It works ≠ it's safe to ship

Your vibe-coded app is leaking data right now.

Paste your URL. We fingerprint your stack and show you exactly what a stranger can read — in 30 seconds.

Free score · Fix Pack $29 · we never store your data
Free scan
SAFETY
38
F
LEAKRANKDATA EXPOSED
Supabase detected
users table readable
orders writable
HTTPS + headers
3 tables open · 1.2k rows
scan yours → leakrank.com
1,284 apps scanned · 44% leaking data · live
One scanner · works with
SupabaseFirebaseConvexClerkCustom API

What you get

The scan is free and shows you the damage. The $29 Fix Pack tells you exactly how to fix it, and covers your first month of LeakRank Guard, which installs into your AI coding agent and keeps watching for the bugs a URL can't see.

The scanfree
$0
0–100 score + grade
Problem areas, named
Proof of one live leak
Exact tables / files / lines
Agent fix-prompt
Fix PackBest value
$29 once
Exact table, file + line per issue
Copy-paste fix prompt for your agent
PDF + verified badge
Free re-scan (1/day) to verify the fix
First month of Guard free ($19 value)
Get the Fix Pack, $29
Guard is optional: upgrade within 30 days and your $29 is credited.
30-day money-back guarantee
GuardSubscription
$19/mo
or $180/yr · 2 months free
Installs into your AI coding agent
Scans every change for leaked secrets
Catches leaks before they ship
Agent gets the exact fix, not just a flag
Get LeakRank Guard →
Free first month with a Fix Pack from the last 30 days

What the report actually looks like

Every finding, located and fixed, plus a badge you can show once it is clean.

fix-report · 9 findings, each locatedEXAMPLE
CRITICALSupabase RLS disabled on public.users
where public.users · 1,284 rows readable with the anon key right now
fix   enable RLS; add a policy: auth.uid() = user_id
CRITICALorders table writable by anyone
where public.orders · insert and delete both accepted
fix   add insert/update/delete policies scoped to the owner
HIGHservice_role key in client bundle
where /_next/static/chunks/main.js · line 4,102
fix   move it to a server env var, then rotate the leaked key
+ 6 more, each with its exact location and fix, plus a copy-paste prompt for Cursor or Claude Code.
INCLUDED

Your first month of Guard

The $29 you pay for the Fix Pack is credited toward LeakRank Guard: upgrade within 30 days and the first month costs $0 instead of $19, or take $29 off the annual plan. Optional, and it cancels any time.

What Guard does →
KEEP IT

A badge you can prove

Put it on your site or in a deck. It links to a page that reads the score from our records, so the number holds up when someone checks it.

How the badge works →
Scan my app free →free score · no signup · about 30 seconds

What we scan

Four checks from your URL alone — then Guard reads your code for the leaks a URL scanner physically can't see.

New to any of these? Read what row level security is or how Firebase security rules work, or browse all the security guides.

01
Database exposure
RLS / security rules off — tables a stranger can read or write with your public key.
02
Leaked secrets / keys
API keys, service-role tokens and .env values sitting in your client bundle.
03
Auth & endpoints
Admin routes and APIs that answer without a session, plus missing security headers.
04
Deploy hygiene
Source maps, debug routes and stack traces left switched on in production.
05 · GUARD
Continuous, in your agent
Installs into Claude Code, Cursor, Codex, or Windsurf and scans every change — the secrets and config risks that never show up from a URL.
0–100

Find out before a stranger does.

Free score in 30 seconds · no signup · we never store your data.

Get my free scan →