Updated 2026-09-09 54 views

Levlix Security Check Guide

The Security Audit module scans your server for risky settings and turns the result into a score, a grade and a list of concrete fixes.

/security-check finds mistakes such as an @everyone role with Manage Channels or an invite that skips verification in one run.

Setup

The module is on by default. If you turned it off, enable Security Audit again on the Module Management page of the dashboard.

The module overview in the dashboard, where each Levlix module is switched on or off per server
The module overview in the dashboard, where each Levlix module is switched on or off per server

For full coverage the bot's role needs View Audit Log, Manage Webhooks, Manage Server and Timeout Members. Checks without their permission are skipped and reported as low-severity findings.

Commands

Command Function Required Permissions
/security-check Runs the audit and shows the report privately Administrator

Results are cached for ten minutes per server; the Re-run audit button forces a fresh scan.

What it checks

Category Examples
Permissions @everyone with Administrator, management, moderation or mention-everyone rights; Manage Roles above an admin role; more than three admin roles; bots with Administrator
Channel Overrides @everyone overrides granting Manage Channel, Permissions, Webhooks, Messages, Threads or Mention @everyone; staff-named channels visible to @everyone
Server Settings Verification level None or Low; content filter off; 2FA requirement for moderation off; default notifications on All Messages; Community server without a rules channel
Bots, Roles, Webhooks More than 15 bots; bots with Kick, Ban, Manage Channels and Manage Roles; 240 or more roles; unused or duplicate roles; four or more roles with Manage Webhooks; orphaned or excessive webhooks
Voice @everyone overrides with Move, Mute or Deafen Members on voice channels, or Mute, Move, Manage Events or Manage Channel on stage channels
AutoMod, Invites, Apps No active AutoMod rule (one-click baseline available); invites that bypass verification; more than ten integrations; moderation-sounding commands usable by everyone
Community Welcome screen entries pointing at non-public channels; unclaimed vanity URL
Bot Self-Check Levlix's top role below a privileged role; missing bot permissions; Anti-Nuke switched off

How results are presented

The report is only visible to you. It shows the grade (A to F), the score (0 to 100) and the issue count, then one block per severity: Extreme, High, Medium, Low and Info. A finding costs 25, 12, 5, 2 or 0 points; the grade is A from 90 points, B from 75, C from 60, D from 40, E from 20 and F below.

Pick a finding from the select menu for details, remediation steps and the affected roles, channels or members. Only the person who ran the command can use the menu, and the report expires after ten minutes.

Dashboard

Dashboard administrators find the same report under Moderation, Security Report, where you can mark a finding as an accepted risk so it stops counting against the score, apply a one-click fix to selected findings (the AutoMod fix installs Levlix's baseline presets), export the report as Markdown, follow the score history, and enable daily notifications to a channel, administrators or the owner when the score drops.

What is stored

  • /security-check stores nothing; the report lives in memory for ten minutes.
  • Dashboard audits and the re-scan after a one-click fix are saved with score, grade and findings; Levlix keeps the last 30 runs per server.
  • Accepted risks are saved with the finding, the administrator, the reason and the time.
  • Notification preferences are saved per server.

FAQ

The report says "Failed to build the security report". Check the bot's permissions, especially View Audit Log and Manage Webhooks, then run the command again.

Does the check change anything on my server? No. /security-check is read-only. Changes only happen through the dashboard's fix buttons, and each Discord-side change lands in Discord's audit log with a reason starting with "Levlix Security Audit auto-fix".

Was this article helpful?

Thanks for your feedback! Your vote helps us improve the documentation.

Your vote could not be saved. Please reload the page and try again.

Share this guide

Your Privacy

We use essential cookies to operate this site and optionally Google Analytics to improve our services. You can accept all, reject all, or choose which categories you allow.

Privacy Policy

Cookie Preferences

Choose which categories of cookies you want to allow. You can change this at any time.

Essential Cookies

Required

Session, CSRF protection, login state.

Analytics Cookies

Optional

Google Analytics 4 with anonymized IP, used to understand aggregate usage.