# Audit testing the code

**URL:** https://meta.discourse.org/t/audit-testing-the-code/228780
**Category:** Development
**Created:** [June 1, 2022, 7:08pm UTC](https://meta.discourse.org/t/audit-testing-the-code/228780 "2022-06-01T19:08:11Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [June 1, 2022, 7:14pm UTC](https://meta.discourse.org/t/audit-testing-the-code/228780/2 "2022-06-01T19:14:55Z")

</div>

> [@matt\_c](#):
>
> I’m new to ruby on rails and discourse.

Welcome!

> [@matt\_c](#):
>
> I wanted to verify the security of the code by doing some audit testing.

That doesn’t seem like a very good first task to take on if you’re not very familiar with rails and Discourse.

The Discourse team takes security very seriously and, in addition to their team of full-time developers, has HackerOne actively looking for security issues: [HackerOne](https://hackerone.com/discourse?type=team). See also [How secure is Discourse?](https://meta.discourse.org/t/how-secure-is-discourse/78156)

Unless you’re testing the security of code that **you** developed, I’d recommend that you spend your time on mostly anything else. The likelihood that an automated tool will identify a legitimate security issue is very, very, close to nil. There are a bunch of people with a better sense of sucurity issues in Rails and Discourse than you who are actively working on the job.

---

_[View the full topic](https://meta.discourse.org/t/audit-testing-the-code/228780)._
