Skip to content
OkayToShip

How it works

You paste a link. We open your app the way a visitor's browser would, collect what it can see, and check it against a list of common launch problems, including the ones AI-built apps often ship with. You get a score, a status for six areas, and the issues we found.

What we check

  • Security

    Database and payment keys left in your page code, tables anyone can read, missing security headers, and exposed files like .env and source maps.

  • SEO

    Whether search engines see your content or an empty page. Titles, descriptions, link previews, sitemap and robots.txt.

  • Speed

    Core Web Vitals, script size and images, measured with Lighthouse on a mobile profile.

  • Design & UX

    Whether the homepage looks like one product — text sizes, buttons, headings, a clear first screen — and works on a phone: no sideways scrolling, tap targets big enough, forms that don't zoom.

  • Payments

    Whether checkout works, whether a visitor can change the price in the browser, and secret payment keys in the code.

  • Legal

    Privacy policy, terms, a cookie banner when you use trackers, a way to contact you, and SPF, DKIM and DMARC records for your email.

  • Costs

    Paid AI APIs like OpenAI or Anthropic called straight from the browser, where anyone can reuse your key and run up your bill.

What we don't check

A good score means none of our checks found a problem. It doesn't mean the app has no problems.

  • Pages behind a login

    The free scan sees what a signed-out visitor sees.

  • Your source code

    We read only the code your site sends to every browser. Your server code and database stay out of reach.

  • Business rules

    Whether discounts stack or a trial can be restarted. These need a person who knows your product.

  • Load and attack testing

    We never try to overload your site, guess passwords or break in.

  • Mobile apps

    Not yet. We don't check apps from the App Store or Google Play. Telegram bots are checked in beta: paste @username into the same field.

Passive and active checks

Passive: every scan

Only what any browser can see. You confirm the app is yours, or that you have permission.

  • Load your pages and the scripts they use
  • Read response headers and cookie settings
  • Look up DNS records for your domain
  • Request a short list of well-known files, like /.env and /.git/config, with plain GET requests
  • Run Lighthouse for speed and SEO

Active: only after you verify ownership

These touch your data, so we run them only on apps you have proved are yours.

  • Use the public database key from your code to test whether tables can be read without signing in
  • Sign in with two test accounts you give us, to check that one user can't see another user's data

Verifying that you own the app

Coming soon. Pick one of three ways. Each uses a token from your projects page.

  • Meta tag

    Add a tag with your token to the <head> of your home page.

  • File

    Upload a file with your token to /.well-known/okaytoship.txt.

  • DNS record

    Add a TXT record with your token to your domain.

Limits

  • 3 free scans per domain a day, with a quick bot check.
  • We don't scan government, banking, healthcare or education sites.
  • Only public domains. No IP addresses or internal networks.

How we handle your data

Scan my project