SPECIFICATION // CLOUDFLARE SECURITY & INFRASTRUCTURE GUARDIAN
flareguard
The unified, high-performance Rust security auditor for Cloudflare. AST secret scanning, Worker binding verification, Zone posture auditing, and origin IP leak hunting in a single binary.
$ cargo install flareguard
01. The 4 Unified Pillars
RUST HIGH-PERFORMANCE ENGINE
[ Pillar 01 // Secrets ]
flareguard secrets
Scans static bundles, dist folders, and git history for leaked Cloudflare API Tokens, Global Keys, and Turnstile secrets.
$ flareguard secrets dist/ --check
[ Pillar 02 // Bindings ]
flareguard bindings
OXC JavaScript/TypeScript AST scanner that validates wrangler.jsonc bindings against actual code usage (D1, KV, R2, Vectorize).
$ flareguard bindings src/ --strict
[ Pillar 03 // Zone Posture ]
flareguard zone
Live security posture audit for Cloudflare zones: SSL/TLS Strict, HSTS, WAF Managed Rules, Bot Fight Mode, and DNSSEC.
$ flareguard zone --zone example.com
[ Pillar 04 // Origin Hunter ]
flareguard origin
Discovers unmasked backend origin IPs behind Cloudflare proxies via DNS SPF/MX records, CRT.sh logs, and HTTP probes.
$ flareguard origin example.com --check