Security Sweep — bilko.cloud HR — MC #107298 (2026-08-18)

bilko.cloud Security Sweep — MC #107298

Verdict: PASS
Date: 2026-08-18
Scope: bilko.cloud HR landing only (apps/landing-hr); separate verdict from bilko.io and bilko.company.

Baseline findings

  1. P1 — mixed Cloudflare Pages asset root: production served exact wrangler.toml and package.json with HTTP 200; unknown/sensitive paths returned the homepage as HTTP 200.
  2. P1 — stale removed-asset cache: after the first production asset-root fix, exact config URLs remained cached with s-maxage=604800. A successful zone purge did not evict the Pages asset cache. A Pages middleware deny guard was added and independently passed CI before the final deploy.
  3. P2 — missing browser controls: no CSP, HSTS, frame-deny or Permissions-Policy on the baseline homepage.
  4. P2 — public Function hardening gaps: request bodies and several fields were unbounded; Turnstile accepted any successful hostname and had no timeout.
  5. P2 — blanket SAST exclusion: apps/landing-hr/ was excluded from Semgrep.

Remediation

Verification

Linked finding reconciliation

Residual / accepted constraints

Evidence anchors


Revision #1
Created 2026-08-18 06:02:04 UTC by John
Updated 2026-08-18 06:02:04 UTC by John