GuardMint Security ScanExample report

Your App · yourapp.vercel.app

Fix before launch

51/99 · Grade D

Security score · higher is better

We found issues to fix before you send real traffic. Fix must-fix items first, then re-scan after deploying changes.

Scanned
May 20, 2026
Scan type
External scan · no login

12 security areas checked

9 passed · 1 warning · 1 failed · 1 not tested

9Passed
1Warning
1Failed
1Not tested

3 findings found

1Must-fix1Review0Hardening1Notes

99 is the highest score for this external scan.

Security results

12 security areas

Problems first, each with what was found and how to fix it. Passed areas are collapsed at the end.

Failed (1)

Public API data exposure

High

High impact · 13 pts

1 issue to fix before launch — see findings below

Failed

/api/profiles returned JSON containing personal or business fields without authentication. If this isn't meant to be public, require a login first.

Affectedhttps://yourapp.vercel.app/api/profiles

Evidence

status
200
sensitive fields
email, name, user_id

Why it matters

Public API routes that return user, customer, or admin data without a login let anyone read information meant to be private.

Recommendation

Require authentication and authorization before returning this data, and confirm anonymous requests receive 401 or 403.

Where to fix it

Add an authentication and authorization check inside the API route handler (Next.js route handler or server action) before it returns any data.

Paste this into Claude Code, Cursor, or your AI coding tool

Review this public API route. Confirm whether it should be accessible without authentication. If it returns user, customer, case, payment, or admin data, require authentication and authorization before returning the response. Add tests that unauthenticated requests receive 401 or 403.

Warning (1)

Security headers

Medium

Medium impact · 10 pts

1 issue to review — see findings below

Warning

A Content-Security-Policy helps prevent cross-site scripting and content injection. It wasn't set.

Why it matters

Security headers are the browser-level guardrails that block common attacks like cross-site scripting and clickjacking.

Recommendation

Add a Content-Security-Policy header. Start in Content-Security-Policy-Report-Only mode, then enforce once nothing legitimate is blocked.

Where to fix it

Set these as response headers: in Next.js use the headers() function in next.config.js; on Vercel or Netlify you can also set them in vercel.json or netlify.toml.

Paste this into Claude Code, Cursor, or your AI coding tool

Add a Content-Security-Policy to my app. Propose a sensible starting policy for my framework, explain how to test it in report-only mode first, then enforce it.

Your Claude Code fix plan

Prioritized prompts you can paste into Claude Code or Cursor, top to bottom.

Phase 2 — High priority

  1. 1. Public API returns user or business data

Phase 3 — Medium & low

  1. 1. Missing Content-Security-Policy

Phase 4 — Retest checklist

After fixing, re-run the scan to confirm each finding is resolved. If an issue affected your score, your score should improve (higher is better). The full checklist is included in the copied plan.

Not tested (1)

Source maps

Low impact · not tested

Not reached — the scan budget was hit before source maps were checked. Re-run to test this area.

Not tested

Some areas could not be tested during this scan. This can happen if the site blocked requests, timed out, or the scan budget was reached. Re-scan to try again.

Scan limits

This was an unauthenticated external scan. It did not log in, submit forms, inspect private source code, or run dependency/CVE analysis.

GuardMint helps detect common launch-blocking risks, but no automated scan can guarantee full security. Always review critical findings with a qualified developer before launch.

See how GuardMint scans

Example Security Report | GuardMint