Blog

Things small teams leak and how to close them

Every guide here answers a finding Zoltra reports: what it actually means, the fix, and the command that proves the fix landed. The first three are worth shipping before anything else. The rest are the classes we see most often on real apps — including yours, probably.

No paywall, no account. Each post has the fix, the verification, and the common ways the mistake drifts back.

Start here

Three fixes that are worth shipping before anything else.

1 · 7 min · Browser bundle

Your browser bundle is leaking secrets — and you shipped it

How NEXT_PUBLIC_ silently bakes keys into JavaScript sent to every visitor, why it matters more now that agents scrape everything, and the two-line rename that closes it.

Fix: rename to server-only · Verify: curl the bundle

2 · 8 min · Supabase / Postgres

Your Supabase tables are readable by the world — until you turn this on

Why a fresh table without Row Level Security is reachable by any granted role, how leaked anon keys make that worse, and the one policy pattern that fixes the common case.

Fix: enable RLS + revoke anon · Verify: one SELECT as anon

3 · 7 min · Route Handlers

Your /api route is open and you have not noticed

How a quick endpoint that returns rows becomes a public data API, why auth on the frontend page does not cover the handler, and the one check that actually closes it.

Fix: check the caller · Verify: curl without a session

The finding guides

What each class of finding means, and how to close it.

Guide · 7 min · Reading a report

How to read your Zoltra report without a security background

Severity versus confidence, what the evidence means, which finding to fix first, and what a scan honestly cannot see.

Start here if you are new to the dashboard

Guide · 8 min · Any web app

The security headers your app is missing, and what each one actually does

The most common finding we report, explained header by header, with a copy-paste fix for Next.js and the curl command that verifies it.

Fix: next.config headers · Verify: curl -sI

Guide · 9 min · DNS, no code

Anyone can send email as your domain. Two DNS records mostly fix that

SPF, DMARC, and CAA explained in order of application, including how to tighten DMARC without dropping your own receipts.

Fix: TXT records · Verify: dig

Guide · 10 min · Server-side fetch

The “fetch this URL” feature can read your server from the inside

What SSRF does to a link-preview or webhook feature, what the loopback and callback findings prove, and the three-layer fix that holds up.

Fix: resolve-then-check · Verify: four curl cases

Guide · 9 min · Server code

When the scanner says injection: what error-based SQLi and reflected XSS actually mean

Two scary-sounding findings, explained without the drama — what the polite probes prove, what they do not, and the two patterns that close both classes.

Fix: parameterize + encode · Verify: retest

Guide · 6 min · One route handler

Your login link can be pointed anywhere, and your users cannot tell

Why an open redirect is worth ten quiet minutes, the same-origin helper that closes it, and the three hostile URLs to test against.

Fix: same-origin check · Verify: Location header

See what shippedFree scan

Zoltra investigates what your site exposes, opens fix pull requests for confirmed code-level vulnerabilities, and checks whether the repair worked after it shipped.

Latest writing

Researched from primary sources, with the boundary of what we can measure stated inside each piece. Zoltra Research →

How an API key escapes an AI-built Next.js app

A privileged key read inside a client component ends up in the public bundle. Here is how the leak happens and the three checks that catch it before launch.

· Zoltra Research