WHAT YOU RECEIVE
FOCUSED SECURITY REVIEW / N8N
Review the community nodes your n8n workflows actually use.
Community nodes run inside your automation environment. The exact package version, the workflow inputs mapped into it, and the permissions of the n8n process all affect the risk.
n8n's security audit lists community nodes, while its verification rules set standards for packages seeking verified status. A package name or failed verification alone does not establish an exploitable workflow. Our review connects installed code to the input paths your team actually runs.
We offer a paid, fixed-scope review for teams operating self-hosted n8n. We agree the package and workflow set, fee, access boundaries, and deliverables in writing before work begins.
No credentials or workflow exports in the first message. Contacting us does not authorize testing.HOW IT WORKS
From installed code to real exposure.
A package finding only matters in context. We separate code behavior from workflow reachability and document what the evidence supports.
Inventory
Identify installed community packages, exact versions, and the workflows that use them.
Trace
Review where webhook, message, or other lower-trust values enter node parameters and what those nodes can access or execute.
Resolve
Deliver a short evidence-backed report with affected paths, limits, priorities, and changes your team can verify.
START PRIVATELY
Tell us what you run.
Share your n8n hosting model, approximate number of community nodes, and the workflow or review deadline. We will suggest a bounded review and quote.