FREE · SAFE PUBLIC SCAN · NO LOGIN


We protect your app.

You shipped fast with AI. Dr. Security runs a safe public scan and tells you what's exposed and exactly how to fix it.

+0
SECURITY CHECKS
Headers, secrets, TLS, DNS, config, and more.
~0s
TIME TO RESULT
Findings and severity, fast.
$0
FREE PREVIEW
See your risk before you pay.
BUILT FOR APPS SHIPPED ONLovable, Bolt, Cursor, v0, Replit, Base44, GitHub, Supabase, Firebase, Framer, Webflow, Figma, Anthropic, Windsurf

HOW IT WORKS

https://your-app.com
STEP 01

Paste your URL

Any public site or app. No account, no code access, no setup required.

API keys & secrets
Security headers
SSL / TLS
STEP 02

We scan, safely

Passive public checks only — no exploits, no fuzzing, no heavy crawling.

A
API KEYS & SECRETS
Key exposed in public bundle
STEP 03

Get a findings report

Prioritized findings, ranked by severity, with copy-paste fixes for your AI tools.

WHAT WE CHECK

01
Your private keys are exposed
API KEYS & SECRETS
Hiding in your app's public code, where anyone can find them.
02
Anyone can read or change your data
DATABASE PERMISSIONS
Your Supabase or Firebase database is set to let anyone in, not just you.
03
Your site is missing basic protections
SECURITY HEADERS
Simple safeguards that stop attackers from hijacking pages or stealing clicks.
04
Your connection security has gaps
SSL / TLS & CORS
Weak encryption settings, or rules that let other sites read your data.
05
Internal files are sitting out in the open
CONFIG & DEBUG FILES
Settings files, backups, or error pages that reveal more than they should.
06
Attackers can see exactly what you're running
TECH FINGERPRINT
The frameworks and tools behind your app, making it easier to target known weak spots.

SEE A REAL REPORT

Every finding shows its severity, redacted evidence, the business impact, and the exact fix. The free preview shows your critical issues — the full report unlocks the rest.

CRITICALFix immediately — likely exploitable now.
HIGHSerious exposure — fix before you scale.
MEDIUMWorth hardening soon.
report · shipfast.app6 findings
EVIDENCE
SUPABASE_KEY = "eyJhbGci••••••••••••redacted"
WHY IT MATTERS
Anyone can read this key from your public JavaScript and query your database directly.
Rotate the exposed Supabase key, move it server-side, and enable row-level security so the anon key can't read protected tables.
+ 3 more findings with fixesUNLOCK FULL REPORT

GET YOUR BADGE.

Every scan earns a free embeddable badge. Drop it in your README, landing page, or launch post. It links back to a live, publicly verifiable report, so anyone can confirm it's real.

WHY IT MATTERS

AI builders move fast, and API keys or database credentials often end up sitting in the app's public code where anyone can find them. A visible badge shows users, investors, and collaborators that someone actually checked, instead of just taking your word for it.

A
Scanned by
DR. SECURITY
Click the badge to see a sample report

WHO IT'S FOR

AI Builders

Shipped with AI, unsure what leaked

Lovable, Bolt, Cursor, v0. Fast to launch — but easy to leave keys, database rules, and config exposed. Get confidence before you share it.

Technical Founders

Need evidence, not guesswork

A credible external report to share with teammates, customers, and investors — with prioritized findings and remediation you can track.

Teams

Continuous public exposure watch

Scheduled scans, alerts, and history across multiple assets, so a risky change never ships unnoticed.

WHY US, NOT A TRADITIONAL SCANNER

Dr. Security
Traditional scanners
Built for AI-built & vibe-coded apps
Yes
Plain-language findings, no jargon
Yes
Often not
Copy-paste AI fix prompts
Yes
One-time report, no subscription
$99
Usually not
Free public preview in ~60s
Yes
Limited
Safe, passive-by-default scanning
Yes
Varies
FREE PREVIEW
$0
See if you're exposed right now — no strings attached.
LAUNCH REPORT
$0
Every issue found, explained plainly, with exact fixes to hand your AI tool.
FOUNDER MONITOR
$149$0/mo
Save $298/year · $1490 billed annually
Same continuous coverage, billed annually.

COMPARE PLANS

FREE PREVIEW
LAUNCH REPORT
FOUNDER MONITOR
Risk grade for your URL

Risk grade for your URL

A single A-F letter grade summarizing your site's overall security posture, computed from every check we run. It's the fastest way to see at a glance whether you're in good shape or need to act.

Critical findings, named

Critical findings, named

The most severe issues we find, spelled out by name (like an exposed API key) instead of a vague risk score. You'll know exactly what's wrong before you decide to fix it.

All findings, every severity

All findings, every severity

Every issue we find, not just the critical ones - including medium and low severity items that are easy to overlook but still worth fixing before they add up into bigger problems.

Copy-paste AI fix prompts

Copy-paste AI fix prompts

A ready-to-paste prompt for each finding that tells your AI coding tool exactly what to fix and how, so remediation takes minutes instead of researching the issue yourself.

Full evidence & PDF export

Full evidence & PDF export

The exact evidence behind every finding (redacted where sensitive), plus a downloadable PDF report - useful for sharing proof of your security posture with teammates, customers, or investors.

Weekly automated re-scans

Weekly automated re-scans

We re-check your app every week automatically, so a new issue introduced by a code change gets caught even if you forget to run a manual scan.

Change & regression alerts

Change & regression alerts

An email the moment a previously-passing check starts failing, so you catch a regression - like a security header that got removed - right after it ships, not weeks later.

Grade history & trends

Grade history & trends

See how your security grade has changed over time, so you can tell whether your posture is improving or slipping as your app evolves.

SAFE BY DEFAULT

WE ONLY RUN
HTTP security headers & TLS / certificate metadata
DNS, robots & sitemap metadata
Public JavaScript & asset inspection
Safe HEAD/GET on obvious public files
Technology fingerprinting
WE NEVER
Exploit attempts or destructive tests
Form fuzzing or credential testing
Authenticated or internal scans without consent
High-volume crawling
Anything that could degrade availability

FAQ

Is scanning my site safe?
Yes. The free scan is passive and public-only. No exploit attempts, no fuzzing, no authenticated access, and nothing that could degrade your site.
Do I need to give you code access?
No. A free scan needs only a public URL. Deeper checks like repository scanning require you to verify ownership and grant explicit access first.
What do I get for free?
Your critical findings with severity and business impact, redacted evidence, and one basic fix per issue. Upgrade for the full report and fix prompts.
How fast are results?
Most public scans finish in about a minute. You'll see progress as checks complete, then a findings report you can act on right away.

FIND OUT WHAT YOU'RE EXPOSING.