Any public site or app. No account, no code access, no setup required.
API keys & secrets
Security headers
SSL / TLS
STEP 02
We scan, safely
Passive public checks only — no exploits, no fuzzing, no heavy crawling.
A
API KEYS & SECRETS
Key exposed in public bundle
STEP 03
Get a findings report
Prioritized findings, ranked by severity, with copy-paste fixes for your AI tools.
WHAT WE CHECK
01
Your private keys are exposed
API KEYS & SECRETS
Hiding in your app's public code, where anyone can find them.
02
Anyone can read or change your data
DATABASE PERMISSIONS
Your Supabase or Firebase database is set to let anyone in, not just you.
03
Your site is missing basic protections
SECURITY HEADERS
Simple safeguards that stop attackers from hijacking pages or stealing clicks.
04
Your connection security has gaps
SSL / TLS & CORS
Weak encryption settings, or rules that let other sites read your data.
05
Internal files are sitting out in the open
CONFIG & DEBUG FILES
Settings files, backups, or error pages that reveal more than they should.
06
Attackers can see exactly what you're running
TECH FINGERPRINT
The frameworks and tools behind your app, making it easier to target known weak spots.
SEE A REAL REPORT
Every finding shows its severity, redacted evidence, the business impact, and the exact fix. The free preview shows your critical issues — the full report unlocks the rest.
CRITICALFix immediately — likely exploitable now.
HIGHSerious exposure — fix before you scale.
MEDIUMWorth hardening soon.
report · shipfast.app6 findings
EVIDENCE
SUPABASE_KEY = "eyJhbGci••••••••••••redacted"
WHY IT MATTERS
Anyone can read this key from your public JavaScript and query your database directly.
Every scan earns a free embeddable badge. Drop it in your README, landing page, or launch post. It links back to a live, publicly verifiable report, so anyone can confirm it's real.
WHY IT MATTERS
AI builders move fast, and API keys or database credentials often end up sitting in the app's public code where anyone can find them. A visible badge shows users, investors, and collaborators that someone actually checked, instead of just taking your word for it.