shadowaudit

Frequently Asked Questions

Everything you need to know about shadowaudit.

How does shadowaudit detect shadow API routes?▾
shadowaudit performs static analysis of your source code — no runtime probing needed. It parses framework-specific route definitions (Express routers, Rails routes.rb, Django URL patterns, FastAPI decorators, etc.) and compares them against your OpenAPI/Swagger specification. Any route that exists in code but is absent from the spec is flagged as a "shadow route" — a leading indicator of undocumented attack surface. The scanner also checks whether each route has authentication middleware applied. As of v1.6.0, every finding is mapped to its OWASP API Security Top 10 (2023) category (API1-API10) so you can cite the relevant risk in security reports.
Which frameworks does shadowaudit support?▾
shadowaudit currently supports 8 frameworks: Express, FastAPI, Django, Flask, NestJS, Rails, Grape, and Spring Boot. Each framework has a dedicated scanner that understands its routing patterns, middleware chains, and authentication conventions. The CLI auto-detects your framework, or you can specify it with --framework. We are actively adding more frameworks — vote for the next one on our GitLab issues.
What is the difference between Open Source, Pro, and Enterprise?▾
Open Source (free, forever) includes the full MIT-licensed CLI: all 8 frameworks, table/JSON/SARIF/Markdown output, GitHub Actions inline annotations, OWASP API Top 10 (2023) mapping, a 0-100 risk score per scan, .shadowauditignore support, and CI/CD exit codes. Pro is the single paid tier — it adds the hosted layer: cloud sync with the web dashboard, scan history and trends, diff reports between deploys, ABOM PDF reports, unlimited share links, email alerts on critical findings, and priority email support. Pro is $19/mo or $179/yr for the first 20 members (the founding rate, locked for life), then $40/mo or $384/yr at the standard rate. Enterprise is the custom tier — SSO/SAML, team seats, custom scanners, compliance reporting, and an SLA — priced individually; contact arifubaid0345@proton.me for a quote. The CLI is fully functional without paying — paid tiers are for teams that need collaboration, reporting, and audit trails.
What happens when the 20 founding slots are full?▾
The switch happens automatically — no manual step, no waiting on us. The pricing page and every checkout link flip to the standard rate: Pro becomes $40/mo or $384/yr, paid through the new payment links. Founding members are unaffected — they keep paying $19 or $179 forever from their original subscription, even if prices rise later. Cancelling a Founding subscription forfeits the locked rate — resubscribing later happens at the then-current price.
What is the risk score and how is it calculated?▾
Every scan ends with a 0-100 risk score in the summary box. Formula: 100 − (critical findings × 15) − (high findings × 7) − (info findings × 1), capped at 0. The score is broken into 4 bands: 0-30 CRITICAL RISK (red), 31-60 HIGH RISK (yellow), 61-80 MEDIUM RISK (blue), 81-100 LOW RISK (green). The score is recalculated after .shadowauditignore filtering, so excluding intentional routes (health checks, metrics) gives you an accurate picture of your real API risk.
How does the OWASP API Top 10 mapping work?▾
shadowaudit maps each finding to the most relevant OWASP API Security Top 10 (2023) category using a heuristic based on severity, HTTP method, and auth status. For example: a CRITICAL finding on a destructive route (POST/PUT/PATCH/DELETE) with no auth maps to API5 (Broken Function Level Authorization / BFLA). A CRITICAL GET with no auth maps to API1 (Broken Object Level Authorization / BOLA). Undocumented routes map to API9 (Improper Inventory Management / Shadow APIs). The full OWASP reference is printed at the bottom of every scan so you can copy it into security reports. We cover 4 of the 10 categories today and publish exactly which on our coverage page.
Is my source code sent to your servers?▾
No. shadowaudit runs locally in your environment via the CLI. It scans your code on your machine and only uploads the findings (route inventory, severity counts, file paths, line numbers) to the dashboard if you explicitly run with --cloud. The source code itself never leaves your machine. If you prefer zero cloud, use --format json and keep results locally. Your scan data is encrypted at rest (AES-256) and in transit (TLS 1.3). You can delete your data at any time.
Can I cancel my subscription at any time?▾
Yes. You can cancel anytime through Suby or by contacting support. Cancellation takes effect at the end of your current billing period — you retain Pro access until then. No early-termination fees. If you cancel, your scan data is retained for 90 days in case you resubscribe, then permanently deleted.
What if I lose my token?▾
If you lose your dashboard link, enter your subscription email at our recovery page and we'll send your dashboard link instantly. The email must match the one you used when subscribing. If you no longer have access to that email, contact support at ubaid0345@proton.me with proof of payment.

Still have questions?

We respond to support emails within 24 hours.

Contact support