xlogs, scanned by xlogs

After every deploy, and once a day, the same scanner you can run runs against xlogs.com. This page shows the result as it came back. Nothing is edited out: the minor findings we have not fixed are here too, and so is every check that could not complete.

Nothing serious found

Scanned Tue, 06 Oct 2026 21:05:09 UTC, after a deploy, in 4.4s, running engine commit 262f63a. 1 low.

Findings

  • Low Someone could send email that looks like it is from you at SPF. xlogs.com publishes no SPF record. This domain does not appear to receive mail, so the risk is spoofing only.

Every check, and what it found

CheckResultDetail
Database exposed to the publicNot applicableNo Supabase connection visible in this app's code, so there was no database to test
Secret keys shipped to the browserClearNo secrets in the 21 scripts we read, against 18 key formats
Protective security headersClearAll 5 headers we check were set
Auth tokens in browser storageClearNo token written to browser storage in the 21 scripts we read
Original source code downloadableClearNo public source map on the 21 bundles we checked
Private files served publiclyClearNone of the 6 private paths we requested returned that file
Dependency list served publiclyClearWe requested /package-lock.json and it was not served
Scripts from compromised CDNsClearThis page loads no third-party scripts, so there was nothing to compare
DNS pointing at something you lostClearNo CNAME on this hostname, so nothing could be left dangling
Other addresses on your domainClearNo other names listed in public certificate logs
Email spoofing protectionFoundMissing SPF or DMARC, so mail can be forged as your domain

Recent runs

WhenTriggerFindingsCould not complete
Tue, 06 Oct 2026 21:05:09 UTCafter a deploy1 low0
Tue, 06 Oct 2026 20:03:56 UTCafter a deploy1 low0
Tue, 06 Oct 2026 19:03:39 UTCafter a deploy1 low3

How this page is made

The scan runs on our servers with the same engine as every other scan, against a target fixed in code, so nobody can point it anywhere else. It runs at most once an hour. What each check sends is listed on the methodology page, and the story of the first time we scanned ourselves and fixed what it found is on before and after.