What we check
Five areas, checked automatically every time we scan your code and your live site. Here's what's in each one, and what we've found in real apps.
Security
The failures we find most often in AI-built products. None of them are clever attacks. All of them are one line of missing code between a stranger and your users' data.
17 leaked keys in one codebase, including two Stripe keys and a private signing key. 15 of them were still in the live code.
What we find most often
Keys sitting in your JavaScript
API keys and tokens hardcoded into the bundle every visitor downloads.
Database tables anyone can read
Missing Supabase row-level security or Firebase rules, leaving user records open to anyone holding the public key.
Routes that never ask who you are
API endpoints that create, change or delete records without checking identity.
Secrets committed to the repo
.env files and credentials sitting in your git history, still live long after they were pasted in.
Dependencies with known exploits
Packages carrying published vulnerabilities, including the ones you never chose directly.
Unsafe rendering and missing headers
Patterns that let someone else's content run inside your users' browsers.
The checks
- Leaked secrets
- A password or key that unlocks one of your accounts, sitting in your code or its history where anyone with a copy can read it. We treat every one as already stolen.
- Risky code
- Patterns in your own code that give an attacker a way in, usually by letting them slip their own instructions into something your app trusts.
- Vulnerable dependencies
- Your project is built on other people's code, and some of it has publicly known flaws. Attackers scan for exactly these, because the weakness is already written up.
- Missing security headers
- Standard settings that tell browsers how to protect your visitors. Without them, browsers fall back to their most permissive behaviour.
- Legal pages
- Pages you are required to publish in the UK and EU, like a privacy policy and a sub-processor disclosure. The gap usually surfaces in a customer's security review or a regulator's complaint.
AI security review
An AI model also reads how your app fits together and asks how someone could misuse it, using STRIDE, a standard way of listing how software gets attacked. Its findings are labelled AI-generated and treated as leads to confirm, not verdicts, so they never count towards your score.
Accessibility
The people who can't use what you built, and the standards your customers' procurement teams will ask about.
A site that blocked zooming on phones and gave keyboard users no way to skip past its repeated menus.
The checks
- Screen readers and keyboards
- Parts of a site that people relying on a screen reader or a keyboard cannot use. That locks out real customers, and in many places it is also a legal requirement.
SEO
The reasons search engines can't find, read or rank the product you just launched.
99 pages that almost nothing linked to, and the same page title used on 100 pages.
The checks
- Search basics
- The tags that tell Google and social platforms what each page is. When they're missing or wrong, pages rank lower and look broken when shared.
- How search engines find your pages
- Whether search engines can find and index your pages. A page that never gets crawled can never rank, however good it is.
- Page content
- Pages with too little on them for search engines to treat as worth showing. Search engines increasingly drop thin pages from results altogether.
- Trust signals
- Whether a real, accountable business is clearly behind the site: a contact page, a privacy policy, named authors. It matters most if you sell anything or write about money, health or safety.
- Internal links
- Whether your pages link to each other, so visitors and search engines can move between them instead of hitting dead ends.
- AI agent readiness
- How easily AI assistants like ChatGPT and Claude can read your site. These are recommendations only and never affect your score.
Reliability & Performance
Slow pages and silent errors that lose people before they ever sign up.
No caching on any of 100 pages, and one JavaScript file over 250 KB.
The checks
- Speed
- Pages that are slower to load than they need to be. Visitors leave slow pages, and Google factors loading speed into where you rank.
Housekeeping
Dead code, unused dependencies and duplication: the drag that makes every future change slower.
600 unused files and 962 copied blocks of code in a single project.
The checks
- Project setup
- Groundwork most projects have, like keeping .env files out of git, error monitoring and a pinned Node version. None of it is urgent on its own, but each one is a safety net you will want later.
- Copy-pasted code
- The same logic copied into more than one place. Fix a bug in one copy and the others keep it, which is how problems you thought were fixed come back.
- Unused packages
- Packages your project installs but never uses. Each one is extra code shipped with your app, and one more thing that can carry a security flaw.
- Unused code
- Files nothing in your project uses. They're a common leftover from AI coding tools, and they make every change riskier because it is not obvious what is safe to touch.
How we score it
Every finding gets a severity, so you always know what to fix first.
- Critical
- Someone could exploit this now. Fix it first.
- High
- Serious, and worth fixing this week.
- Medium
- A real weakness to fix when you can.
- Low
- Minor, but worth tidying.
- Info
- For awareness only. Never urgent.
Not a challenge at all. The explanations are the best part for me. Simple and clear.
Alice ClementsFounder, Tooti Music