Background: I review AI-built apps for clients, and the same problems kept showing up on sites that worked perfectly:
- Row-level security is off, so the public Supabase key in the page returns entire tables to anyone.
- Secret keys are sitting in the JS bundle.
- A .env file or source maps got shipped by accident.
- There are no SPF or DKIM records, so password resets land in spam.
So I automated the outside part of what I check.
You paste a URL, and in about 20 minutes it:
- reads up to 20 pages in a phone browser
- checks every script for leaked keys
- asks your database for rows using the public key from your own page, the way a stranger would
- tries 63 common private file paths
- checks email DNS, headers and TLS
- runs OWASP ZAP and Nuclei
You get a score out of 100, a Ready / Almost / Hold verdict, and the most serious thing it found. That part is free, with no signup. The full report with every finding and the fix (as code and as a prompt for your AI tool) is $49.99 one time.
What it can't do: it doesn't log in, so anything behind auth goes untested. That includes whether user A can see user B's data once logged in, so you still need the two-browser test for that. It's automated, not a human pentest. It also sends real test input, so only run it on a site you own.
From the scans so far: 200+ sites checked, 36% came back Hold, and the most common critical finding was weak db security.
I'd really like feedback on false positives and on what it misses. trylaunchproof.com
Source: r/nocode · by /u/Negative-Tank2221