{"product_id":"n8n-security-drift-scanner-smtp-email-new-findings","title":"n8n Security Drift Scanner: SMTP Email New Findings","description":"\u003ch3\u003en8n Security Drift Scanner: SMTP Email New Findings\u003c\/h3\u003e\n\u003cp\u003eCatch risky changes in your \u003cstrong\u003en8n\u003c\/strong\u003e automation before they become incidents. This workflow performs a \u003cstrong\u003eweekly, read-only security audit\u003c\/strong\u003e of every active workflow on your instance, detects new security issues and configuration drift, and \u003cstrong\u003eemails only the findings that are new since the last run\u003c\/strong\u003e via SMTP.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRuns every Monday at 07:30\u003c\/strong\u003e using a schedule trigger, then loads all workflows through the \u003cstrong\u003en8n API\u003c\/strong\u003e (archived workflows are skipped).\u003c\/li\u003e\n  \u003cli\u003eUses a \u003cstrong\u003eCode\u003c\/strong\u003e node to scan each workflow for \u003cstrong\u003ehardcoded secrets\u003c\/strong\u003e, including inactive ones (because templates can be cloned and exported).\u003c\/li\u003e\n  \u003cli\u003eFor \u003cstrong\u003eactive workflows\u003c\/strong\u003e, checks for:\n    \u003cul\u003e\n      \u003cli\u003e\u003cstrong\u003eUnauthenticated webhooks\u003c\/strong\u003e\u003c\/li\u003e\n      \u003cli\u003e\u003cstrong\u003eBroken or missing error handling workflows\u003c\/strong\u003e\u003c\/li\u003e\n      \u003cli\u003eWebhook authentication headers present in the \u003cstrong\u003eexecution log\u003c\/strong\u003e\n\u003c\/li\u003e\n      \u003cli\u003eActive \u003cstrong\u003etest\u003c\/strong\u003e or \u003cstrong\u003etemp\u003c\/strong\u003e workflows\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/li\u003e\n  \u003cli\u003eCompares \u003cstrong\u003eexecution-data protection\u003c\/strong\u003e and \u003cstrong\u003eMCP access\u003c\/strong\u003e against the strictest previously observed value, so a \u003cstrong\u003elowered setting is reported\u003c\/strong\u003e instead of becoming the new normal.\u003c\/li\u003e\n  \u003cli\u003eSends an email containing \u003cstrong\u003eonly new findings\u003c\/strong\u003e since the previous run. The baseline is saved \u003cem\u003eafter\u003c\/em\u003e the email is sent, preventing lost results if sending fails.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS operators who want automated, recurring \u003cstrong\u003en8n security hygiene\u003c\/strong\u003e across many teams and workflows.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers who need early warnings when secrets, webhook exposure, or error handling are accidentally changed.\u003c\/li\u003e\n  \u003cli\u003eTeams managing workflow templates who want protection against exported\/cloned workflows carrying hidden risks.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eIntegrations\/credentials: \u003cstrong\u003en8n API key\u003c\/strong\u003e (for “Fetch All Workflows”) and \u003cstrong\u003eSMTP\u003c\/strong\u003e credentials (for “Dispatch Alert Email”).\u003c\/li\u003e\n  \u003cli\u003eNodes used: \u003cstrong\u003eif\u003c\/strong\u003e, \u003cstrong\u003en8n\u003c\/strong\u003e (API fetch), \u003cstrong\u003eset\u003c\/strong\u003e, \u003cstrong\u003ecode\u003c\/strong\u003e, \u003cstrong\u003eemail send\u003c\/strong\u003e, and \u003cstrong\u003esticky note\u003c\/strong\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eSetup highlights\u003c\/h3\u003e\n\u003cp\u003eCreate an \u003cstrong\u003en8n API key\u003c\/strong\u003e in \u003cem\u003eSettings \u0026gt; n8n API\u003c\/em\u003e, add it as a credential for Fetch All Workflows, configure SMTP credentials for email delivery, set \u003cstrong\u003enotifyTo\u003c\/strong\u003e and \u003cstrong\u003enotifyFrom\u003c\/strong\u003e, and run once manually to build the initial baseline (the first scheduled run reports all findings once in production).\u003c\/p\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":46196314243251,"sku":"N8N-20703","price":10.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/mMkUpKPIEADvsKJf8AMsX_On6X8xOj.png?v=1791623628","url":"https:\/\/buyflowscripts.com\/products\/n8n-security-drift-scanner-smtp-email-new-findings","provider":"N8N Commerce","version":"1.0","type":"link"}