> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replit.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Project Security Center

> Choose a security scan, review findings, and fix vulnerabilities before you publish your Replit App.

export const chatIcon = (name, size = 19) => {
  const paths = {
    MessageCircle: <path d="M7.9 20A9 9 0 1 0 4 16.1L2 22Z" />,
    ChartNoAxesCombined: <>
        <path d="M12 16v5" />
        <path d="M16 14v7" />
        <path d="M20 10v11" />
        <path d="m22 3-8.646 8.646a.5.5 0 0 1-.708 0L9.354 8.354a.5.5 0 0 0-.708 0L2 15" />
        <path d="M4 18v3" />
        <path d="M8 14v7" />
      </>,
    Workflow: <>
        <rect width="8" height="8" x="3" y="3" rx="2" />
        <path d="M7 11v4a2 2 0 0 0 2 2h4" />
        <rect width="8" height="8" x="13" y="13" rx="2" />
      </>,
    Lightbulb: <>
        <path d="M15 14c.2-1 .7-1.7 1.5-2.5 1-.9 1.5-2.2 1.5-3.5A6 6 0 0 0 6 8c0 1 .2 2.2 1.5 3.5.7.7 1.3 1.5 1.5 2.5" />
        <path d="M9 18h6" />
        <path d="M10 22h4" />
      </>,
    Code2: <>
        <path d="m18 16 4-4-4-4" />
        <path d="m6 8-4 4 4 4" />
        <path d="m14.5 4-5 16" />
      </>,
    Presentation: <>
        <path d="M2 3h20" />
        <path d="M21 3v11a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V3" />
        <path d="m7 21 5-5 5 5" />
      </>,
    PanelsTopLeft: <>
        <rect width="18" height="18" x="3" y="3" rx="2" />
        <path d="M3 9h18" />
        <path d="M9 21V9" />
      </>,
    Keyboard: <>
        <rect width="20" height="14" x="2" y="5" rx="2" />
        <path d="M6 9h.01M10 9h.01M14 9h.01M18 9h.01M6 13h.01M10 13h.01M14 13h.01M18 13h.01M8 17h8" />
      </>,
    Layers3: <>
        <path d="m12 2 9 5-9 5-9-5 9-5Z" />
        <path d="m3 12 9 5 9-5M3 17l9 5 9-5" />
      </>,
    CalendarClock: <>
        <path d="M16 2v4M8 2v4M3 10h18" />
        <rect width="18" height="19" x="3" y="4" rx="2" />
        <path d="M12 14v3l2 1" />
      </>,
    ConversationProject: <>
        <path d="M3 4h8v6H6l-3 2V4Z" />
        <rect width="9" height="9" x="12" y="11" rx="1.5" />
        <path d="M12 14h9M15 11v9" />
      </>,
    CursorDesign: <>
        <path d="m5 3 13 7-6 2-2 6L5 3Z" />
        <path d="M15 16h6M18 13v6" />
      </>,
    AppWindow: <>
        <rect width="20" height="18" x="2" y="3" rx="2" />
        <path d="M2 8h20M6 5.5h.01M9 5.5h.01" />
      </>,
    CloudUpload: <>
        <path d="M12 13v8M8 17l4-4 4 4" />
        <path d="M20 16.5A5 5 0 0 0 18 7h-1.3A7 7 0 0 0 3.3 9.4 4.5 4.5 0 0 0 5 18h2" />
      </>,
    Image: <>
        <rect width="18" height="18" x="3" y="3" rx="2" ry="2" />
        <circle cx="9" cy="9" r="2" />
        <path d="m21 15-3.086-3.086a2 2 0 0 0-2.828 0L6 21" />
      </>,
    FileUp: <>
        <path d="M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z" />
        <path d="M14 2v4a2 2 0 0 0 2 2h4" />
        <path d="M12 12v6" />
        <path d="m15 15-3-3-3 3" />
      </>,
    Search: <>
        <circle cx="11" cy="11" r="8" />
        <path d="m21 21-4.3-4.3" />
      </>,
    Sparkles: <path d="M9.937 15.5A2 2 0 0 0 8.5 14.063l-6.135-1.582a.5.5 0 0 1 0-.962L8.5 9.936A2 2 0 0 0 9.937 8.5l1.582-6.135a.5.5 0 0 1 .963 0L14.063 8.5A2 2 0 0 0 15.5 9.937l6.135 1.581a.5.5 0 0 1 0 .964L15.5 14.063a2 2 0 0 0-1.437 1.437l-1.582 6.135a.5.5 0 0 1-.963 0z" />,
    Briefcase: <>
        <path d="M16 20V4a2 2 0 0 0-2-2h-4a2 2 0 0 0-2 2v16" />
        <rect width="20" height="14" x="2" y="6" rx="2" />
      </>,
    WandSparkles: <>
        <path d="m21.64 3.64-1.28-1.28a1.21 1.21 0 0 0-1.72 0L2.36 18.64a1.21 1.21 0 0 0 0 1.72l1.28 1.28a1.2 1.2 0 0 0 1.72 0L21.64 5.36a1.2 1.2 0 0 0 0-1.72" />
        <path d="m14 7 3 3" />
        <path d="M5 6v4" />
        <path d="M19 14v4" />
        <path d="M10 2v2" />
        <path d="M7 8H3" />
        <path d="M21 16h-4" />
        <path d="M11 3H9" />
      </>
  };
  return <svg width={size} height={size} viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="1.8" strokeLinecap="round" strokeLinejoin="round" aria-hidden="true">
      {paths[name] ?? paths.Sparkles}
    </svg>;
};

export const ChatExample = ({icon, iconSrc, tag, title, href, palette, children}) => {
  const body = <>
      {palette && <div className={`chat-use-case-visual palette-${palette}`}>
          <div className="chat-use-case-window">
            <i />
            <i />
            <i />
            <b />
            <b />
            <b />
          </div>
          <em>
            {iconSrc ? <img src={iconSrc} alt="" width="26" height="26" /> : chatIcon(icon, 24)}
          </em>
        </div>}
      <span>
        {iconSrc ? <img src={iconSrc} alt="" width="19" height="19" /> : chatIcon(icon, 19)}
      </span>
      {tag && <div className="chat-example-tag">{tag}</div>}
      <strong>{title}</strong>
      <p>{children}</p>
      <small>{href ? "Explore →" : ""}</small>
    </>;
  const className = `chat-example${palette ? " has-visual" : ""}`;
  return href ? <a className={className} href={href}>
      {body}
    </a> : <div className={className}>{body}</div>;
};

export const ChatExampleGrid = ({hasVisuals, children}) => {
  return <section className={`chat-mkt chat-workflow-grid${hasVisuals ? " has-visuals" : ""}`}>
      {children}
    </section>;
};

<Frame>
  <img src="https://mintcdn.com/replit/m66KQX7992wJ3rkk/images/security-scanner/security-scanner-hero.png?fit=max&auto=format&n=m66KQX7992wJ3rkk&q=85&s=fe56b3d0d0735cc2a6dbdba2b252badc" alt="Project Security Center showing security scan findings grouped by severity" style={{ display: "block", margin: "0 auto" }} width="3402" height="2058" data-path="images/security-scanner/security-scanner-hero.png" />
</Frame>

The Project Security Center is the central place to find and fix security and privacy vulnerabilities in a Replit App. In your project's **Tools** pane, select **Security Center** to run scans, review findings, and send accepted issues to Agent for remediation.

<Note>
  New to dependency security? See [Security
  concepts](/features/security/concepts) for definitions of CVE, SBOM, exposure,
  Fix with Agent, Republish, and Auto-Protect.
</Note>

## Choose a security scan

Compare [security scan levels](/features/security/security-scan-levels) to see what Levels 1, 2, and 3 check.

Choose the scan that matches the type of review you need:

<div id="agent-security-scans" />

<div id="level-3-scans" />

<ChatExampleGrid>
  <ChatExample title="Review your source code" icon="Code2" href="/features/security/agent-security-scans">
    Use an Agent security scan for the normal code-review workflow. Security
    Agent audits your codebase, reports findings, and helps you fix them.
  </ChatExample>

  <ChatExample title="Test the running app" icon="Search" href="/features/security/black-box-pen-tests">
    Use a Level 3 scan when you also need a black-box pen test of the running
    app. Level 3 runs that test alongside a source-code review.
  </ChatExample>
</ChatExampleGrid>

Both paths report findings in **Security Center**. Agent security scans are available to paid Replit builders.

## Automatic dependency scans

Automatic dependency scans check project packages against public vulnerability records. These scans are free and run automatically. When a new Common Vulnerabilities and Exposures (CVE) entry is disclosed, Replit checks it against your project's dependencies and surfaces matches in the **Security** pane without requiring a manual rescan.

Dependency scanning supports Node.js/npm, Python, Go, Rust, PHP, and Ruby.

Automatic dependency fixing is currently focused on Node.js/npm.

<Frame>
  <img src="https://mintcdn.com/replit/MuLW6SmzOLVKbNrI/images/project-security-center/fix-all-with-agent.png?fit=max&auto=format&n=MuLW6SmzOLVKbNrI&q=85&s=8d6a692c34d6d106462fa714bdc703aa" alt="Automatic dependency scans card with the Fix all with Agent action" width="1440" height="900" data-path="images/project-security-center/fix-all-with-agent.png" />
</Frame>

### Auto-Protect

Auto-Protect extends automatic dependency scanning. When Replit detects a matching vulnerability, Agent prepares and tests a patch and emails you a direct link. The patch remains pending in the **Security** pane for your review. After you apply it, republish the app so the production version includes the fix.

Auto-Protect covers dependency CVEs only. Use an [Agent security scan](/features/security/agent-security-scans) to review application code.

Both Auto-Protect settings are off by default:

<Steps>
  <Step title="Enable patch preparation">
    A Workspace admin goes to **Settings** > **Account** > **Advanced**, then
    selects the minimum severity (low, medium, high, or critical) at which
    Replit should prepare remediations.
  </Step>

  <Step title="Enable security emails">
    Go to **Settings** > **Personalization** > **Email Notifications**, then
    select the minimum severity at which you want to receive notifications.
  </Step>
</Steps>

For each new vulnerability, Replit sends at most one email per Workspace that summarizes all affected projects. Select **Go to Task** to inspect an Agent-prepared patch before applying it. After you apply the patch, the vulnerability appears as **pending republish** until you publish a new version.

<Note>
  Agent-prepared remediations are billed like other Agent work, including when
  Auto-Protect prepares them proactively.
</Note>

## Review findings

Security results appear in the **Security** pane and are grouped by severity:

| Severity | Guidance |
| - | - |
| Critical | Immediate risks that you should address before publishing |
| High | Serious issues that could be exploited under certain conditions |
| Medium | Potential risks that are less likely to be exploitable |
| Low / Informational | Minor issues and best-practice recommendations |

Review each finding before accepting, revising, or dismissing it. Send accepted issues to Agent for remediation, then rerun the relevant scan after applying fixes.

## Security checks during development and publishing

### Security scan while you build

As you build with Agent, Replit automatically reviews the files Agent changes for common insecure patterns and hardcoded secrets. This is an early, lightweight check in the Agent workflow rather than a full codebase review. Its results do not appear as a separate report in the **Security** pane.

### Publish checks

Replit also runs a security scan before publishing. The **Block publishing of critical vulnerabilities** setting determines what happens when the scan finds a critical issue:

* **On**: Publishing is blocked until the issue is resolved or dismissed.
* **Off**: Publishing proceeds, and the finding remains available for review.

Enterprise organizations can require this setting for every app.

These checks complement, rather than replace, a full [Agent security scan](/features/security/agent-security-scans) or [Level 3 scan](/features/security/black-box-pen-tests).

## Next steps

* Follow the [Agent security scan workflow](/features/security/agent-security-scans).
* Learn how to run [black-box pen tests with Level 3](/features/security/black-box-pen-tests).
* Learn more about [Publishing](/learn/projects-and-artifacts/replit-deployments).
* Read [How Replit secures AI-generated code](https://blog.replit.com/securing-ai-generated-code).
