Skip to content
ScanMyApp
AI AGENTHuman-verified reports when it matters

Your AI code audit agent

Finds leaked keys, open databases and unprotected routes in your app — with fix prompts you can paste straight into Cursor, Lovable or Claude Code.

Results in secondsNo signupPassive checks only

scanmyapp-agent · your-app.com● example
Platform detectedLovable + Supabase
HTTPS & certificatevalid
Security headers2 missing
Secrets in public JS1 exposed key
Exposed files (.env, .git)none
Checking source maps_
SECURITY SCORE62/100
1 critical2 high1 low

BUILT FOR APPS ON

  • Supabase
  • Next.js
  • Lovable
  • Cursor
  • Laravel
  • Firebase
  • Python

Why ScanMyApp

A code audit without the agency overhead

Traditional security reviews are built for enterprise teams. Ours is built for founders and developers who ship fast.

Time to first results
Weeks of scheduling
Seconds for the free scan, minutes for an audit
Sales process
Scoping calls and custom quotes
No calls. Fixed prices, paid online
Report
Long PDF written for security teams
Plain-English findings, ranked by severity
Fixes
“Remediate according to best practices”
Copy-paste prompts for Cursor, Lovable or Claude Code
Human review
Always, and billed by the day
Only when you need it, from $249

What the agent checks

The flaws AI coding tools leave behind

Raw scanner output is a wall of noise. Our agent cross-checks every result, drops duplicates and false positives, explains each issue in plain English and writes the fix.

  • secrets

    Leaked API keys

    OpenAI, Stripe or Supabase service_role keys shipped in your front-end or buried in Git history.

  • database

    Missing Row Level Security

    Supabase tables anyone can read or write, and Firebase rules left open after testing.

  • auth

    Unprotected API routes

    Endpoints that skip authentication or trust the user ID sent by the browser.

  • dependencies

    Vulnerable dependencies

    Packages with known CVEs in your npm, Composer or pip lockfiles.

  • headers

    Missing security headers

    No Content-Security-Policy, HSTS or frame protection on your public pages.

  • exposure

    Exposed files

    .env files, .git folders, backups and source maps reachable from the internet.

The report

Every finding comes with the fix

A clear PDF a non-developer can read: score out of 100, the three priorities to fix first, the exact file and line, and a prompt you paste back into your AI tool.

See a full sample report
Sample · Express auditScore 58/100
  • criticalRow Level Security disabled on table “profiles”
    supabase/migrations/002_profiles.sql
  • highAPI route returns any user’s orders without auth check
    app/api/orders/route.ts:14
  • lowReferrer-Policy header not set
    next.config.ts
Fix promptcopy

In supabase/migrations/002_profiles.sql, the table "profiles" has Row Level Security disabled. Enable RLS on this table and add a policy so users can only select and update their own row (auth.uid() = id). Do not change any other table.

How it works

Three steps. Zero calls.

  1. 01

    Paste your URL or connect your repo

    Start with the free external scan, or connect GitHub in read-only mode (or upload a zip) for a full audit.

  2. 02

    The agent audits your code

    Our scanning engine runs in a disposable container, then the AI reads your auth, routes and database rules like a reviewer would. Your code is never executed.

  3. 03

    Get your report and fix prompts

    Score, ranked findings and copy-paste fixes in minutes. On premium plans, a senior engineer verifies every finding first.

We scan ourselves

We run ScanMyApp on ScanMyApp.

A security tool has to pass its own test. We publish our own score and update it after every release.

SCANMYAPP.DEV SCOREFirst report coming soon
Our security

Security first

We apply what we sell

  • Your code is analysed statically, never executed
  • Cloned code is deleted right after the analysis
  • Read-only GitHub access, revocable in one click
  • NDA signed online before any full audit
  • Scores come from fixed rules, never invented by AI

Pricing

Simple, fixed pricing

No calls, no surprises. Refunded if the report brings nothing useful.

Free scan — $0

Passive external checks on your live URL. Score in seconds, no signup.

Scan my app free

Express audit

AI AGENT

$99one-time

Report in minutes

  • Full repository analysis
  • Security score out of 100
  • Findings ranked by severity
  • Copy-paste fix prompts
  • PDF + online report
Start an express audit

AI + human review

HUMAN-VERIFIED

$249–$499one-time

Delivered in 48–72 h

  • Everything in Express
  • False positives removed by an engineer
  • Human recommendations
  • “Verified by an expert” report
Get a verified review

Full code audit

HUMAN-VERIFIED

$1,500–$3,000fixed quote, instant

Delivered in 5–10 days

  • Architecture, quality, database and security
  • Led by a senior security engineer
  • Video walkthrough of the findings
  • NDA signed before access
Get my instant quote

Already fixed your issues? Re-scan from $49 and get a before/after report.

Is your app leaking something right now?

Find out in seconds. Free, passive, no signup.

Results in secondsNo signupPassive checks only

FAQ

Questions, answered

Is this a penetration test?

No. The free scan only reads what is publicly visible from your URL, and audits analyse your source code statically. We never attack your app, run exploits or brute-force anything.

What happens to my code?

It is cloned with read-only access into a disposable, isolated container, analysed without ever being executed, then deleted. Only the findings are kept.

Which stacks do you support?

Laravel/PHP, Next.js/Node, Python, and apps built on Supabase or Firebase — including apps made with Lovable, Cursor, Bolt or Replit. Other stacks are declined automatically rather than half-audited.

Do I need to book a call?

Never. You order, pay and receive your report online. Full audits get an instant quote from a short form and a recorded video walkthrough instead of a meeting.

Does a good score mean my app is secure?

No. A score reflects what was checked, and every report lists what was not. It is an automated audit, not a security guarantee.

How is the score calculated?

By fixed rules based on the severity of each finding. The AI explains issues and writes fixes, but it never decides your score.

What if the report isn’t useful?

You get a refund. If the report brings nothing useful, tell us and we pay you back.