do You Trust the Browser for Who's Admin?Critical
C31IDOR Check — Can Users Reach Each Other's Records by Changing an Id?Critical
C34Password Storage Check — Are Passwords Actually Hashed Before Saving?Critical
C37Math.random() Token Check — Are Your Tokens Actually Unguessable?High
C42OAuth State Check — Is Your Social Login CSRF-Proof?High
C46Seed Credentials Check — Does admin/admin123 Still Work?High
C47JWT Secret Check — Can Anyone Forge Your Session Tokens?High

FAQ

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan