slopstopper-demo
Scanned 8/15/2026, 12:26:39 AM at commit d3fd109
Security (7)
- decisionnext@14.2.5 has known vulnerabilitiessev 10 · conf 0.90 · risk/effort 1.80
next@14.2.5 has known vulnerabilities
OSV.dev lists: GHSA-36qx-fr4f-26g5 (patched in 15.5.16), GHSA-3g8h-86w9-wvmq (patched in 15.5.16), GHSA-3h52-269p-cp9r (patched in 14.2.30), GHSA-3x4c-7xq6-9pq8 (patched in 15.5.14), GHSA-4342-x723-ch2f (patched in 14.2.32), GHSA-4633-3j49-mh5q (patched in 15.5.21), GHSA-4c39-4ccg-62r3 (patched in 15.5.21), GHSA-5j59-xgg2-r9c4 (patched in 14.2.35), GHSA-68g3-v927-f742 (patched in 15.5.21), GHSA-7gfc-8cq8-jh5f (patched in 14.2.15), GHSA-7m27-7ghc-44w9 (patched in 14.2.21), GHSA-89xv-2m56-2m9x (patched in 15.5.21), GHSA-8h8q-6873-q5fj (patched in 15.5.16), GHSA-955p-x3mx-jcvp (patched in 15.5.21), GHSA-9g9p-9gw9-jx7f (patched in 15.5.10), GHSA-c4j6-fc7j-m34r (patched in 15.5.16), GHSA-f82v-jwr5-mffw (patched in 14.2.25), GHSA-ffhc-5mcf-pf4q (patched in 15.5.16), GHSA-g5qg-72qw-gw5v (patched in 14.2.31), GHSA-g77x-44xx-532m (patched in 14.2.7), GHSA-ggv3-7p47-pfv8 (patched in 15.5.13), GHSA-gp8f-8m3g-qvj9 (patched in 14.2.10), GHSA-gx5p-jg67-6x7h (patched in 15.5.16), GHSA-h25m-26qc-wcjf (patched in 15.0.8), GHSA-h64f-5h5j-jqjh (patched in 15.5.16), GHSA-m99w-x7hq-7vfj (patched in 15.5.21), GHSA-mwv6-3258-q52c (patched in 14.2.34), GHSA-p9j2-gv94-2wf4 (patched in 15.5.21), GHSA-q4gf-8mx6-v5v3 (patched in 15.5.15), GHSA-qpjv-v59x-3qc4 (patched in 14.2.24), GHSA-vfv6-92ff-j949 (patched in 15.5.16), GHSA-wfc6-r584-vfw7 (patched in 15.5.16), GHSA-xv57-4mr9-wg8v (patched in 14.2.31). Resolved via `node_modules/next` — this may be a transitive/nested copy, not the top-level declared range.
at package.json
fix: Upgrades next to a patched version.
Check next's changelog for a patched release addressing GHSA-36qx-fr4f-26g5 (patched in 15.5.16), GHSA-3g8h-86w9-wvmq (patched in 15.5.16), GHSA-3h52-269p-cp9r (patched in 14.2.30), GHSA-3x4c-7xq6-9pq8 (patched in 15.5.14), GHSA-4342-x723-ch2f (patched in 14.2.32), GHSA-4633-3j49-mh5q (patched in 15.5.21), GHSA-4c39-4ccg-62r3 (patched in 15.5.21), GHSA-5j59-xgg2-r9c4 (patched in 14.2.35), GHSA-68g3-v927-f742 (patched in 15.5.21), GHSA-7gfc-8cq8-jh5f (patched in 14.2.15), GHSA-7m27-7ghc-44w9 (patched in 14.2.21), GHSA-89xv-2m56-2m9x (patched in 15.5.21), GHSA-8h8q-6873-q5fj (patched in 15.5.16), GHSA-955p-x3mx-jcvp (patched in 15.5.21), GHSA-9g9p-9gw9-jx7f (patched in 15.5.10), GHSA-c4j6-fc7j-m34r (patched in 15.5.16), GHSA-f82v-jwr5-mffw (patched in 14.2.25), GHSA-ffhc-5mcf-pf4q (patched in 15.5.16), GHSA-g5qg-72qw-gw5v (patched in 14.2.31), GHSA-g77x-44xx-532m (patched in 14.2.7), GHSA-ggv3-7p47-pfv8 (patched in 15.5.13), GHSA-gp8f-8m3g-qvj9 (patched in 14.2.10), GHSA-gx5p-jg67-6x7h (patched in 15.5.16), GHSA-h25m-26qc-wcjf (patched in 15.0.8), GHSA-h64f-5h5j-jqjh (patched in 15.5.16), GHSA-m99w-x7hq-7vfj (patched in 15.5.21), GHSA-mwv6-3258-q52c (patched in 14.2.34), GHSA-p9j2-gv94-2wf4 (patched in 15.5.21), GHSA-q4gf-8mx6-v5v3 (patched in 15.5.15), GHSA-qpjv-v59x-3qc4 (patched in 14.2.24), GHSA-vfv6-92ff-j949 (patched in 15.5.16), GHSA-wfc6-r584-vfw7 (patched in 15.5.16), GHSA-xv57-4mr9-wg8v (patched in 14.2.31), and confirm the upgrade doesn't break existing usage before bumping. If next isn't a direct dependency in package.json, add an "overrides" entry (npm) forcing it to a safe version instead of trying to edit a range that isn't there.
- decisionSupabase client used, no local RLS policy files foundsev 10 · conf 0.35 · risk/effort 0.70
Supabase client used, no local RLS policy files found
A Supabase client is initialized in this repo, but no SQL migration/policy files were found under supabase/. This may mean row-level security is unconfigured — or it may just be configured directly in the Supabase dashboard, which this heuristic can't see.
at lib/supabase.ts
fix: Confirm RLS is enabled on every table and review the actual policies in the Supabase dashboard.
In the Supabase dashboard, check Authentication > Policies for each table. Enable RLS and add explicit policies for select/insert/update/delete rather than leaving tables open.
- decisionlodash@4.17.15 has known vulnerabilitiessev 8 · conf 0.90 · risk/effort 1.44
lodash@4.17.15 has known vulnerabilities
OSV.dev lists: GHSA-29mw-wpgm-hmr9 (patched in 4.17.21), GHSA-35jh-r3h4-6jhm (patched in 4.17.21), GHSA-f23m-r3pf-42rh (patched in 4.18.0), GHSA-p6mc-m468-83gw (patched in 4.17.19), GHSA-r5fr-rjxr-66jc (patched in 4.18.0), GHSA-xxjr-mmjv-4gpg (patched in 4.17.23). Resolved via `node_modules/lodash` — this may be a transitive/nested copy, not the top-level declared range.
at package.json
fix: Upgrades lodash to a patched version.
Check lodash's changelog for a patched release addressing GHSA-29mw-wpgm-hmr9 (patched in 4.17.21), GHSA-35jh-r3h4-6jhm (patched in 4.17.21), GHSA-f23m-r3pf-42rh (patched in 4.18.0), GHSA-p6mc-m468-83gw (patched in 4.17.19), GHSA-r5fr-rjxr-66jc (patched in 4.18.0), GHSA-xxjr-mmjv-4gpg (patched in 4.17.23), and confirm the upgrade doesn't break existing usage before bumping. If lodash isn't a direct dependency in package.json, add an "overrides" entry (npm) forcing it to a safe version instead of trying to edit a range that isn't there.
- decisionpostcss@8.4.31 has known vulnerabilitiessev 8 · conf 0.90 · risk/effort 1.44
postcss@8.4.31 has known vulnerabilities
OSV.dev lists: GHSA-6g55-p6wh-862q (patched in 8.5.12), GHSA-fxqj-rqcc-2cmp (patched in 8.5.23), GHSA-qx2v-qp2m-jg93 (patched in 8.5.10), GHSA-r28c-9q8g-f849 (patched in 8.5.18). Resolved via `node_modules/postcss` — this may be a transitive/nested copy, not the top-level declared range.
at package.json
fix: Upgrades postcss to a patched version.
Check postcss's changelog for a patched release addressing GHSA-6g55-p6wh-862q (patched in 8.5.12), GHSA-fxqj-rqcc-2cmp (patched in 8.5.23), GHSA-qx2v-qp2m-jg93 (patched in 8.5.10), GHSA-r28c-9q8g-f849 (patched in 8.5.18), and confirm the upgrade doesn't break existing usage before bumping. If postcss isn't a direct dependency in package.json, add an "overrides" entry (npm) forcing it to a safe version instead of trying to edit a range that isn't there.
- guidedAPI route with no visible rate limitingsev 6 · conf 0.45 · risk/effort 0.90
API route with no visible rate limiting
app/api/tasks/route.ts accepts a mutating request with no rate-limiting library or identifier found anywhere in the file. Without one, a single client can hit this endpoint as fast as it wants — this may already be handled at the infrastructure/CDN level (e.g. Vercel's or Cloudflare's own edge rate limiting), which this heuristic can't see.
at app/api/tasks/route.ts
fix: Adds rate limiting to this route.
A library like @upstash/ratelimit (works well with Vercel's edge/serverless functions) or express-rate-limit (for a traditional Node server) can bound requests per IP/user with a few lines.
- guidedSession-cookie-authenticated route with no visible CSRF protectionsev 6 · conf 0.40 · risk/effort 0.80
Session-cookie-authenticated route with no visible CSRF protection
app/api/tasks/route.ts authenticates via a session cookie but has no CSRF marker anywhere in the file or a root middleware.ts. If this endpoint only accepts JSON via an explicit Authorization header rather than an auto-attached session cookie, this is likely a false positive — CSRF specifically targets cookie-authenticated requests.
at app/api/tasks/route.ts
fix: Adds CSRF protection to this route, or confirms SameSite cookie settings already cover it.
Set the session cookie's SameSite attribute to "lax" or "strict" (blocks most cross-site submissions), or add an explicit CSRF token check (e.g. via edge-csrf or csrf-csrf) for stronger protection.
- decision@supabase/auth-js@2.65.0 has known vulnerabilitiessev 4 · conf 0.90 · risk/effort 0.72
@supabase/auth-js@2.65.0 has known vulnerabilities
OSV.dev lists: GHSA-8r88-6cj9-9fh5 (patched in 2.70.0). Resolved via `node_modules/@supabase/auth-js` — this may be a transitive/nested copy, not the top-level declared range.
at package.json
fix: Upgrades @supabase/auth-js to a patched version.
Check @supabase/auth-js's changelog for a patched release addressing GHSA-8r88-6cj9-9fh5 (patched in 2.70.0), and confirm the upgrade doesn't break existing usage before bumping. If @supabase/auth-js isn't a direct dependency in package.json, add an "overrides" entry (npm) forcing it to a safe version instead of trying to edit a range that isn't there.
Reliability (4)
- auto-fixNo CI pipeline detectedsev 6 · conf 0.90 · risk/effort 5.40
No CI pipeline detected
No CI configuration (.github/workflows, .gitlab-ci.yml, .circleci/config.yml, azure-pipelines.yml, or a Jenkinsfile) was found in this repo. Without one, broken code has no automated gate before reaching production.
fix: Adds a CI pipeline that runs your test suite on every push/PR.
Run with --fix --repo <path> (or use the hosted app's auto-fix PR) to scaffold a GitHub Actions workflow (.github/workflows/ci.yml) that installs dependencies and runs whichever of lint/typecheck/test/build scripts your project already has.
- auto-fixNo app/error.tsx foundsev 6 · conf 0.85 · risk/effort 5.10
No app/error.tsx found
This looks like a Next.js App Router project with no app/error.tsx. Unhandled errors in a route will crash to a blank/default error page instead of a graceful fallback.
at app/error.tsx
fix: Adds a global app/error.tsx boundary.
Run with --fix --repo <path> to scaffold a standard app/error.tsx.
- guidedExternal call with no visible timeoutsev 6 · conf 0.45 · risk/effort 0.90
External call with no visible timeout
app/page.tsx:6 calls out to an external service with no timeout marker nearby. If that service hangs, this request can hang indefinitely.
at app/page.tsx:6
fix: Adds a timeout to this call.
fetch(url, { signal: AbortSignal.timeout(5000) }) — or the equivalent timeout option for your HTTP client — and handle the abort error explicitly.
- guidedPossible N+1 database querysev 6 · conf 0.40 · risk/effort 0.80
Possible N+1 database query
lib/dashboard.ts:8 calls a database/ORM method inside what looks like a loop. If this runs once per item in a collection, it can turn one page load into dozens or hundreds of individual queries.
at lib/dashboard.ts:8
fix: Batches this into a single query.
Replace the per-item call with one findMany({ where: { id: { in: [...] } } }) (or your ORM's equivalent batch/IN query) outside the loop.
Observability (2)
- auto-fixNo error-monitoring integration detectedsev 6 · conf 0.85 · risk/effort 5.10
No error-monitoring integration detected
No Sentry (or equivalent) dependency or script tag was found. Without this, exceptions thrown in production have nowhere to be logged or alerted on.
fix: Adds Sentry (or an equivalent error-monitoring service).
Run with --fix --repo <path> to scaffold Sentry config files and add @sentry/nextjs to package.json (then run npm install and set a real DSN).
- guidedNo uptime monitoring configuredsev 6 · conf 0.50 · risk/effort 1.00
No uptime monitoring configured
You told the intake that no uptime monitor is configured. Without one, an outage can go unnoticed until a user reports it.
fix: Set up a free uptime monitor pointed at your production URL.
Add a free monitor (e.g. UptimeRobot, Better Uptime, or your hosting provider's built-in monitor) that pings your production URL every few minutes and alerts you by email/SMS on failure.
Functional (1)
- guidedNo automated tests foundsev 8 · conf 0.85 · risk/effort 2.27
No automated tests found
No test files matching common npm conventions were found in this repo.
fix: Add a unit/integration test suite.
Add *.test.ts files alongside your source using vitest or jest (a common devDependency); start with the highest-risk business logic, not 100% coverage.