senclaw/secscan
app Đánh giá tư thế bảo mật cho website và máy chủ CỦA CHÍNH MÌNH. Quét thụ động (L1): security header, cờ cookie, lộ thông tin phiên bản, tư thế DNS/email (SPF/DMARC/CAA/DNSSEC) — một GET duy nhất, không gửi payload tấn công nào, an toàn chạy trên production. Chấm điểm 0-100 và hạng A+..F theo khuôn MDN Observatory, kèm luật trần kiểu SSL Labs (một lỗi nặng kéo tụt hạng, không cho các mục tốt pha loãng). So được hai lần quét để biết cái gì mới, cái gì đã vá, cái gì tái phát. KHÔNG khai thác lỗ hổng, KHÔNG brute-force, KHÔNG DoS — đó là ranh giới thiết kế chứ không phải phần chưa làm. Tài sản phải xác minh quyền sở hữu (DNS TXT / CNAME / .well-known / thẻ meta) trước khi chạy được lớp chủ động
Install
senclaw app install senclaw/secscan
Verifies sha512 and SenClaw’s signature before writing to disk.
Documentation
This package has no README. Check the source repository below.
Declared permissions
{
"network": [
"127.0.0.1"
],
"exec": [
"./secscan"
]
}Declared by the publisher, not enforced by SenClaw. The CLI compares this against what you already have installed and asks before anything widens.
Published by
The checkmark means SenClaw confirmed who this publisher is. It says nothing about whether their packages are safe.
About
| Owner | @senclaw |
| Latest | 1.0.0 |
| Downloads (30d) | 0 |
| Repository | github.com/NortonBen/senclaw-app ↗ |
Versions
| Version | Tags | Artifacts | Published |
|---|---|---|---|
1.0.0 | latest | darwin-arm64, linux-x64, win32-x64 | 2026-08-07 |
Artifacts · 1.0.0
| Platform | Format | Signature | File | Size |
|---|---|---|---|---|
darwin-arm64 | zip | unsigned | secscan-app.zip | 3859 KB |
linux-x64 | zip | unsigned | secscan-app.zip | 4286 KB |
win32-x64 | zip | unsigned | secscan-app.zip | 4250 KB |
Unsigned builds require sign-in to download and are not distributed to the auto-updater, because unsigned executables from a new domain get flagged as unsafe. Sign and notarize (macOS) or Authenticode-sign (Windows) to distribute publicly.
Auto-update endpoints
For a Tauri app — add to tauri.conf.json:
"endpoints": ["https://senclaw.bacnd.com/api/v1/updates/tauri/senclaw/secscan/{{target}}/{{arch}}/{{current_version}}"]For an electron-updater app — generic provider URL:
https://senclaw.bacnd.com/updates/senclaw/secscan/stable
Only signed/notarized artifacts are offered as updates — a client fetches the update without credentials, and unsigned binaries are not publicly downloadable.
Something wrong with this package?
Report this package
Report this package
Tell us what is wrong and a moderator will look at it. Be specific — a report that names a version and a behaviour can be checked in minutes; one that says “looks sketchy” cannot be acted on at all.
Not about this package? Contact us instead. What happens to a report is described in reporting and moderation.
API: GET https://senclaw.bacnd.com/api/v1/packages/senclaw/secscan