Nordik

How the Launch Risk Score is built

A passive check of one public URL, scored from 0 to 100. 100 means no check found a verified problem; it is not a claim that the site is secure. Rubric version 1.0.0.

What the scan does

  • Reads only. It loads the page, the scripts the page loads, robots.txt and a few well-known paths. It never logs in, writes, submits a form or reads a row of data, and it never uses a key it finds.
  • Supabase checks use only the public anon key the site itself ships: row-count requests that return a number, not data, and two read-only settings requests.
  • Polite. It honours robots.txt and waits at least one second between requests to the same host.
  • Masked. Secret values in the evidence are masked; a key that is found is reported, never used.

The score

score = max(0, 100 − the weight of every failed check)

Weights: critical 40, high 25, medium 10, low 5, info 0. A check that could not run (blocked by robots.txt, nothing to probe, or the request failed) costs nothing and is listed as not checked. If no check could run at all, there is no score. The same results always give the same score.

The checks

CheckSeverity and pointsA failed check showsIt does not show
Service-role token in public JavaScript
js_service_role_token
critical −40A fetched public script or page contains a Supabase service_role JWT or sb_secret_ key.That the token is still valid; the token is never used.
.env-style files served
env_files_exposed
critical −40A well-known env path answered a GET with KEY=VALUE-style text.What the values are (never recorded) or whether they are live.
Secret keys in public JavaScript
js_secret_keys
high −25A fetched public script or page contains a string in the format of a provider secret key (audit secret patterns).That the key is live or has any privilege; the key is never used.
Tables answering an anon count request
supabase_tables_anon_count
high −25A table named in the scripts answered an anon-key HEAD request with a row count above zero.What the rows contain (never requested), or the state of tables not named in the scripts.
Auth settings readable without login
supabase_auth_settings
medium −10The project auth settings endpoint answered without login and reported sign-up open with email auto-confirm on.That any account was created (no sign-up is ever submitted).
Storage buckets listed without login
supabase_storage_buckets
medium −10The storage bucket list endpoint answered an anon-key request with at least one bucket.That any object is readable (objects are never listed or fetched).
Security headers
security_headers
medium −10The page response lacks at least one of: HSTS (https), CSP, X-Content-Type-Options nosniff, frame protection, Referrer-Policy.That the site is exploitable; headers on other pages or paths were not read.
Source maps served
source_maps_exposed
medium −10A script's .map file answered a HEAD request with a non-HTML content type.What the map contains (not downloaded).
Supabase project and anon key present
supabase_exposure
info 0The page or its scripts name a Supabase project URL and an anon or publishable key (public by design).That any data is reachable; see the table check.

Limits

One page and its scripts, not a crawl. Keys are found by their format, so a key assembled at runtime is missed. A good score is not a clean bill of health: the full App Audit reads the code itself.