Every guide here answers a finding Zoltra reports: what it actually means, the fix, and the command that proves the fix landed. The first three are worth shipping before anything else. The rest are the classes we see most often on real apps — including yours, probably.
No paywall, no account. Each post has the fix, the verification, and the common ways the mistake drifts back.
Three fixes that are worth shipping before anything else.
How NEXT_PUBLIC_ silently bakes keys into JavaScript sent to every visitor, why it matters more now that agents scrape everything, and the two-line rename that closes it.
Fix: rename to server-only · Verify: curl the bundle
2 · 8 min · Supabase / PostgresWhy a fresh table without Row Level Security is reachable by any granted role, how leaked anon keys make that worse, and the one policy pattern that fixes the common case.
Fix: enable RLS + revoke anon · Verify: one SELECT as anon
3 · 7 min · Route HandlersHow a quick endpoint that returns rows becomes a public data API, why auth on the frontend page does not cover the handler, and the one check that actually closes it.
Fix: check the caller · Verify: curl without a session
What each class of finding means, and how to close it.
Severity versus confidence, what the evidence means, which finding to fix first, and what a scan honestly cannot see.
Start here if you are new to the dashboard
Guide · 8 min · Any web appThe most common finding we report, explained header by header, with a copy-paste fix for Next.js and the curl command that verifies it.
Fix: next.config headers · Verify: curl -sI
Guide · 9 min · DNS, no codeSPF, DMARC, and CAA explained in order of application, including how to tighten DMARC without dropping your own receipts.
Fix: TXT records · Verify: dig
Guide · 10 min · Server-side fetchWhat SSRF does to a link-preview or webhook feature, what the loopback and callback findings prove, and the three-layer fix that holds up.
Fix: resolve-then-check · Verify: four curl cases
Guide · 9 min · Server codeTwo scary-sounding findings, explained without the drama — what the polite probes prove, what they do not, and the two patterns that close both classes.
Fix: parameterize + encode · Verify: retest
Guide · 6 min · One route handlerWhy an open redirect is worth ten quiet minutes, the same-origin helper that closes it, and the three hostile URLs to test against.
Fix: same-origin check · Verify: Location header
Zoltra investigates what your site exposes, opens fix pull requests for confirmed code-level vulnerabilities, and checks whether the repair worked after it shipped.
Researched from primary sources, with the boundary of what we can measure stated inside each piece. Zoltra Research →