Scan before you ship.
Find exposed API keys before attackers do
Built with Bolt, Lovable, or Cursor? Get a security report on your app in seconds — with fix prompts you paste straight back into your AI coding tool.
No signup required for a quick check. Or view a demo report.
The full scan (including exposed API keys) only runs on sites you've verified you own.
How it works
Sign Up
Create your free account in seconds.
Verify Ownership
Prove you own the site via DNS, meta tag, or file upload.
Scan
Get a full security report with AI-powered fix suggestions.
Every finding comes with a fix prompt
You don't need to know what a CSP is. Copy the prompt, paste it into your AI tool, re-scan to green.
Stripe secret key found in client-side JavaScript
A live secret key (sk_live_…) is readable by anyone who opens your site's JS bundle. With it, an attacker can charge cards and issue refunds as you.
My app has a Stripe secret key (sk_live_...) exposed in the client bundle at /static/js/main.js. Move all Stripe secret key usage to server-side code (an API route or server function), replace any client-side usage with the publishable key, move the secret into an environment variable, and remind me to rotate the compromised key in the Stripe dashboard.
What we scan for
Comprehensive security checks designed for AI-built apps.
Security Headers
CSP, HSTS, X-Frame-Options, and more — we check them all.
Exposed API Keys
Scans JS bundles for leaked Stripe, OpenAI, AWS, and Firebase keys.
SSL/TLS Analysis
Certificate validity, expiry warnings, and protocol checks.
Misconfigurations
Exposed .env files, .git directories, source maps, and debug endpoints.
API & Attack Surface
Finds exposed API docs, GraphQL tooling, directory listings, and verbose errors.
Frontend Security
Checks mixed content, browser storage risks, postMessage, SRI, and WebSocket issues.
AI Fix Prompts
Get copy-paste prompts for your preferred AI coding tool.
Across 15 categories, with a fix prompt for every finding.
Simple pricing
Start free. Upgrade when you need more.
Free Beta
- 3 scans per day
- Basic security score
- Top 3 findings with fixes
- AI fix prompts
- Shareable report link
Pro
- Everything in Free, plus:
- All findings unlocked
- AI fix prompts for every issue
- Scheduled re-scans (daily or weekly)
- Re-scan on deploy via webhook
- Full scan history
- Shareable reports
- Priority beta support
Team
- Everything in Pro, plus:
- Multiple seats
- Hourly scheduled re-scans
- CI/CD workflow support
- Founder-led onboarding
Frequently asked questions
Scan before you ship.
Run a free scan on your app right now — no signup required.