Insecure Defaults
84/100
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
Reviewed on v2026-05-16 - latest is v0.3.1. Scores may not reflect the current version.
Review Scores
Security31/35
Maintain.29/35
Usability24/30
Evidence:
high
Reviewed May 27, 2026Newer version available
Reviewed Version
2026-05-16
Latest Version
0.3.1(drift)
Newer version available
The review covers 2026-05-16; the latest version is 0.3.1. Recheck changes before installing.
Scores reflect the version reviewed and may change with updates.
Security Audit - No Flags Reported
Audited May 27, 2026More by Trail of Bits
- Static Analysis SkillSkill90/100
- Variant AnalysisSkill90/100
- Constant Time AnalysisSkill90/100
- Semgrep AnalysisSkill90/100