What we check

Five areas, checked automatically every time we scan your code and your live site. Here's what's in each one, and what we've found in real apps.

Security

The failures we find most often in AI-built products. None of them are clever attacks. All of them are one line of missing code between a stranger and your users' data.

From a real scan

17 leaked keys in one codebase, including two Stripe keys and a private signing key. 15 of them were still in the live code.

What we find most often

Keys sitting in your JavaScript

API keys and tokens hardcoded into the bundle every visitor downloads.

Database tables anyone can read

Missing Supabase row-level security or Firebase rules, leaving user records open to anyone holding the public key.

Routes that never ask who you are

API endpoints that create, change or delete records without checking identity.

Secrets committed to the repo

.env files and credentials sitting in your git history, still live long after they were pasted in.

Dependencies with known exploits

Packages carrying published vulnerabilities, including the ones you never chose directly.

Unsafe rendering and missing headers

Patterns that let someone else's content run inside your users' browsers.

The checks

Leaked secrets
A password or key that unlocks one of your accounts, sitting in your code or its history where anyone with a copy can read it. We treat every one as already stolen.
Risky code
Patterns in your own code that give an attacker a way in, usually by letting them slip their own instructions into something your app trusts.
Vulnerable dependencies
Your project is built on other people's code, and some of it has publicly known flaws. Attackers scan for exactly these, because the weakness is already written up.
Missing security headers
Standard settings that tell browsers how to protect your visitors. Without them, browsers fall back to their most permissive behaviour.
Legal pages
Pages you are required to publish in the UK and EU, like a privacy policy and a sub-processor disclosure. The gap usually surfaces in a customer's security review or a regulator's complaint.

AI security review

An AI model also reads how your app fits together and asks how someone could misuse it, using STRIDE, a standard way of listing how software gets attacked. Its findings are labelled AI-generated and treated as leads to confirm, not verdicts, so they never count towards your score.

Accessibility

The people who can't use what you built, and the standards your customers' procurement teams will ask about.

From a real scan

A site that blocked zooming on phones and gave keyboard users no way to skip past its repeated menus.

The checks

Screen readers and keyboards
Parts of a site that people relying on a screen reader or a keyboard cannot use. That locks out real customers, and in many places it is also a legal requirement.

SEO

The reasons search engines can't find, read or rank the product you just launched.

From a real scan

99 pages that almost nothing linked to, and the same page title used on 100 pages.

The checks

Search basics
The tags that tell Google and social platforms what each page is. When they're missing or wrong, pages rank lower and look broken when shared.
How search engines find your pages
Whether search engines can find and index your pages. A page that never gets crawled can never rank, however good it is.
Page content
Pages with too little on them for search engines to treat as worth showing. Search engines increasingly drop thin pages from results altogether.
Trust signals
Whether a real, accountable business is clearly behind the site: a contact page, a privacy policy, named authors. It matters most if you sell anything or write about money, health or safety.
Internal links
Whether your pages link to each other, so visitors and search engines can move between them instead of hitting dead ends.
AI agent readiness
How easily AI assistants like ChatGPT and Claude can read your site. These are recommendations only and never affect your score.

Reliability & Performance

Slow pages and silent errors that lose people before they ever sign up.

From a real scan

No caching on any of 100 pages, and one JavaScript file over 250 KB.

The checks

Speed
Pages that are slower to load than they need to be. Visitors leave slow pages, and Google factors loading speed into where you rank.

Housekeeping

Dead code, unused dependencies and duplication: the drag that makes every future change slower.

From a real scan

600 unused files and 962 copied blocks of code in a single project.

The checks

Project setup
Groundwork most projects have, like keeping .env files out of git, error monitoring and a pinned Node version. None of it is urgent on its own, but each one is a safety net you will want later.
Copy-pasted code
The same logic copied into more than one place. Fix a bug in one copy and the others keep it, which is how problems you thought were fixed come back.
Unused packages
Packages your project installs but never uses. Each one is extra code shipped with your app, and one more thing that can carry a security flaw.
Unused code
Files nothing in your project uses. They're a common leftover from AI coding tools, and they make every change riskier because it is not obvious what is safe to touch.

How we score it

Every finding gets a severity, so you always know what to fix first.

Critical
Someone could exploit this now. Fix it first.
High
Serious, and worth fixing this week.
Medium
A real weakness to fix when you can.
Low
Minor, but worth tidying.
Info
For awareness only. Never urgent.

See what we'd find in your code.

Your first scan is free.

Scan my code for free
Not a challenge at all. The explanations are the best part for me. Simple and clear.
Alice ClementsAlice ClementsFounder, Tooti Music