Free security scan · no card, no account

You built your app in a weekend.
How long to break in?

Apps built with Cursor, Lovable or Claude forget the same things: passwords left in the open, doors with no lock. Would you bet your users that yours got lucky? Paste it and know in minutes.

7apps scanned
4+3scan engines
<5 minto verdict
The first finding is free. If the scan finds nothing dangerous, you pay nothing, ever. The clean report is the product. Secrets stay hidden. Your app's name is never published.

What the scan looks for

What if the AI forgot to lock the door?

It happens on almost every app we scan. Not because the tool is bad. Because nobody taught it to think like a burglar. We do. Every scan asks what a hacker would ask:

In your code

paste a GitHub repo

asked is a password sitting in plain sight? it was.
asked does the admin page need a login? it didn't.
asked can strangers tamper with your database? they could.
each one: a fix you can paste in

On your live site

paste your URL

asked can anyone download your settings file? they can.
asked is your source code readable? it is.
asked are your admin docs open? wide open.
each one: a fix you can paste in

After the scan

You'll ship code tomorrow. Who's watching then?

Today's scan ends today. Next week's vibe-coding session can open a brand-new hole, and it won't email you about it. We will.

The scan
Free
one look, on the house
  • Full scan of repo or site
  • Your verdict + worst finding, free
  • Clean scan? The clean bill is yours free too
Start below
Full report
€13
once · yours forever
  • Every finding, exact file and line
  • A paste-ready fix for each one
  • Sleep tonight. Actually.
Scan first, then unlock
Daily watch
€49/mo
per app · cancel anytime
  • Full report included day one
  • Re-scanned every 24 hours
  • New hole? You know within a day, not when it's too late
Scan first, then decide

Fair questions

Asked by everyone. Answered straight.

Is scanning other people's repos even legal?

We only accept public repos and public URLs, and the form requires you to confirm you own the target. Scanning public code for defensive purposes is standard practice; exploiting anything would not be, and we never do.

Will you tell anyone what you found in my app?

No. Reports are unlisted pages only you and we can link to. We never publish client findings without written permission. Your repo name appears nowhere public.

What if it finds nothing?

Then you get a clean bill worth having: proof that today's version of your app passes every check. That's the free product working exactly as intended.

Why should I trust prompts written about my code?

Because every finding ships with redacted evidence from your actual files, and every prompt tells you how to verify the fix yourself. You are always the last gate.