ShipCheck

Defensive pre-flight for Lovable, Bolt, and v0 apps

$19full report

Don’t ship this yet.

You built it in Lovable or Bolt. Stripe goes live this week. We check TLS, leaked secrets, open paths, CORS, cookies, payments on a preview host, and whether your public API describes itself — something response headers alone cannot tell you. Missing frame lock is a default to fix before checkout, not a catastrophe.

Public https only. We don’t store the page. We never show full secrets.

    Your report

    Hold

    DEV MODE. Polar not connected. Full report unlocked for screenshots.

    The part that is worth $19

    $19 once. Numbered findings in founder language, and the exact prompt to paste back into Lovable or Bolt.

    Unlock full report · $19

    Pre-flight list

    The eight checks

    The same eight every time. We fetch the URL you pasted and the same-origin scripts it loads. Existence checks only. No payloads.

    1. 01

      TLS / HTTPS

      Will browsers show Not secure, or is the live URL encrypted?

    2. 02

      Frame lock

      X-Frame-Options or CSP frame-ancestors. Fix this before checkout — a Lovable/Bolt default, not a leaked database.

    3. 03

      Secrets in the JS bundle

      Stripe secret keys, Supabase service_role, long JWTs. Anon keys are expected; we still flag them so you check RLS. Lovable does not turn that on for you.

    4. 04

      Open paths

      /.env, /debug, /health, /api/debug. Bolt will ship with /debug open. We only check that the path exists.

    5. 05

      CORS

      A wildcard origin plus credentials lets any website call your API as the signed-in user.

    6. 06

      Cookies

      Secure, HttpOnly, SameSite. Missing Secure on HTTPS is a launch-killer.

    7. 07

      Stripe on a preview domain

      Stripe.js on lovable.app, bolt.host, or vercel.app. Preview URLs get deleted, stolen, or indexed.

    8. 08

      Public API listing

      If the page embeds a Supabase URL and anon key, we ask the REST root whether it describes itself. Headers alone cannot do this.

    Price

    Free tells you to stop. $19 tells you what to paste.

    $19 once. You get the findings in founder language and the exact prompt to paste back into Lovable or Bolt.

    Free with every scan

    • TLS on or off
    • Which of the four core headers exist
    • Stack fingerprint
    • Launch-killer, warn, and OK counts

    Enough to know if you should hold the launch.

    Example · public Lovable app

    What the report looks like

    Real scan of dm-decoder.lovable.app on 17 Aug 2026. Not your URL. Numbers are not invented.

    Example report · 17 Aug 2026

    Caution

    No leaked keys. A few defaults to fix before checkout.

    TLS

    HTTPS on

    https://dm-decoder.lovable.app/

    Headers

    2 of 4 core headers

    CSP · HSTS · frame · nosniff

    Stack

    Lovable · Cloudflare

    Fingerprint only

    Issues

    3 warnings

    0 launch-killer · 5 ok

    #02 Warn

    This page can be embedded in another website

    Fix this before you take payments. This is a Lovable default, not a leaked database.

    #05 Warn

    Public keys are in the frontend (usually OK)

    The anon/publishable key is meant to be public. Double-check these are not secret keys. We never display full values.

    #06 Warn

    A debug URL is publicly reachable

    /debug answered 200. On this app that is likely the same HTML page, not a dumped console.

    OK #01 TLS · #03 cookies · #04 CORS · #07 no Stripe.js on this preview · #08 stack fingerprint

    The $19 report adds the exact prompt to paste back.

    No GitHub. No account. URL only.

    For

    Founders who ship from the chat UI and never open GitHub. Launching in the next 48 hours. Already paying Lovable or Bolt Pro.

    Not for

    A pentest. A scanner you point at other people’s apps. Anyone who wants a GitHub login and a dashboard.