All services

Protect what you run · Security

Find the risks before someone else does.

Vulnerable packages, leaked secrets, unpatched servers, weak domains and attacks, found on the servers and code you already run here, with the fix beside each one.

  • Vulnerable dependencies
  • Leaked secrets
  • Server hardening and updates
  • Attacks blocked automatically

Security score

storefront · production

Grade B

Open findings by severity, with the fix beside each one.

Score
84
Critical
0
High
1

Illustrative interface with sample data.

Works with

  • Composer
  • npm
  • OSV
  • Ubuntu
  • Cloudflare
  • TLS
  • SPF and DMARC
  • SOC 2 evidence

Protect what you run

Security that knows what you run.

Your code and packages

Known vulnerabilities in Composer and npm packages, and secrets committed by mistake, checked on every deploy.

Your servers

SSH settings, open ports, pending security updates and who has access, graded, with one-click fixes.

Your domains

Certificates, TLS versions, security headers, SPF and DMARC, and DNS records that could be taken over.

Attacks and audits

Brute-force and scanning blocked automatically, access reviews, and compliance evidence ready for auditors.

Inside Security

What you can do

Code

Ship without known holes

Problems in what you deploy, found before and after it goes live.

  • Dependency scanning

  • Deploy gate

  • Secret scanning

Servers

Hardened and patched

The servers you run here, checked like an auditor would.

  • Hardening score

  • Security updates

  • Team SSH keys

Edge

Domains and traffic

What the internet sees, and who’s knocking.

  • Domains and email

  • Firewall and bots

  • Attack blocking

Compliance

Ready for the questionnaire

Evidence from what the platform already records.

  • Access reviews

  • Compliance reports

A practical path through Security

Turn on. Scan. Fix.

Security uses what you already manage here, so there’s nothing to install.

  1. 01

    Turn on Security

    Switch it on for a project; the first scans start straight away.

  2. 02

    Read the findings

    See the most serious problems first, each with what to do about it.

  3. 03

    Fix and confirm

    Apply the fix, run the check again, and watch the finding clear.

Safety and accountability

Careful with what it touches.

Checks read what they need and change nothing unless you choose a fix. Findings about secrets never show the secret itself.

  • Read-only checks
  • Fixes only when you choose
  • Secrets never displayed
  • Ignored with a reason
  • Recorded in the audit log
  • Your servers and accounts

Good to know

Straight answers about Security.

Do I need to install anything?

No. Security reads what BuildPusher already manages: your deploys, servers and domains.

Will it change my servers?

Only when you choose a fix, or turn on automatic blocking or updates.

Where does vulnerability data come from?

The open OSV database, which collects advisories for Composer, npm and more.

Part of BuildPusher

Start with Security.

Every service has a free tier. Turn on the others when a project needs them, on the same account and bill.

Start free