A condition report for the app you built.
You shipped something with Lovable, Bolt, v0, Cursor or Replit, and it works. Whether it is safe, and whether it will still be running next month, is a different question. Enter the address and we tell you what we find, in plain language.
Under a minute. The link works without an account, so you can forward it to whoever will do the work.
What we check
Five checks on every report, run against what your app serves to the public.
- AvailabilityWhether your app responds, and how quickly
- TransportYour security certificate and when it expires
- HeadersThe protections browsers apply to your pages
- Access controlWhether session cookies are kept out of reach of scripts
- ConfigurationScripts or images loaded over an insecure connection
- ConfigurationWhether search engines are told to list your app
- SecretsAPI keys and passwords visible in your app’s code
- ExposureConfiguration and source files reachable by anyone
- ExposureBackups, database exports and open folders
- ConfigurationWhich websites your API answers to
- Access controlWhether your database tables can be read without signing in
Permission first
We only check apps whose owner asked. Ownership is attested and recorded, never assumed.
Read-only, always
We look at what your app already serves to any visitor, the way a browser does. Nothing is signed into, changed or exfiltrated.
The gap, never the data
A finding records that a key was exposed and where — never the key itself. A report about your security must not become the leak.