# Payload CMS Security Scanner — Find public collection leaks (`renzomacar/payload-security-scanner`) Actor

Probes a public Payload CMS instance for collections readable without auth. Default templates leave read access wide open during development.

- **URL**: https://apify.com/renzomacar/payload-security-scanner.md
- **Developed by:** [Renzo Madueno](https://apify.com/renzomacar) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, NaN bookmarks
- **User rating**: No ratings yet

## Pricing

Pay per usage

This Actor is paid per platform usage. The Actor is free to use, and you only pay for the Apify platform usage, which gets cheaper the higher subscription plan you have.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-usage

## What's an Apify Actor?

Actors are a software tools running on the Apify platform, for all kinds of web data extraction and automation use cases.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

In JavaScript/TypeScript projects, use official [JavaScript/TypeScript client](https://docs.apify.com/api/client/js.md):

```bash
npm install apify-client
```

In Python projects, use official [Python client library](https://docs.apify.com/api/client/python.md):

```bash
pip install apify-client
```

In shell scripts, use [Apify CLI](https://docs.apify.com/cli/docs.md):

````bash
# MacOS / Linux
curl -fsSL https://apify.com/install-cli.sh | bash
# Windows
irm https://apify.com/install-cli.ps1 | iex
```bash

In AI frameworks, you might use the [Apify MCP server](https://docs.apify.com/platform/integrations/mcp.md).

If your project is in a different language, use the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).


# README

## Payload CMS Security Scanner — Find public collection leaks

> **Every Payload CMS template I've checked (template-blog, template-website, template-ecommerce) ships with `access: { read: () => true }` on most collections so you can browse the API in development.** That setting often makes it to production unchanged — and the moment it does, anyone with your CMS URL can list every record in `users`, `orders`, `media`, custom collections, you name it. **This actor finds those leaks in 30 seconds.**

Probes a public Payload CMS instance for **collections readable without authentication**. Sends `/api/{collection}?limit=1` per collection. Returns counts + a verbatim `curl` reproducer per finding. Counts only — never row data.

> 💸 **Found a leak?** I do turnkey Payload audits + access-function rewrites for **$99** ([Stripe](https://buy.stripe.com/00w9AT9TWdaW7yx9KkcAo01) — 48h, money-back). Or **$29/mo** weekly auto-scans at [rls-monitor.vercel.app](https://rls-monitor.vercel.app/).

> ⭐️ **Solo dev competing with bigger Apify publishers.** A [30-second review](https://apify.com/renzomacar/payload-security-scanner#reviews) is the single thing that lifts ranking. Thank you.

### Why this exists

Payload CMS uses per-collection `access` functions for authorization. The framework is excellent — but the **defaults in every official template are permissive**:

```ts
// from payloadcms/template-blog (default):
export const Posts: CollectionConfig = {
  slug: 'posts',
  access: {
    read: () => true,  // ← anyone can read all posts
  },
  // ...
};
````

That's fine for `posts` (you probably want them public). But the same `() => true` pattern is copy-pasted onto:

1. **`users`** — anyone gets to enumerate emails, hashed passwords (yes, the hash + salt are returned), roles, login attempt counts
2. **`orders`/`transactions`** — full purchase history, Stripe IDs, shipping addresses
3. **`media`** — file metadata + the signed URLs to download them

This scanner probes ~30 common collection slugs plus any you pass as hints.

### How to run

Either:

1. **Leave inputs empty** + click **Run** for a DEMO sample report
2. **Provide your `payloadUrl`** to scan your actual instance

```json
{
  "payloadUrl": "https://cms.your-domain.com",
  "collectionHints": ["my-custom-collection"],
  "outputFormat": "both"
}
```

### What you get

- **HTML report** (`report.html` in run's KV store): severity-coded findings, copy-pasteable curl reproducers, exact code change to fix each leaky collection
- **Dataset rows**: one structured row per finding

### Sample finding

```
[CRITICAL] users — readable anonymously
Total records: 2,891
Sample columns: id, email, name, role, createdAt, updatedAt, loginAttempts, lockUntil, hash, salt
Sensitive columns detected: email, hash, salt

Reproducer:
curl 'https://cms.your-domain.com/api/users?limit=1' -I
```

### How to fix (code change, ~5 min per collection)

In your Payload config, for each leaky collection, set `access.read`:

```ts
// collections/Users.ts
import { CollectionConfig } from 'payload/types';

export const Users: CollectionConfig = {
  slug: 'users',
  access: {
    read: ({ req: { user } }) => Boolean(user),     // ← require auth
    // or strict per-record:
    // read: ({ req: { user } }) => ({ id: { equals: user?.id } }),
  },
  // ...
};
```

If the collection **should** be public (blog posts, product catalog), use Payload's **field-level** access control:

```ts
fields: [
  { name: 'title', type: 'text' },                              // public
  { name: 'authorEmail', type: 'email',
    access: { read: ({ req: { user } }) => Boolean(user) } },   // auth-only
],
```

### Ethical use

- Only scan instances you own or have explicit permission to scan
- Probe queries use `?limit=1` to confirm exposure without exfiltrating contents

### Related

- **Stripe audit ($99 one-time)**: [buy.stripe.com/00w9AT9TWdaW7yx9KkcAo01](https://buy.stripe.com/00w9AT9TWdaW7yx9KkcAo01)
- **Weekly auto-scans ($29/mo)**: [rls-monitor.vercel.app](https://rls-monitor.vercel.app/)
- **Sister scanners**: [Supabase](https://apify.com/renzomacar/supabase-rls-scanner), [Firebase](https://apify.com/renzomacar/firebase-security-auditor), [Strapi](https://apify.com/renzomacar/strapi-security-scanner), [Directus](https://apify.com/renzomacar/directus-security-scanner), [Payload CMS](https://apify.com/renzomacar/payload-security-scanner), [Convex](https://apify.com/renzomacar/convex-security-scanner), [Hasura](https://apify.com/renzomacar/hasura-security-scanner), [PocketBase](https://apify.com/renzomacar/pocketbase-security-scanner), [Appwrite](https://apify.com/renzomacar/appwrite-security-auditor), [Nhost](https://apify.com/renzomacar/nhost-security-scanner).

Built by [Renzo](https://github.com/Perufitlife).

# Actor input Schema

## `payloadUrl` (type: `string`):

Your Payload CMS base URL, e.g. https://cms.your-domain.com. Must be publicly reachable. Leave empty + click Run for a sample report.

## `collectionHints` (type: `array`):

Beyond ~30 common collection slugs, list any custom slugs from your config.

## `outputFormat` (type: `string`):

JSON for programmatic use; HTML report saved to KV store under report.html.

## Actor input object example

```json
{
  "collectionHints": [],
  "outputFormat": "both"
}
```

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {};

// Run the Actor and wait for it to finish
const run = await client.actor("renzomacar/payload-security-scanner").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {}

# Run the Actor and wait for it to finish
run = client.actor("renzomacar/payload-security-scanner").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{}' |
apify call renzomacar/payload-security-scanner --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=renzomacar/payload-security-scanner",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

```json
{
    "openapi": "3.0.1",
    "info": {
        "title": "Payload CMS Security Scanner — Find public collection leaks",
        "description": "Probes a public Payload CMS instance for collections readable without auth. Default templates leave read access wide open during development.",
        "version": "0.1",
        "x-build-id": "CQdbesZhkwjQ4PUbY"
    },
    "servers": [
        {
            "url": "https://api.apify.com/v2"
        }
    ],
    "paths": {
        "/acts/renzomacar~payload-security-scanner/run-sync-get-dataset-items": {
            "post": {
                "operationId": "run-sync-get-dataset-items-renzomacar-payload-security-scanner",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for its completion, and returns Actor's dataset items in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        },
        "/acts/renzomacar~payload-security-scanner/runs": {
            "post": {
                "operationId": "runs-sync-renzomacar-payload-security-scanner",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor and returns information about the initiated run in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK",
                        "content": {
                            "application/json": {
                                "schema": {
                                    "$ref": "#/components/schemas/runsResponseSchema"
                                }
                            }
                        }
                    }
                }
            }
        },
        "/acts/renzomacar~payload-security-scanner/run-sync": {
            "post": {
                "operationId": "run-sync-renzomacar-payload-security-scanner",
                "x-openai-isConsequential": false,
                "summary": "Executes an Actor, waits for completion, and returns the OUTPUT from Key-value store in response.",
                "tags": [
                    "Run Actor"
                ],
                "requestBody": {
                    "required": true,
                    "content": {
                        "application/json": {
                            "schema": {
                                "$ref": "#/components/schemas/inputSchema"
                            }
                        }
                    }
                },
                "parameters": [
                    {
                        "name": "token",
                        "in": "query",
                        "required": true,
                        "schema": {
                            "type": "string"
                        },
                        "description": "Enter your Apify token here"
                    }
                ],
                "responses": {
                    "200": {
                        "description": "OK"
                    }
                }
            }
        }
    },
    "components": {
        "schemas": {
            "inputSchema": {
                "type": "object",
                "properties": {
                    "payloadUrl": {
                        "title": "Payload CMS Instance URL (leave empty for DEMO)",
                        "type": "string",
                        "description": "Your Payload CMS base URL, e.g. https://cms.your-domain.com. Must be publicly reachable. Leave empty + click Run for a sample report."
                    },
                    "collectionHints": {
                        "title": "Extra collection slugs to probe (optional)",
                        "type": "array",
                        "description": "Beyond ~30 common collection slugs, list any custom slugs from your config.",
                        "default": [],
                        "items": {
                            "type": "string"
                        }
                    },
                    "outputFormat": {
                        "title": "Output format",
                        "enum": [
                            "json",
                            "html-report",
                            "both"
                        ],
                        "type": "string",
                        "description": "JSON for programmatic use; HTML report saved to KV store under report.html.",
                        "default": "both"
                    }
                }
            },
            "runsResponseSchema": {
                "type": "object",
                "properties": {
                    "data": {
                        "type": "object",
                        "properties": {
                            "id": {
                                "type": "string"
                            },
                            "actId": {
                                "type": "string"
                            },
                            "userId": {
                                "type": "string"
                            },
                            "startedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "finishedAt": {
                                "type": "string",
                                "format": "date-time",
                                "example": "2025-01-08T00:00:00.000Z"
                            },
                            "status": {
                                "type": "string",
                                "example": "READY"
                            },
                            "meta": {
                                "type": "object",
                                "properties": {
                                    "origin": {
                                        "type": "string",
                                        "example": "API"
                                    },
                                    "userAgent": {
                                        "type": "string"
                                    }
                                }
                            },
                            "stats": {
                                "type": "object",
                                "properties": {
                                    "inputBodyLen": {
                                        "type": "integer",
                                        "example": 2000
                                    },
                                    "rebootCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "restartCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "resurrectCount": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "computeUnits": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "options": {
                                "type": "object",
                                "properties": {
                                    "build": {
                                        "type": "string",
                                        "example": "latest"
                                    },
                                    "timeoutSecs": {
                                        "type": "integer",
                                        "example": 300
                                    },
                                    "memoryMbytes": {
                                        "type": "integer",
                                        "example": 1024
                                    },
                                    "diskMbytes": {
                                        "type": "integer",
                                        "example": 2048
                                    }
                                }
                            },
                            "buildId": {
                                "type": "string"
                            },
                            "defaultKeyValueStoreId": {
                                "type": "string"
                            },
                            "defaultDatasetId": {
                                "type": "string"
                            },
                            "defaultRequestQueueId": {
                                "type": "string"
                            },
                            "buildNumber": {
                                "type": "string",
                                "example": "1.0.0"
                            },
                            "containerUrl": {
                                "type": "string"
                            },
                            "usage": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "integer",
                                        "example": 1
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            },
                            "usageTotalUsd": {
                                "type": "number",
                                "example": 0.00005
                            },
                            "usageUsd": {
                                "type": "object",
                                "properties": {
                                    "ACTOR_COMPUTE_UNITS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATASET_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "KEY_VALUE_STORE_WRITES": {
                                        "type": "number",
                                        "example": 0.00005
                                    },
                                    "KEY_VALUE_STORE_LISTS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_READS": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "REQUEST_QUEUE_WRITES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_INTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "DATA_TRANSFER_EXTERNAL_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_RESIDENTIAL_TRANSFER_GBYTES": {
                                        "type": "integer",
                                        "example": 0
                                    },
                                    "PROXY_SERPS": {
                                        "type": "integer",
                                        "example": 0
                                    }
                                }
                            }
                        }
                    }
                }
            }
        }
    }
}
```
