Skip to content
ScanMyApp

Free scan · No signup

Free vulnerability scan for your app

Paste your app URL. We check what anyone on the internet can see: leaked keys in your JavaScript, exposed files, missing security headers. You get a score and the fixes.

Launch period: each scan is reviewed by an engineer before it’s sent. Your report arrives by email within 24 hours.

  • Passive checks only — we never attack your app
  • No account, no credit card
  • 3 free scans per day

What the free scan checks

Everything visible from your URL

These checks read your public pages and files, exactly like a curious visitor would.

  • Secrets in your public JavaScript

    OpenAI keys, Stripe secret keys, Supabase service_role keys and other credentials shipped to the browser.

  • Exposed files

    .env files, .git folders, backups and source maps reachable from the internet.

  • Security headers

    Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options and Referrer-Policy.

  • HTTPS and certificate

    Certificate validity and the redirect from HTTP to HTTPS.

  • Supabase exposure

    Whether your project URL and public key are visible, so you know what an attacker sees.

  • Your platform

    Lovable, Bolt, Vercel, Netlify… so the advice fits how your app was built.

What it can’t see

The worst flaws live in your code

A green external scan doesn’t mean a safe app. The express audit reads your repository and finds what the URL can’t show.

Run the $99 express audit
  • Your source code and Git historyaudit
  • Database rules (Row Level Security, Firebase rules)audit
  • Authentication and API route logicaudit
  • Vulnerable dependenciesaudit

FAQ

About the free scan

Is the scan safe for my live app?

Yes. It only reads what any visitor can already see from your URL. No attacks, no injections, no brute force and nothing is written to your app. Our requests identify themselves as ScanMyApp-Bot (see scanmyapp.dev/bot).

Why is the report sent by email?

During our launch, every free scan is reviewed by an engineer before it is sent, so you never get an invented finding. You receive it within 24 hours.

Is a clean scan a sign my app is secure?

No. The external scan sees only part of the risk. Most serious issues in AI-built apps live in the code and the database rules, which only an audit can check.

What do you do with my email?

We use it to send your report. Tips and alerts are only sent if you tick the box, and every email has an unsubscribe link.