Webhook signature-verification audit. Stripe, GitHub, Shopify, Twilio +17. Local. Deterministic.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
The only scanner laser-focused on webhook signature verification.
Local. Deterministic. Zero-network. JS/TS + Python + PHP + Go. Five minutes from npx to fix.
No traffic leaves your machine. No telemetry. No SaaS sign-up required.
π Full documentation: docs.hookwarden.dev
Every Sunday at 22:00 UTC, this repo's CI runs hookwarden against 45 popular open-source projects β currently cal.com, documenso, formbricks, twenty, plane, unkey, typebot, papermark (full target list, combined β
190k+) β to prove the scanner works on real production code.
Latest sweep β 2026-06-09 Β· 20/45 projects clean (zero critical/high)
| Provider | π¨ critical | β οΈ high | π‘ manual-review | Rules that fired |
|---|---|---|---|---|
| n8n integrations | 81 | 0 | 0 | n8n/missing-signature-verification (Γ78)n8n/raw-body-misuse (Γ3) |
| Slack integrations | 7 | 1 | 0 | slack/missing-signature-verification (Γ7)slack/verify-after-side-effect (Γ1) |
| Standard Webhooks integrations | 7 | 0 | 0 | standardwebhooks/missing-signature-verification (Γ3)standardwebhooks/raw-body-misuse (Γ4) |
| Stripe integrations | 6 | 0 | 0 | stripe/hardcoded-secret-prefix (Γ2)stripe/missing-signature-verification (Γ4) |
| GitHub integrations | 0 | 0 | 0 | β |
| Shopify integrations | 0 | 0 | 0 | β |
| Square integrations | 0 | 0 | 0 | β |
| Twilio integrations | 0 | 0 | 0 | β |
These are bugs in the webhook handlers that receive provider events β flaws in the integrating projects' integration code, not in the providers' own SDKs or services.
Coverage note: the engine couldn't parse 238 files across the corpus (broken syntax or language features the parser doesn't model). Those are scan-coverage diagnostics β not handler bugs β and are excluded from the table above.
Hookwarden checks 11 rule classes across 21 providers β most of the corpus handles webhooks correctly, hence the short list. The full rule catalog lives in the docs.
Per-target findings are never published before responsible disclosure β see methodology. To run the same scan against your own code:
Every dollar of fraud that flows through a webhook starts with a verification bug β and verification bugs hide in plain sight.
A handler that accepts an unsigned payload, compares HMACs with ==, or skips the signature check on a ?test=true path silently routes attacker traffic into your business logic. The bug is one line in a 50K-line app, and it looks plausible β not the shape general-purpose SAST tools are tuned to flag. They were built for SQL injection and prototype pollution; webhook verification falls between their default rule packs.
hookwarden does one thing. It walks your repo, parses every webhook handler across 11 frameworks, and labels each one verified, not-verified, or manual-review β with the exact file, line, and a fix quoted from provider docs. The catalog (21 named providers β Stripe, GitHub, Shopify, Slack, Twilio, Square, Sentry, Zendesk, DocuSign, PagerDuty, Notion, Auth0, HubSpot, Intercom, Linear, Zoom, Calendly, Bitbucket, Mailchimp, Postmark, plus Standard Webhooks conformant providers like Clerk, Resend, Mux) encodes signature quirks no generic scanner has the surface area to know: Stripe's 5-minute timestamp tolerance, Slack's v0:${ts}:${body} scheme, Twilio's SHA-1 outlier.
The three-state verdict is not a hedge. manual-review is what you get when hookwarden can't prove safety or unsafety from the source alone β a handler inside a middleware chain the analyzer couldn't unroll, say. It's how the false-positive rate stays honest (<5%, measured against a 200-repo OSS corpus). A tool that reports every gray area as a bug isn't a security tool; it's noise. β How the verdict works
hookwarden is a CLI, not a library β run it with
npx hookwarden scan .or install globally withnpm i -g hookwarden. (The plainnpm i hookwardenthat npm auto-suggests on the package page installs it as a local dependency, which isn't what you want for a command-line tool.)
Or install natively:
| OS | Recommended | Alternates |
|---|---|---|
| Linux | brew install Hookwarden/tap/hookwarden | npm i -g hookwarden Β· pip install hookwarden Β· direct binary |
| macOS | brew install Hookwarden/tap/hookwarden | npm i -g hookwarden Β· npx hookwarden |
| Windows | scoop bucket add hookwarden https://github.com/Hookwarden/scoop-bucket && scoop install hookwarden | npm i -g hookwarden Β· pip install hookwarden |
Node 22+ is required for the npm/npx/macOS-brew paths; the standalone binaries (Linux x64/arm64, Windows x64) bundle the runtime. Direct binary downloads are intentionally unsigned (Gatekeeper / SmartScreen will warn) β prefer brew / scoop / npm / pip, which verify by SHA-256. β Install guide
| Channel | Command |
|---|---|
| brew (macOS/Linux) | brew upgrade hookwarden |
| scoop (Windows) | scoop update hookwarden |
| npm (global) | npm i -g hookwarden@latest |
| pip | pip install -U hookwarden |
| npx (no install) | npx hookwarden@latest scan . β @latest bypasses the npx cache |
| direct binary | re-download from Releases |
Rule pack versions move with the CLI (engine, rules, and CLI ship as a fixed group β 0.7.5 everywhere). Pin in CI with npx hookwarden@0.7.5 scan . if you want byte-stable verdicts across runs.
--diff-only, --provider stripe,github (phased rollout), --include/--exclude globs, --strict-suppressions, repo-level hookwarden.config.yaml, and more: npx hookwarden --help and the CLI docs.
--history)By default scan only looks at your working tree. --history also walks the
git history β including files that were committed then deleted before HEAD β
so a secret that was force-pushed away is still found. It's off by default and
bounded to the last 1000 commits; narrow it with --since <ref|date>:
--history is fully open-source and never requires a token.
--verify-secrets)--verify-secrets checks whether a leaked API-key-class credential is still
alive by making a single read-only call to the secret's own provider
(Stripe / GitHub) directly from your machine β hookwarden never sees the secret.
A live leak is escalated to critical; a dead (rotated/revoked) one is
downgraded to info. It's paid (team tier), off by default, and explicit
opt-in only.
whsec_, GitHub webhook secret) is always
reported unverified β no provider can confirm a signing secret's liveness.HOOKWARDEN_TOKEN, findings are reported unverified and no
provider call is made.hookwarden doesn't just name the fix β it applies it. The fix subcommand mechanically rewrites the safety: safe subset across JS/TS, Python, PHP, and Go (covering timing-unsafe comparisons β crypto.timingSafeEqual / hmac.compare_digest / hash_equals, and raw-body misuse). The other 188 rules are architectural and emit per-finding fix prose instead.
Every rewrite lands in a staging dir and is re-scanned before replacing the original; the fixer never edits inside strings or comments. β hookwarden fix Β· Safety levels
Captured verbatim β each line is what you'll see in your terminal, not a mockup. One Express middleware bug produces three findings, because that single mistake violates three distinct invariants; fixing one (re-ordering the middleware) clears all three:
| Glyph | Severity | SARIF level | Counts toward --fail-on? |
|---|---|---|---|
Γ | critical | error | yes |
! | high | error | yes |
β² | medium | warning | yes |
Β· | low | note | yes |
i | info | note | no β informational (e.g. library-verified) |
The state column is the three-state verdict. Output is also available as byte-stable JSON and SARIF 2.1.0 (round-trips through GitHub Code Scanning, dedupes via partialFingerprints). β Output formats & JSON schema
4 languages Β· 15 frameworks Β· 21 providers Β· 230 rules Β· 100% cited. Every rule carries β₯1 external citation (CWE / RFC / Svix / Stripe spec) alongside the provider's own docs β auditors and reviewers can follow any finding back to a stable external source. JS/TS parse with Babel; Python, PHP, and Go with tree-sitter (WASM).
| Language | Frameworks |
|---|---|
| JavaScript / TypeScript | Express Β· Hono Β· Fastify Β· Next.js |
| Python | Flask Β· FastAPI Β· Django |
| PHP | Laravel Β· Symfony Β· Slim Β· vanilla single-file |
| Go | net/http Β· chi Β· gin Β· echo |
Every rule carries fix guidance quoted from the provider's canonical security docs. Full per-rule reference and coverage matrix: docs.hookwarden.dev/rules.
Uploads SARIF to Code Scanning automatically; findings appear as PR annotations. Raw-CLI + SARIF-upload recipe, exit-code matrix, and diff-only PR scans: β CI integration guide.
hookwarden is specialized on purpose. The general-purpose scanners below are excellent β they're just not in this fight.
| Tool | What it does well | Webhook verification |
|---|---|---|
| semgrep | General-purpose SAST; flexible rules | Low signal β generic matching misses body-parsing order, timing-safe paths, SDK flows |
| snyk Code | Broad vuln detection (paid SaaS) | No webhook rules; doesn't model HMAC reachability |
| GitGuardian / TruffleHog | Secret-leak detection | Finds hardcoded secrets; doesn't audit whether verification is correct |
| Datadog Static Analysis | Broad SAST; good cloud signal | No webhook specialization; low-signal for this bug class |
| hookwarden | Webhook verification logic only | 230 rules (100% cited), 21 providers, three-state verdicts, <5% FP on a 200-repo corpus |
hookwarden is not a general-purpose SAST or DAST scanner β it won't find XSS, SQL injection, or memory-safety bugs, and it isn't trying to. Keep semgrep, CodeQL, or your DAST for those. Already running one? hookwarden is additive β it finds the one class of bug they weren't built to catch.
@hookwarden/mcp is a Model Context Protocol server that gives AI coding agents the scan_handler tool. Paste in any webhook handler, get back the same 3-state verdict (verified / not-verified / manual-review) the CLI would emit β fully local, deterministic, no traffic leaves the agent's machine.
The rule pack is bundled inline, content-hashed, and version-pinned to the engine β scan_handler cross-checks both on every call and fails loudly on drift. β @hookwarden/mcp on npm
A pnpm monorepo with a strict, CI-enforced dependency boundary: the engine is pure-functional (no I/O, no filesystem, no network), so the same engine runs in the CLI, in CI, in the MCP server, and β eventually β in a browser playground without modification.
| Package | Purpose | License |
|---|---|---|
@hookwarden/engine | Handler discovery, reachability analysis, evidence collection. Pure-functional, browser-safe. | Apache 2.0 |
@hookwarden/rules | Provider catalog, YAML rule packs, parameterized predicate factories. | Apache 2.0 |
@hookwarden/fix | Auto-remediation β bounded location for AST mutation (Babel traverse + generator). | Apache 2.0 |
@hookwarden/mcp | Model Context Protocol server β scan_handler tool for AI coding agents. | Apache 2.0 |
hookwarden | CLI binary β reads config, drives the engine, renders text/JSON/SARIF. | Apache 2.0 |
dependency-cruiser enforces the engine's I/O boundary in every PR.
@hookwarden/mcp developer preview (Model Context Protocol server exposing scan_handler to Claude Code, Cursor, Continue, and the Anthropic Agent SDK β pasted handler code returns a 3-state verdict locally, zero-network, deterministic). β MCP serverrefs βΊ block per finding; JSON envelope gains scan.findings[].references: string[]. v0.7.1 cited every rule; v0.7.2 makes citations actually visible to scan consumers).hookwarden fix auto-remediation (mechanical AST rewrites, safe/manual-only per rule).--provider filter for phased rollout.Rule-pack PRs are the highest-value contribution β adding a provider is a catalog edit plus N rule YAMLs, no new TypeScript in most cases. See the existing 21 in packages/rules/rules/ as worked examples, and CONTRIBUTING.md.
Bug reports & feature requests: open an issue. Docs: docs.hookwarden.dev Β· hookwarden.dev.
To add yourself after a merged PR, comment
@all-contributors please add @<username> for <contribution>.
Apache 2.0 β see LICENSE. The CLI, engine, and rule packs are open source and will stay that way. A separate closed-source SaaS tier handles continuous monitoring, secret-leak scanning, automated rotation, and SOC 2 evidence export β hookwarden.dev.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/hookwarden-webhook-integrity)<a href="https://allmcps.com/mcp/hookwarden-webhook-integrity"><img src="https://allmcps.com/api/badge/hookwarden-webhook-integrity?style=directory" alt="Hookwarden β Webhook Integrity on AllMCPs" /></a>