What Codex left exposed
4DNS misconfiguration and subdomain takeover
Subdomain takeover risk, dangling CNAME records, and misconfigured nameservers. These don't show up in a linter - they show up in an external scan.
Cloud storage exposed to the public
Public access on storage buckets. One misconfigured bucket can expose your entire data layer.
Missing HTTP security headers
HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Missing headers are the most common finding across all app types.
Overly permissive CORS
A frequent finding in apps where the API layer was added quickly. We check your cross-origin policies for over-permissive configurations.