SPECIFICATION // CLOUDFLARE SECURITY & INFRASTRUCTURE GUARDIAN

flareguard

The unified, high-performance Rust security auditor for Cloudflare. AST secret scanning, Worker binding verification, Zone posture auditing, and origin IP leak hunting in a single binary.

$ cargo install flareguard
01. The 4 Unified Pillars RUST HIGH-PERFORMANCE ENGINE
[ Pillar 01 // Secrets ]

flareguard secrets

Scans static bundles, dist folders, and git history for leaked Cloudflare API Tokens, Global Keys, and Turnstile secrets.

$ flareguard secrets dist/ --check
[ Pillar 02 // Bindings ]

flareguard bindings

OXC JavaScript/TypeScript AST scanner that validates wrangler.jsonc bindings against actual code usage (D1, KV, R2, Vectorize).

$ flareguard bindings src/ --strict
[ Pillar 03 // Zone Posture ]

flareguard zone

Live security posture audit for Cloudflare zones: SSL/TLS Strict, HSTS, WAF Managed Rules, Bot Fight Mode, and DNSSEC.

$ flareguard zone --zone example.com
[ Pillar 04 // Origin Hunter ]

flareguard origin

Discovers unmasked backend origin IPs behind Cloudflare proxies via DNS SPF/MX records, CRT.sh logs, and HTTP probes.

$ flareguard origin example.com --check