Scan n8n Code nodes and expressions for injection
Check the JavaScript and expressions inside a workflow, not just its node settings. Flags expressions reaching for the host runtime through a constructor chain, process.env, require() or globalThis (the pattern behind CVE-2025-68613), values interpolated into an Execute Query field instead of query parameters, and Code nodes calling the network with no credential governing the traffic.
Input
Output fields
Sign up on Apify01
Create your Apify account to access the n8n Workflow Auditor - Linter & Security Review.
Start the run02
The Actor will start running based on the input automatically.
Receive the output03
Monitor the progress in real-time. You will be notified as soon as your dataset is complete and ready for review.
Integrate into your workflow04
The final output is delivered in JSON, CSV, or Excel format, ready to be plugged into your workflow.
