Skip to content

17 public modules + 6 heavy scanners (3 external)

Built with AI?
Check if it's safe.

Scan your deployed app for exposed secrets, database vulnerabilities, and auth bypass, then get the exact prompt to fix them.

Paste a website URL or GitHub repo link, and we auto-detect which scan to run.

Works with
L
Lovable
B
Bolt.new
C
Cursor
V
v0.dev
R
Replit
W
Windsurf
CC
Claude Code
L
Lovable
B
Bolt.new
C
Cursor
V
v0.dev
R
Replit
W
Windsurf
CC
Claude Code
17
pre-verification URL modules
6
verified-owner heavy scanners
100%
verified scanner coverage required for a public score card

Within 60 seconds

Three steps. Zero stress.

1

Paste your URL

No signup. No install. No access needed.

2

We scan everything

17 public modules report before verification. 6 heavy scanners, including 3 external engines, require a verified owner.

3

Get fix prompts

Copy-paste into your AI tool. Fixed in minutes.

Real issues
we find.

Representative examples from the sample report. They are not live findings or weekly telemetry.

sample
criticalSupabase service_role key exposed in frontend

Bypasses all Row Level Security. Full database access.

criticalOpenAI API key in JavaScript bundle

Anyone can use your key. Average cost of leaked key: $2,400.

highFirebase RTDB open to public

All data readable and writable without authentication.

fixedFix prompt ready → "Enable RLS on all tables..."

Copy to Cursor or Lovable. Fix in under 5 minutes.

Comprehensive Analysis

360° security analysis.

15+

Exposed API Keys

Supabase, Firebase, Stripe, OpenAI, AWS credentials leaked in JS bundles.

patterns detected
RLS

Database Security

Tests Row Level Security and Firebase rules. Finds databases anyone can read.

policy testing
Evidence

Auth & Headers

Authentication and session signals, CSP, HSTS, and the applicable security-header set.

checks total
10+

Platform Detection

Identifies which AI tool built the app. Platform-specific recommendations.

platforms
42

Fix Prompts

Copy-paste prompts for Cursor, Lovable, Bolt. Fix issues in minutes, not days.

ready prompts
0-100

Boring Score

13 versioned categories. The bundle-secrets coefficient is 0.25, and the result is normalized by assessed coverage.

weighted score