Go to example tasks
Check n8n webhooks and forms for missing authentication
Find Webhook nodes that accept requests from anyone who learns the URL, with no authentication set and no IF, Switch, Filter or Code node wired directly after them to reject unknown callers. Also flags Form Trigger input that flows into an n8n expression downstream, which is the workflow shape CVE-2026-27493 exploits. One row per exposed entry point, each with the fix.
n8n Workflow Auditor - Linter & Security Reviewmediocre_interest/n8n-workflow-auditor
Severity
Rule ID
Rule
Category
+8 fieldsTextNumberBooleanListObject
Input
Workflow JSON
Rule set:security
Minimum severity:low
Output fields
Severity
Rule ID
Rule
Category
Workflow
Node
Node type
Finding
Parameter
Evidence (masked)
How to fix
Docs
Sign up on Apify01
Create your Apify account to access the n8n Workflow Auditor - Linter & Security Review.
Start the run02
The Actor will start running based on the input automatically.
Receive the output03
Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.
Integrate into your workflow04
The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.
