What a Security Check covers
The same checks on every plan, free or paid. 57 of the rules were written for the holes AI-built apps leave. Pick your stack to see what they catch in your app, and what they miss.
- Secrets
- 214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
- Dependencies
- Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
- Code
- 57 rules for the holes AI-built apps leave, plus 344 general rules at Low.
- Configuration
- Dockerfile, Kubernetes, Terraform, and 27 mobile checks.
What it covers for your app
Pick what you built with.
- Secrets
Covered: Stripe, OpenAI, Anthropic, AWS and GitHub keys, in your files and git history
Covered: A Supabase service-role key, found as a JSON Web Token
Not covered: A Postgres DATABASE_URL connection string
- Dependencies
Covered: package-lock.json, yarn.lock, pnpm-lock.yaml and bun.lock
Not covered: bun.lockb, the binary lockfile (commit the text bun.lock)
Not covered: devDependencies, skipped on purpose
- Code
Covered: Supabase row-level security: open policies, RLS switched off, policies trusting user_metadata
Covered: Admin checks only in "use client" components, swapped IDs, server actions with no auth check
Covered: Server secrets in NEXT_PUBLIC_ variables
- Configuration
Covered: Your Dockerfile, if you have one
Not covered: Vercel project settings
Try
Where it stops
Secrets
- Database connection strings: MongoDB, Postgres, Redis, AMQP.
- Providers without their own rule, such as Postmark, PayPal, Vercel, Segment and Docker Hub. Only a key-named, random-looking value is flagged.
Dependencies
- Development and test dependencies.
bun.lockb, andgo.sumwithoutgo.mod.- Unpinned ranges in
requirements.txt, and Maven versions set by a parent or BOM. - CocoaPods beyond the 8 pods on our own list.
Code and configuration
- Ruby, Rust, Elixir, PHP and Objective-C code.
- Docker Compose files. Helm, CloudFormation and ARM templates are not claimed.
Everything else
- Your running app. Nothing is built, installed or run.
- On an individual plan, a repository over 500 MB or 20,000 files: no git history for secrets, and code rules read the first 20,000 files. The report says so.
A clean report means these checks found nothing blocking on that commit. It is a good sign and never a guarantee.
Try it on your own code.
One free check per repository. No card. Compare plans