senclaw/secscan

app Đánh giá tư thế bảo mật cho website và máy chủ CỦA CHÍNH MÌNH. Quét thụ động (L1): security header, cờ cookie, lộ thông tin phiên bản, tư thế DNS/email (SPF/DMARC/CAA/DNSSEC) — một GET duy nhất, không gửi payload tấn công nào, an toàn chạy trên production. Chấm điểm 0-100 và hạng A+..F theo khuôn MDN Observatory, kèm luật trần kiểu SSL Labs (một lỗi nặng kéo tụt hạng, không cho các mục tốt pha loãng). So được hai lần quét để biết cái gì mới, cái gì đã vá, cái gì tái phát. KHÔNG khai thác lỗ hổng, KHÔNG brute-force, KHÔNG DoS — đó là ranh giới thiết kế chứ không phải phần chưa làm. Tài sản phải xác minh quyền sở hữu (DNS TXT / CNAME / .well-known / thẻ meta) trước khi chạy được lớp chủ động

Install

senclaw app install senclaw/secscan

Verifies sha512 and SenClaw’s signature before writing to disk.

Documentation

This package has no README. Check the source repository below.

Declared permissions

{
  "network": [
    "127.0.0.1"
  ],
  "exec": [
    "./secscan"
  ]
}

Declared by the publisher, not enforced by SenClaw. The CLI compares this against what you already have installed and asks before anything widens.

Published by

@senclawtrusted
benji
44 packages · 0 downloads · member since 2026-07 · GitHub since 2015-06

The checkmark means SenClaw confirmed who this publisher is. It says nothing about whether their packages are safe.

About

Owner@senclaw
Latest1.0.0
Downloads (30d)0
Repositorygithub.com/NortonBen/senclaw-app

Versions

VersionTagsArtifactsPublished
1.0.0latestdarwin-arm64, linux-x64, win32-x642026-08-07

Artifacts · 1.0.0

PlatformFormatSignatureFileSize
darwin-arm64zipunsignedsecscan-app.zip3859 KB
linux-x64zipunsignedsecscan-app.zip4286 KB
win32-x64zipunsignedsecscan-app.zip4250 KB

Unsigned builds require sign-in to download and are not distributed to the auto-updater, because unsigned executables from a new domain get flagged as unsafe. Sign and notarize (macOS) or Authenticode-sign (Windows) to distribute publicly.

Auto-update endpoints

For a Tauri app — add to tauri.conf.json:

"endpoints": ["https://senclaw.bacnd.com/api/v1/updates/tauri/senclaw/secscan/{{target}}/{{arch}}/{{current_version}}"]

For an electron-updater app — generic provider URL:

https://senclaw.bacnd.com/updates/senclaw/secscan/stable

Only signed/notarized artifacts are offered as updates — a client fetches the update without credentials, and unsigned binaries are not publicly downloadable.

Something wrong with this package?

Report this package

Report this package

Tell us what is wrong and a moderator will look at it. Be specific — a report that names a version and a behaviour can be checked in minutes; one that says “looks sketchy” cannot be acted on at all.

Not about this package? Contact us instead. What happens to a report is described in reporting and moderation.

API: GET https://senclaw.bacnd.com/api/v1/packages/senclaw/secscan