Security score
storefront · production
Open findings by severity, with the fix beside each one.
- Score
- 84
- Critical
- 0
- High
- 1
Illustrative interface with sample data.
Protect what you run · Security
Vulnerable packages, leaked secrets, unpatched servers, weak domains and attacks, found on the servers and code you already run here, with the fix beside each one.
storefront · production
Open findings by severity, with the fix beside each one.
Illustrative interface with sample data.
Protect what you run
Known vulnerabilities in Composer and npm packages, and secrets committed by mistake, checked on every deploy.
SSH settings, open ports, pending security updates and who has access, graded, with one-click fixes.
Certificates, TLS versions, security headers, SPF and DMARC, and DNS records that could be taken over.
Brute-force and scanning blocked automatically, access reviews, and compliance evidence ready for auditors.
Inside Security
A closer look at what Security does, grouped by the work it supports.
Code
Problems in what you deploy, found before and after it goes live.
Servers
The servers you run here, checked like an auditor would.
Edge
What the internet sees, and who’s knocking.
Compliance
Evidence from what the platform already records.
A practical path through Security
Security uses what you already manage here, so there’s nothing to install.
Switch it on for a project; the first scans start straight away.
See the most serious problems first, each with what to do about it.
Apply the fix, run the check again, and watch the finding clear.
Safety and accountability
Checks read what they need and change nothing unless you choose a fix. Findings about secrets never show the secret itself.
Better together
Good to know
No. Security reads what BuildPusher already manages: your deploys, servers and domains.
Only when you choose a fix, or turn on automatic blocking or updates.
The open OSV database, which collects advisories for Composer, npm and more.
Part of BuildPusher
Every service has a free tier. Turn on the others when a project needs them, on the same account and bill.