Security Audit Report
App Router
154
Routes
68
Query Params
82
Custom Headers
Credentials or API keys may be exposed in client-side code.
User input rendered without proper sanitization.
Database queries constructed using unsanitized user input.
Untrusted data deserialized without validation.
Endpoints lack proper authorization checks.
User input rendered without proper sanitization.
Database queries constructed using unsanitized user input.
Untrusted data deserialized without validation.
Endpoints lack proper authorization checks.
User input rendered without proper sanitization.
Database queries constructed using unsanitized user input.
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/all-providers
Remediation
Review if this endpoint should require authentication
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/llms-full-txt-proxy
Remediation
Review if this endpoint should require authentication
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/models
Remediation
Review if this endpoint should require authentication
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/models/find
Remediation
Review if this endpoint should require authentication
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/provider-filters
Remediation
Review if this endpoint should require authentication
Endpoint is accessible without authentication (HTTP 200)
Endpoint is accessible without authentication (HTTP 200)
Location
https://openrouter.ai/api/frontend/providers
Remediation
Review if this endpoint should require authentication