ShipCheck
Free security scanner
Built for Lovable, Bolt, Replit, v0, and Cursor apps

Find security issues before your users do

ShipCheck scans your app for leaked API keys, exposed database endpoints, and missing security headers — no signup required.

https://

Leaked API keys

Detects exposed keys for OpenAI, Stripe, AWS, and other common services in responses and scripts.

Database exposure

Probes common endpoints and error pages that might reveal database configuration or tooling.

Missing security headers

Checks for HSTS, CSP, X-Frame-Options, and other headers that protect your users.