For AI-built codebasesBuilt with Claude Code, Cursor, Lovable or Bolt?

You shipped fast.Now find out what it cost you.

AI writes working code quickly. It also leaves committed API keys, outdated dependencies and missing permission checks behind. Connect a repository and get an automated review that shows you exactly what to fix first — in language you do not need a security engineer to translate.

Free audit · no card required · read-only GitHub access

harbourline/harbour-app · main

Needs attention

Two live credentials are committed to this repository and three dependencies have published advisories. Rotate the credentials first — the exposure continues until you do.

2

Critical

3

High

3

Medium

3

Low

CriticalHigh confidence

Supabase service role key committed to the repository

apps/web/.env.production:7

CriticalHigh confidence

Next.js version allows middleware authorization to be bypassed

package-lock.json · next 15.2.2 → 15.2.3

MediumLow confidence · requires human review

API route reads a record by id without an ownership check

app/api/invoices/[id]/route.ts:9

Not covered by this audit: SQL files, 38 vendored files, and ESLint stopped at its time limit after 310 of 412 files.

Illustrative example. Automated findings require review and are not a penetration test.

What we check

Five things AI-assisted code gets wrong

Not because the model is careless, but because it cannot see your whole system — and neither can a founder reading a diff at midnight.

Credentials in your code

API keys, database secrets and tokens committed to the repository. The single most common finding, and the one that costs the most.

Dependencies with known advisories

Your lockfile read against the public advisory database, with the exact version that fixes each one.

Missing permission checks

Endpoints that fetch a record by id and return it without confirming it belongs to the person asking.

Unsafe patterns

Raw HTML rendering, string-built SQL, cookies without the Secure flag, and other patterns with a long history of going wrong.

Reliability gaps

Swallowed errors and unawaited promises — the reason a webhook can report success while quietly doing nothing.

What we could not check

Every report names the files skipped, the languages unsupported and the scanners that ran short. Coverage you cannot see is not coverage.

Four steps

Connect a repository. Read the report. Fix. Re-scan.

The first audit takes a couple of minutes. You do not install anything, and you do not give us write access.

Connect GitHub

Install our GitHub App and pick the repositories it may see. Read-only, and you choose the list.

Start an audit

Choose a branch. We fetch a snapshot into an isolated sandbox and run the scanners that fit your languages.

Read the report

Findings ordered by what matters, each with the file, the line, the evidence and what to do about it.

Fix and re-scan

Re-run against your fix branch. The report tells you which findings you closed and which are new.

How we handle your code

We never run your code. Not once, not anywhere.

A code scanner that installs your dependencies to check them has already executed whatever those dependencies wanted to run. That is the supply-chain attack we exist to warn you about, so we refuse to perform it.

No dependency installation

We read your lockfile and check the exact versions it pins against the advisory database. Nothing is installed, so nothing gets to run.

Isolated, disposable sandboxes

Each scan runs in its own throwaway container with no network access, no credentials in its environment, and hard CPU, memory and time limits.

Your source is not kept

The snapshot is destroyed when the scan ends. We keep the findings and short evidence excerpts — never whole files, never an archive.

Read-only, least privilege

The GitHub App asks for read access to repository contents and nothing else. It cannot push, open pull requests, or change your settings.

Honest limits

What this is — and what it is not

It is

  • An automated code-health and security review
  • Evidence you can check yourself, line by line
  • A prioritised list of what to fix first
  • An honest account of what was not covered

It is not

  • A penetration test
  • A certification or compliance audit
  • A guarantee that your code has no problems
  • A substitute for a human review before you scale

Automated analysis finds classes of problems, not every problem. We report potential issues with a confidence level, and we mark the ones a person needs to judge. We will never tell you your code is secure, because no tool can honestly say that.

Pricing

Start free. Upgrade when re-scanning becomes a habit.

Your first audit costs nothing and needs no card. Most founders find something in it.

Free
One repository, one audit a month. Enough to see where you stand.
$0.00/month
Billed monthly
  • 1 connected repository
  • 1 audit per month
  • Secret scanning and dependency checks
  • Full report with evidence and remediation
  • Findings history kept for 30 days
Most popular
Pro
For founders shipping continuously and re-scanning as they fix.
$49.00/month
Billed monthly
  • Up to 10 connected repositories
  • 30 audits per month
  • All scanners, including Semgrep and Python analysis
  • Unlimited re-scans to confirm your fixes
  • Fix tracking across audits
  • Findings history kept for 12 months
  • Email alerts on critical findings
Audit credits
A one-off pack for a launch push. No subscription, never expires.
$39.00/month
Lifetime
  • 25 audits, used whenever you need them
  • Credits never expire
  • Stack on top of Free or Pro
  • Same scanners and same report
Team
For agencies and accelerators reviewing many codebases.
Talk to us
Billed monthly
  • Unlimited repositories
  • Shared workspace with roles and permissions
  • Portfolio view across every codebase
  • Priority scanning queue
  • Onboarding support

Find out before your users do

One repository, one audit, a few minutes. If it comes back clean, that is worth knowing too.

Free audit · no card required · read-only GitHub access