Skip to content
OkayToShip

Sample report

Sample report on our own test app. We built a small app and left in common mistakes on purpose, so you can see exactly what the full report gives you. These are the real results of the same checks we run on your project, scanned on Oct 11, 2026.

Sampledemo.okaytoship.com

Sample report on our own test app · Oct 11, 2026

Score 23 out of 100

Not ready to launch: 2 critical problems could expose your data or money — fix them first.

22 issues: 2 critical, 4 high, 9 medium, 6 low, 1 info

  • SecurityCriticalYour database master key is visible in your site's code
  • PaymentsCriticalYour Stripe secret key is visible in your site's code
  • SEONeeds workSearch engines and link previews see an empty page
  • SpeedOKNothing to fix here
  • LegalNeeds workNo Privacy Policy link on your homepage
  • CostsNeeds workYour site calls OpenAI directly from the visitor's browser

22 issues, all open

This is what the full report looks like. Open any issue to see the evidence, the risk and how to fix it.

  • Anyone can copy this key and act as your Stripe account: see your customers and their payments, issue refunds, or create charges. Real money can leave your account.

    Do this today: Revoke this key now in your Stripe dashboard and create a new one. It's already public, so removing it from the code is not enough.

    How to fix
    1. Revoke this key now in your Stripe dashboard and create a new one. It's already public, so removing it from the code is not enough.
    2. Move the new key to the server side only: an Edge Function, API route or backend, reading it from a secret environment variable. Never use a public prefix like VITE_, NEXT_PUBLIC_ or REACT_APP_ for it.
    3. Make the page call your server function instead of using the key directly.
    4. In the browser use only the publishable key. Create checkout sessions on the server with the secret key.
    5. Publish the site again and re-run this scan to confirm the key is gone.

    My app exposes a Stripe live secret key in the frontend code that every visitor downloads (it starts with "sk_liv…"). Remove this key from all client-side code and from any environment variables that get bundled into the browser. Move every operation that needs it into a server-side function that reads the key from a secret environment variable, and change the frontend to call that function instead. In the browser use only the publishable key. Create checkout sessions on the server with the secret key. I will revoke the old key and add the new one to the secrets myself. If this needs a secret key, put the server-side code in a Supabase Edge Function and store the key in the project's secrets (not in the code). Keep everything else working exactly as it does now and don't touch unrelated files. When you're done, list what you changed.

    What we found
    https://demo.okaytoship.com/assets/index-D6yG_D9G.jsStripe live secret key: sk_liv…