DevMeth

10 checks in this theme

Input validation & injection checks

SQL injection, XSS, SSRF, path traversal, mass assignment — 10 checks for the input-handling bugs AI-generated code ships with.

Input handling is where AI code breaks

The pattern repeats across frameworks: a route handler that trusts await request.json() straight into a database call, a query assembled by string interpolation, user-rendered HTML, a URL fetched because the client asked, a file upload with no type or size gate, a webhook processed without checking its signature, and a payment amount trusted from the client.

Why AI tools generate it

Validation exists for the happy path a demo needs, not for adversarial input. Models reproduce the request shapes from their training data — and those shapes are the well-behaved ones. Where a guard matters (an ownership check, a signature verify, a server-side price lookup), something else has to ask for it.

How the scan detects it

Static analysis over route handlers, database calls, render paths, and webhook receivers — looking for raw query interpolation, unsanitized rendering, user-controlled fetch targets, path joins, and bodies flowing into writes without validation. Deterministic and FN-biased: when code alone cannot prove a finding is real, it is labeled needs-triage rather than asserted.

The 10 checks

IDCheckSeverity
C18SQL Injection Check — Is User Input Concatenated Into Your Queries?Critical
C19Unvalidated Input Check — Does Request Data Flow Straight Into Writes or Shell?High
C21Upload Endpoint Check — Does Your Upload Accept Any File, No Limits?High
C32Webhook Signature Check — Are Your Endpoints Verifying Providers?Critical
C33Mass Assignment Check — Can Users Overwrite Fields They Never Saw?Critical
C35Payment Amount Check — Can Customers Set Their Own Price?Critical
C38Raw HTML Render Check — Can a Chat Message Run Script in Another User's Browser?High
C39SSRF Check — Can Users Make Your Server Fetch Internal URLs?High
C40Secrets in Logs Check — Is Your Token in the Log Store?High
C44Path Traversal Check — Can /files/../../.env Read Your Secrets?High

FAQ

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan