xlogs, scanned by xlogs
After every deploy, and once a day, the same scanner you can run runs against xlogs.com. This page shows the result as it came back. Nothing is edited out: the minor findings we have not fixed are here too, and so is every check that could not complete.
Nothing serious found
Scanned Tue, 06 Oct 2026 21:05:09 UTC, after a deploy, in 4.4s, running engine commit 262f63a. 1 low.
Findings
- Low Someone could send email that looks like it is from you at
SPF. xlogs.com publishes no SPF record. This domain does not appear to receive mail, so the risk is spoofing only.
Every check, and what it found
| Check | Result | Detail |
|---|---|---|
| Database exposed to the public | Not applicable | No Supabase connection visible in this app's code, so there was no database to test |
| Secret keys shipped to the browser | Clear | No secrets in the 21 scripts we read, against 18 key formats |
| Protective security headers | Clear | All 5 headers we check were set |
| Auth tokens in browser storage | Clear | No token written to browser storage in the 21 scripts we read |
| Original source code downloadable | Clear | No public source map on the 21 bundles we checked |
| Private files served publicly | Clear | None of the 6 private paths we requested returned that file |
| Dependency list served publicly | Clear | We requested /package-lock.json and it was not served |
| Scripts from compromised CDNs | Clear | This page loads no third-party scripts, so there was nothing to compare |
| DNS pointing at something you lost | Clear | No CNAME on this hostname, so nothing could be left dangling |
| Other addresses on your domain | Clear | No other names listed in public certificate logs |
| Email spoofing protection | Found | Missing SPF or DMARC, so mail can be forged as your domain |
Recent runs
| When | Trigger | Findings | Could not complete |
|---|---|---|---|
| Tue, 06 Oct 2026 21:05:09 UTC | after a deploy | 1 low | 0 |
| Tue, 06 Oct 2026 20:03:56 UTC | after a deploy | 1 low | 0 |
| Tue, 06 Oct 2026 19:03:39 UTC | after a deploy | 1 low | 3 |
How this page is made
The scan runs on our servers with the same engine as every other scan, against a target fixed in code, so nobody can point it anywhere else. It runs at most once an hour. What each check sends is listed on the methodology page, and the story of the first time we scanned ourselves and fixed what it found is on before and after.
