Skip to content
DnsLister Forum

Where domain hunters compare notes

LaunchProof: a free outside-in security and launch check for AI-built sites (Lovable, Bolt, Base44, Cursor, Replit)

Background: I review AI-built apps for clients, and the same problems kept showing up on sites that worked perfectly:

  • Row-level security is off, so the public Supabase key in the page returns entire tables to anyone.
  • Secret keys are sitting in the JS bundle.
  • A .env file or source maps got shipped by accident.
  • There are no SPF or DKIM records, so password resets land in spam.

So I automated the outside part of what I check.

You paste a URL, and in about 20 minutes it:

  • reads up to 20 pages in a phone browser
  • checks every script for leaked keys
  • asks your database for rows using the public key from your own page, the way a stranger would
  • tries 63 common private file paths
  • checks email DNS, headers and TLS
  • runs OWASP ZAP and Nuclei

You get a score out of 100, a Ready / Almost / Hold verdict, and the most serious thing it found. That part is free, with no signup. The full report with every finding and the fix (as code and as a prompt for your AI tool) is $49.99 one time.

What it can't do: it doesn't log in, so anything behind auth goes untested. That includes whether user A can see user B's data once logged in, so you still need the two-browser test for that. It's automated, not a human pentest. It also sends real test input, so only run it on a site you own.

From the scans so far: 200+ sites checked, 36% came back Hold, and the most common critical finding was weak db security.

I'd really like feedback on false positives and on what it misses. trylaunchproof.com

Source: r/nocode · by /u/Negative-Tank2221

Leave a Reply

Your email address will not be published. Required fields are marked *