How it works
You paste a link. We open your app the way a visitor's browser would, collect what it can see, and check it against a list of common launch problems, including the ones AI-built apps often ship with. You get a score, a status for six areas, and the issues we found.
What we check
Security
Database and payment keys left in your page code, tables anyone can read, missing security headers, and exposed files like .env and source maps.
SEO
Whether search engines see your content or an empty page. Titles, descriptions, link previews, sitemap and robots.txt.
Speed
Core Web Vitals, script size and images, measured with Lighthouse on a mobile profile.
Design & UX
Whether the homepage looks like one product — text sizes, buttons, headings, a clear first screen — and works on a phone: no sideways scrolling, tap targets big enough, forms that don't zoom.
Payments
Whether checkout works, whether a visitor can change the price in the browser, and secret payment keys in the code.
Legal
Privacy policy, terms, a cookie banner when you use trackers, a way to contact you, and SPF, DKIM and DMARC records for your email.
Costs
Paid AI APIs like OpenAI or Anthropic called straight from the browser, where anyone can reuse your key and run up your bill.
What we don't check
A good score means none of our checks found a problem. It doesn't mean the app has no problems.
Pages behind a login
The free scan sees what a signed-out visitor sees.
Your source code
We read only the code your site sends to every browser. Your server code and database stay out of reach.
Business rules
Whether discounts stack or a trial can be restarted. These need a person who knows your product.
Load and attack testing
We never try to overload your site, guess passwords or break in.
Mobile apps
Not yet. We don't check apps from the App Store or Google Play. Telegram bots are checked in beta: paste @username into the same field.
Passive and active checks
Passive: every scan
Only what any browser can see. You confirm the app is yours, or that you have permission.
- Load your pages and the scripts they use
- Read response headers and cookie settings
- Look up DNS records for your domain
- Request a short list of well-known files, like /.env and /.git/config, with plain GET requests
- Run Lighthouse for speed and SEO
Active: only after you verify ownership
These touch your data, so we run them only on apps you have proved are yours.
- Use the public database key from your code to test whether tables can be read without signing in
- Sign in with two test accounts you give us, to check that one user can't see another user's data
Verifying that you own the app
Coming soon. Pick one of three ways. Each uses a token from your projects page.
Meta tag
Add a tag with your token to the <head> of your home page.
File
Upload a file with your token to /.well-known/okaytoship.txt.
DNS record
Add a TXT record with your token to your domain.
Limits
- 3 free scans per domain a day, with a quick bot check.
- We don't scan government, banking, healthcare or education sites.
- Only public domains. No IP addresses or internal networks.