product
changelog
ShipShield V1 Is Live: What We Shipped (and What's Next)
Why we built this
AI tools like Lovable, Bolt, Replit, and v0 let anyone describe an app and ship it — no engineering background required. That's the whole point, and it's genuinely great. The problem is what happens after the AI finishes: the same speed that ships a working app also ships a secret key baked into the JS bundle, or a database with no row-level security, and nobody notices until it's a problem.
Most of the people building these apps aren't developers. They don't know what a CORS header is, and they shouldn't have to. So we built ShipShield: paste a URL, get a plain-English report of what's actually wrong, and a copy-paste prompt to fix it in the same tool you built the app with.
This is V1. Here's what's in it.
What's live today
Public URL scanning, no login required. Paste any live app URL and we run a read-only pass against it — nothing is written, nothing is exploited, nothing is brute-forced.
- Leaked secret keys — we scan the loaded JS bundle for live API keys and service credentials (
sk_live_, Supabaseservice_role, AWSAKIA…, private key blocks, and more) that were never meant to leave the server. - Missing security headers — checks for the headers that stop clickjacking, MIME sniffing, and other browser-level attacks (CSP, X-Frame-Options, HSTS, and friends).
- Exposed config & source files — a careful, rate-limited check for things like
/.envor/.git/configsitting in production where they shouldn't be. - Open CORS policy — flags a backend that will happily talk to any origin on the internet.
A report you'd actually want to screenshot. Every scan produces a grade (A–F) plus a scored breakdown, with each issue explained in plain English: what it is, why it matters, and how bad it actually is. We use three confidence levels — Critical, Likely, Worth Checking — and we never tell you "you're safe." We tell you what we found in the checks we ran, because that's the honest claim.
Copy-paste fixes, not tickets. Every finding ships with a ready-made prompt you paste straight into your AI builder's chat — tailored to whether you're on Supabase, Firebase, or something else — so fixing it takes one message, not a Stack Overflow rabbit hole.
Free scan, one paid tier. Your first scan is free. If you want unlimited re-scans, saved history, and an emailed report every time, that's $19/month. No enterprise sales call, no seat licenses.
What's explicitly not in V1 — on purpose
We left a few obvious things out of this release, deliberately:
- Ownership verification. Right now anyone can scan any public URL, the same way anyone can view page source. Authenticated scans behind an ownership check are next.
- Open-database / RLS probing. Checking whether your Supabase row-level security is actually configured correctly needs an ownership gate first — we're not going to probe your data without proof it's yours.
- Deploy-triggered, always-on monitoring. The whole pitch of ShipShield is that we watch your app, not just scan it once. That's coming — V1 proves the checks are worth running before we make them continuous.
Why start here
One-time scanners already exist. What doesn't exist — for people who aren't developers — is something that watches an app continuously, across every AI tool they might use, and explains findings in language that doesn't assume a CS degree. Public checks alone catch the scariest, most common issues, because they're sitting in the JS bundle every visitor already downloads. That's roughly 80% of the value for 20% of the build, and it's the fastest way to prove the bigger bet is worth making.
Try it now: paste your app's URL into the free scanner and see what your AI builder shipped without telling you.
Hardik Desai


