Craft Audit
An audit tool for Craft CMS projects. It checks Twig templates for N+1 queries, missing eager loading and XSS risks, scans for known Craft and plugin CVEs, and checks security headers.
- Role
- Creator
- Years
- 2026
- Status
- Source on GitHub
- Stack
Source on GitHub
- category
- Dev tools
- stack
- Node.js, TypeScript
The brief
Craft sites pick up slow queries, outdated plugins and security gaps that code review can miss.
The build
Static checks on templates and config, a plugin vulnerability list, an opt-in HTTP security headers check, a CSP generator, and a Craft 4 to 5 migration checker.