Your AI code audit agent
Finds leaked keys, open databases and unprotected routes in your app — with fix prompts you can paste straight into Cursor, Lovable or Claude Code.
BUILT FOR APPS ON
- Supabase
- Next.js
- Lovable
- Cursor
- Laravel
- Firebase
- Python
Why ScanMyApp
A code audit without the agency overhead
Traditional security reviews are built for enterprise teams. Ours is built for founders and developers who ship fast.
What the agent checks
The flaws AI coding tools leave behind
Raw scanner output is a wall of noise. Our agent cross-checks every result, drops duplicates and false positives, explains each issue in plain English and writes the fix.
- secrets
Leaked API keys
OpenAI, Stripe or Supabase service_role keys shipped in your front-end or buried in Git history.
- database
Missing Row Level Security
Supabase tables anyone can read or write, and Firebase rules left open after testing.
- auth
Unprotected API routes
Endpoints that skip authentication or trust the user ID sent by the browser.
- dependencies
Vulnerable dependencies
Packages with known CVEs in your npm, Composer or pip lockfiles.
- headers
Missing security headers
No Content-Security-Policy, HSTS or frame protection on your public pages.
- exposure
Exposed files
.env files, .git folders, backups and source maps reachable from the internet.
The report
Every finding comes with the fix
A clear PDF a non-developer can read: score out of 100, the three priorities to fix first, the exact file and line, and a prompt you paste back into your AI tool.
- criticalRow Level Security disabled on table “profiles”supabase/migrations/002_profiles.sql
- highAPI route returns any user’s orders without auth checkapp/api/orders/route.ts:14
- lowReferrer-Policy header not setnext.config.ts
In supabase/migrations/002_profiles.sql, the table "profiles" has Row Level Security disabled. Enable RLS on this table and add a policy so users can only select and update their own row (auth.uid() = id). Do not change any other table.
How it works
Three steps. Zero calls.
- 01
Paste your URL or connect your repo
Start with the free external scan, or connect GitHub in read-only mode (or upload a zip) for a full audit.
- 02
The agent audits your code
Our scanning engine runs in a disposable container, then the AI reads your auth, routes and database rules like a reviewer would. Your code is never executed.
- 03
Get your report and fix prompts
Score, ranked findings and copy-paste fixes in minutes. On premium plans, a senior engineer verifies every finding first.
We scan ourselves
We run ScanMyApp on ScanMyApp.
A security tool has to pass its own test. We publish our own score and update it after every release.
Security first
We apply what we sell
- Your code is analysed statically, never executed
- Cloned code is deleted right after the analysis
- Read-only GitHub access, revocable in one click
- NDA signed online before any full audit
- Scores come from fixed rules, never invented by AI
Pricing
Simple, fixed pricing
No calls, no surprises. Refunded if the report brings nothing useful.
Free scan — $0
Passive external checks on your live URL. Score in seconds, no signup.
Express audit
AI AGENT$99one-time
Report in minutes
- Full repository analysis
- Security score out of 100
- Findings ranked by severity
- Copy-paste fix prompts
- PDF + online report
AI + human review
HUMAN-VERIFIED$249–$499one-time
Delivered in 48–72 h
- Everything in Express
- False positives removed by an engineer
- Human recommendations
- “Verified by an expert” report
Full code audit
HUMAN-VERIFIED$1,500–$3,000fixed quote, instant
Delivered in 5–10 days
- Architecture, quality, database and security
- Led by a senior security engineer
- Video walkthrough of the findings
- NDA signed before access
Already fixed your issues? Re-scan from $49 and get a before/after report.
Built for your stack
Checks tailored to the tools you build with
- SupabaseMissing RLS, exposed service keys and open tables.Supabase security
- LovableA second opinion when Lovable’s own scan is green.Lovable security
- CursorThe security gaps AI-written code tends to leave.Cursor security
- Vibe-coded appsBolt, Replit and every AI-built app shipped fast.Vibe-coded apps security
Is your app leaking something right now?
Find out in seconds. Free, passive, no signup.
FAQ
Questions, answered
Is this a penetration test?
No. The free scan only reads what is publicly visible from your URL, and audits analyse your source code statically. We never attack your app, run exploits or brute-force anything.
What happens to my code?
It is cloned with read-only access into a disposable, isolated container, analysed without ever being executed, then deleted. Only the findings are kept.
Which stacks do you support?
Laravel/PHP, Next.js/Node, Python, and apps built on Supabase or Firebase — including apps made with Lovable, Cursor, Bolt or Replit. Other stacks are declined automatically rather than half-audited.
Do I need to book a call?
Never. You order, pay and receive your report online. Full audits get an instant quote from a short form and a recorded video walkthrough instead of a meeting.
Does a good score mean my app is secure?
No. A score reflects what was checked, and every report lists what was not. It is an automated audit, not a security guarantee.
How is the score calculated?
By fixed rules based on the severity of each finding. The AI explains issues and writes fixes, but it never decides your score.
What if the report isn’t useful?
You get a refund. If the report brings nothing useful, tell us and we pay you back.
