AI wrote your app. Check if people can attack it.

Paste URL

630 sites scanned 3,949 issues found 1 in 3 leaked a key

What we check

60+ checks
  • Supabase & Firebase Can anyone read your tables straight from the browser?
  • Leaked API keys Did your build ship secrets into the JavaScript?
  • Unprotected endpoints Can strangers write, edit, or delete your data?
  • Login & sessions Does your sign-in actually stop anyone?
  • Admin & debug routes Is your admin panel or API docs wide open?
  • File storage Can people browse and download your users' uploads?
  • Script injection Can attackers run their own code on your site?
  • Certificates & transport Is traffic to your site actually encrypted?

Scan apps built with

Any web app with a public URL works. These are just the ones we see most.