10 checks in this theme
Input validation & injection checks
SQL injection, XSS, SSRF, path traversal, mass assignment — 10 checks for the input-handling bugs AI-generated code ships with.
Input handling is where AI code breaks
The pattern repeats across frameworks: a route handler that trusts await request.json() straight into a database call, a query assembled by string interpolation, user-rendered HTML, a URL fetched because the client asked, a file upload with no type or size gate, a webhook processed without checking its signature, and a payment amount trusted from the client.
Why AI tools generate it
Validation exists for the happy path a demo needs, not for adversarial input. Models reproduce the request shapes from their training data — and those shapes are the well-behaved ones. Where a guard matters (an ownership check, a signature verify, a server-side price lookup), something else has to ask for it.
How the scan detects it
Static analysis over route handlers, database calls, render paths, and webhook receivers — looking for raw query interpolation, unsanitized rendering, user-controlled fetch targets, path joins, and bodies flowing into writes without validation. Deterministic and FN-biased: when code alone cannot prove a finding is real, it is labeled needs-triage rather than asserted.
The 10 checks
FAQ
DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.
Check your app — free
10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.
Run the free scan