zexahq/better-auth-starter
No critical or high-risk findings. 1 worth a look.
2 warnings in the paths between 3 routes and 4 tables.
Every file was read, but 1 place in them could not be parsed — listed at the end of this report.
- ROUTES
- 3
- TABLES
- 4
- FILES READ
- 67/67
- RULES RUN
- 12/12
2 findings
1 medium1 low
Server Action loginUser (src/app/auth/login/action.ts) has no validator or rate limiter attached.
Server Action loginUser (src/app/auth/login/action.ts) is a public POST endpoint: it accepts whatever arguments a caller sends, as often as they send them.
- Missing
- Schema validation of the action's arguments, and a rate limit.
- Confidence
- Inline validation (zod.parse on the form data) and platform rate limits are not always visible to the parser. Check before acting.
Fix
const Input = z.object({ title: z.string().min(1).max(200) }); export async function loginUser(formData: FormData) { const parsed = Input.safeParse(Object.fromEntries(formData)); if (!parsed.success) return { error: parsed.error.flatten() }; // ...use parsed.data, never formData directly }Intended? If validation and rate limiting happen upstream (Vercel Firewall, a middleware), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guardedGET /api/admin/users has no validator or rate limiter attached.
GET /api/admin/users can be called at any rate. Cheap to fix, rarely urgent on a read.
- Missing
- A rate limit.
- Confidence
- Inline validation (zod.parse, pydantic models) and platform rate limits are not always visible to the parser. Check before acting.
Fix
// 60 requests per IP per minute. app.get("/api/admin/users", rateLimit({ windowMs: 60_000, limit: 60 }), handler);Intended? If validation and rate limiting happen upstream (an API gateway, Vercel Firewall), turn the rule off for the repo:
{ "policy": { "rules": { "public-entry-guarded": "off" } } }in wyro.json.public-entry-guarded
1 place could not be parsed, so any route or table declared there is missing from this report:
src/app/api/auth/[...all]/route.ts— Next route file exports no recognised method handler
Free account, no card. The repository opens as an editable graph.
Add this check to the README
[](https://wyro.in/scan/zexahq/better-auth-starter)It updates itself whenever the repository changes and links back to this report.
What this is
Wyro reads the repository’s routes and data models and checks the paths between them: whether a route can reach a table without passing a guard, whether a datastore holding personal data is exposed to a public read, whether an endpoint that issues credentials requires the credentials it issues.
It is rule-based, not a model. The same commit produces the same result every time, and it does not guess at business rules it cannot see. A rule with nothing to look at is reported as not having run — never as a pass.
This check runs on public source through GitHub’s own API and needs no account. A free account adds the editable architecture canvas, private repositories on paid plans, and a CI gate. No card required.
Maintain this repository? You can have this report removed, and a real vulnerability is disclosed to you privately before it is published. How public reports are handled.