Scan free

What a Security Check covers

The same checks on every plan, free or paid. 57 of the rules were written for the holes AI-built apps leave. Pick your stack to see what they catch in your app, and what they miss.

Secrets
214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
Dependencies
Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
Code
57 rules for the holes AI-built apps leave, plus 344 general rules at Low.
Configuration
Dockerfile, Kubernetes, Terraform, and 27 mobile checks.

What it covers for your app

Pick what you built with.

Secrets

Covered: Stripe, OpenAI, Anthropic, AWS and GitHub keys, in your files and git history

Covered: A Supabase service-role key, found as a JSON Web Token

Not covered: A Postgres DATABASE_URL connection string

Dependencies

Covered: package-lock.json, yarn.lock, pnpm-lock.yaml and bun.lock

Not covered: bun.lockb, the binary lockfile (commit the text bun.lock)

Not covered: devDependencies, skipped on purpose

Code

Covered: Supabase row-level security: open policies, RLS switched off, policies trusting user_metadata

Covered: Admin checks only in "use client" components, swapped IDs, server actions with no auth check

Covered: Server secrets in NEXT_PUBLIC_ variables

Configuration

Covered: Your Dockerfile, if you have one

Not covered: Vercel project settings

Where it stops

Secrets

  • Database connection strings: MongoDB, Postgres, Redis, AMQP.
  • Providers without their own rule, such as Postmark, PayPal, Vercel, Segment and Docker Hub. Only a key-named, random-looking value is flagged.

Dependencies

  • Development and test dependencies.
  • bun.lockb, and go.sum without go.mod.
  • Unpinned ranges in requirements.txt, and Maven versions set by a parent or BOM.
  • CocoaPods beyond the 8 pods on our own list.

Code and configuration

  • Ruby, Rust, Elixir, PHP and Objective-C code.
  • Docker Compose files. Helm, CloudFormation and ARM templates are not claimed.

Everything else

  • Your running app. Nothing is built, installed or run.
  • On an individual plan, a repository over 500 MB or 20,000 files: no git history for secrets, and code rules read the first 20,000 files. The report says so.

A clean report means these checks found nothing blocking on that commit. It is a good sign and never a guarantee.

Try it on your own code.

Scan free

One free check per repository. No card. Compare plans

CodexMotiveShield: an audit for the app you did not entirely write.

© 2026 CodexMotive. Scanning reads your files; it never runs them.