Preflyt - Post-Deploy Security Scan
After deploying a web app, API, or backend to a public URL, run a Preflyt scan to detect exposed secrets, misconfigurations, and unsafe defaults.
When to use this
- After deploying a web application to production or staging
- After deploying a backend API (Node, Python, Go, etc.)
- After any infrastructure change that exposes a new URL
How to run a scan
npx preflyt-check https://your-deployed-url.com
With options:
# Fail if issues found (for CI/CD)
npx preflyt-check https://your-deployed-url.com --fail
# Generate a shareable report link
npx preflyt-check https://your-deployed-url.com --share
# With Pro license for unlimited scans
npx preflyt-check https://your-deployed-url.com --key YOUR_LICENSE_KEY
Exit codes:
- 0: scan completed, no issues (or issues found without --fail)
- 1: issues found with --fail set, or scan error
What it checks
- Exposed .env and config files (database passwords, API keys)
- Exposed .git repositories (source code leakage)
- Exposed backend source code (app.py, server.js, config.php served as static files)
- Exposed database files (dynamic detection using project name - {name}.db, {name}.sqlite3)
- Open database ports (MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch)
- Directory listing detection and dangerous file parsing
- Exposed admin panels and debug endpoints
- Missing security headers (HSTS, CSP, X-Frame-Options, CORS)
- Exposed backup files and source maps
- Server version leakage
- Insecure cookie flags
What it does NOT do
- Does not scan source code or local files
- Does not perform exploit attempts
- Does not test authentication logic
- Does not scan localhost or private networks
- Does not read or transmit any local environment variables, files, or code
Privacy
- Without --share: all results display in the terminal only. No data is sent to preflyt.dev beyond the initial scan request containing the target URL.
- With --share: scan results are uploaded to preflyt.dev and a public report link is generated (valid 30 days).
- The scan sends only the target URL to api.preflyt.dev. No local files, code, or environment variables are transmitted.
- The npm package is open source and zero-dependency: https://github.com/doureios39/preflyt-check
Integration examples
Deploy script
#!/bin/bash
git pull
npm run build
pm2 restart app
sleep 5
npx preflyt-check https://mysite.com --fail || echo "Security issues found"
Git hook (post-receive)
#!/bin/bash
# .git/hooks/post-receive
git pull
npm run build
pm2 restart app
sleep 5
npx preflyt-check https://mysite.com
GitHub Actions
- name: Security scan
run: npx preflyt-check ${{ env.DEPLOY_URL }} --fail
Agent behavior
When a deployment to a public URL is detected:
- Run
npx preflyt-check <deployed-url>
- If HIGH severity findings exist, recommend immediate fix
- If MEDIUM or LOW findings, inform the user and suggest fixes
- If no findings, confirm deployment appears safe
- Never let a Preflyt error block a deployment - if the scan fails, report the error and move on
Notes
1---2name: preflyt3description: Scan deployed web apps for security misconfigurations after every deploy. Checks for exposed .env files, databases, source code, open ports, missing security headers, .git exposure, directory listings, and more. Non-intrusive, read-only.4---56# Preflyt - Post-Deploy Security Scan78After deploying a web app, API, or backend to a public URL, run a Preflyt scan to detect exposed secrets, misconfigurations, and unsafe defaults.910## When to use this1112- After deploying a web application to production or staging13- After deploying a backend API (Node, Python, Go, etc.)14- After any infrastructure change that exposes a new URL1516## How to run a scan1718```bash19npx preflyt-check https://your-deployed-url.com20```2122With options:23```bash24# Fail if issues found (for CI/CD)25npx preflyt-check https://your-deployed-url.com --fail2627# Generate a shareable report link28npx preflyt-check https://your-deployed-url.com --share2930# With Pro license for unlimited scans31npx preflyt-check https://your-deployed-url.com --key YOUR_LICENSE_KEY32```3334Exit codes:35- 0: scan completed, no issues (or issues found without --fail)36- 1: issues found with --fail set, or scan error3738## What it checks3940- Exposed .env and config files (database passwords, API keys)41- Exposed .git repositories (source code leakage)42- Exposed backend source code (app.py, server.js, config.php served as static files)43- Exposed database files (dynamic detection using project name - {name}.db, {name}.sqlite3)44- Open database ports (MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch)45- Directory listing detection and dangerous file parsing46- Exposed admin panels and debug endpoints47- Missing security headers (HSTS, CSP, X-Frame-Options, CORS)48- Exposed backup files and source maps49- Server version leakage50- Insecure cookie flags5152## What it does NOT do5354- Does not scan source code or local files55- Does not perform exploit attempts56- Does not test authentication logic57- Does not scan localhost or private networks58- Does not read or transmit any local environment variables, files, or code5960## Privacy6162- Without --share: all results display in the terminal only. No data is sent to preflyt.dev beyond the initial scan request containing the target URL.63- With --share: scan results are uploaded to preflyt.dev and a public report link is generated (valid 30 days).64- The scan sends only the target URL to api.preflyt.dev. No local files, code, or environment variables are transmitted.65- The npm package is open source and zero-dependency: https://github.com/doureios39/preflyt-check6667## Integration examples6869### Deploy script70```bash71#!/bin/bash72git pull73npm run build74pm2 restart app75sleep 576npx preflyt-check https://mysite.com --fail || echo "Security issues found"77```7879### Git hook (post-receive)80```bash81#!/bin/bash82# .git/hooks/post-receive83git pull84npm run build85pm2 restart app86sleep 587npx preflyt-check https://mysite.com88```8990### GitHub Actions91```yaml92- name: Security scan93 run: npx preflyt-check ${{ env.DEPLOY_URL }} --fail94```9596## Agent behavior9798When a deployment to a public URL is detected:991. Run `npx preflyt-check <deployed-url>`1002. If HIGH severity findings exist, recommend immediate fix1013. If MEDIUM or LOW findings, inform the user and suggest fixes1024. If no findings, confirm deployment appears safe1035. Never let a Preflyt error block a deployment - if the scan fails, report the error and move on104105## Notes106107- All checks are read-only and non-intrusive108- Scans take approximately 15-30 seconds109- Free tier: 3 scans. Pro ($9.99/mo): unlimited110- Website: https://preflyt.dev111- npm: https://www.npmjs.com/package/preflyt-check112- Source: https://github.com/doureios39/preflyt-check