ERB Snippets + View Audit for Rails

Paste one .html.erb view and see the raw, html_safe, params and CSRF findings a Rails security review sends back. 26 rules. Runs in this page — the file is never uploaded, and there is no account.

Loaded with a sample view so you can see the output straight away. Paste your own over it — it stays in this browser tab.

Why not just ask an AI assistant?

An assistant reads what you paste it. These 26 rules read every line of every view, in the same order, every time — and they carry the Rails-specific reason, not a general "sanitise your input". A model that has never seen your app/views cannot tell you that line 214 of _row.html.erb is the one printing params[:q] into an attribute.

What it costs to find these by hand

A senior Rails contractor bills $80–$140 an hour in 2026, and a scoped web-application penetration test starts around $5,000. This page finds the same class of escaping and CSRF defect in one view for nothing.

Why now

Escaping defects are found by whoever looks first. If that is your security reviewer, it is a blocked release; if it is someone outside, it is a stored-XSS disclosure against a page your users are already loading.

Get one email when this rule changes
We watch the regulation and vendor sources behind ERB Snippets + View Audit for Rails every day. When a rule changes, you get a single email with what changed and the updated check. No newsletter.

Install free

Free for the file open in your editor - no key, no limit. The workspace sweep and the report ask for a key.

npmDocker Hub
npx @readystack/erb-rails-view-snippets-audit <file>
docker run --rm -v "$PWD:/w" getreadystack/erb-rails-view-snippets-audit /w

Team? One key for every ReadyStack linter, 5 seats, $149 once

Get the complete version $29

This page is the working piece. The full pack has everything below.

Paste or open one .html.erb view and see every raw, html_safe, params and CSRF finding a Rails security review sends back — 26 rules, 36 snippets, offline in the editor, no account.

A senior freelance Rails contractor bills $80-$140 an hour in 2026 (Arc.dev, adriano-junior.com, 2026 rate surveys) and a scoped web-application penetration test starts around $5,000 (Invicti, DeepStrike 2026 pricing guides). Neit

Buy the full version — $29
ENDEJAESPT

Find a tool