Scan free

What a Security Check covers

The same checks on every plan, free or paid. 83 of the rules were written for mistakes that work fine until someone looks. Pick your stack to see what they catch in your app, and what they miss.

Secrets
214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
Dependencies
Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
Code
83 rules for mistakes that work fine until someone looks, plus 344 general rules at Low.
Configuration
Dockerfile, Kubernetes, Terraform, and 27 mobile checks.

New: AI and payment checks

We now flag the mistakes AI-built apps make when they connect to an LLM or to Stripe: AI output that runs as code, reaches your database or lands in your page as HTML, API keys shipped to the browser, Stripe webhooks anyone can fake, and checkouts where the buyer sets their own price. 26 new checks in JavaScript, TypeScript and Python.

AI integration
  • AI output run as code or a command Critical
  • AI output run as SQL Critical
  • LangChain allowed to run code on your server Critical
  • AI output shown as HTML High
  • An AI API key in the browser High
  • LangChain allowed to call any address High
  • AI choosing the URL or file your server uses Moderate

OpenAI, Anthropic, Vercel AI SDK, Google GenAI, LiteLLM and LangChain, plus tool and MCP-server handlers.

Stripe payments
  • A webhook anyone can fake Critical
  • A failed signature check that is ignored Critical
  • The signature check skipped when the secret is missing High
  • The buyer setting their own price High

Express, Next.js route handlers, Fastify, Flask, FastAPI and Django.

Login and API security
  • Login tokens signed with a secret written in the code High
  • Login token signature check turned off High
  • Flask session key written in the code High
  • Whole project folder served to the web High
  • Any website able to use your users' logins Moderate

JavaScript, TypeScript and Python.

Improved

Secret keys in public env vars: Vite variables are checked too. Keys that are public by design, such as Firebase web keys, Stripe publishable keys and Supabase anon keys, are no longer reported by this check, and each leaked key is one finding, not two.

What these don't check

  • Data is followed within one file. AI output that passes through your own helper in another file is not followed.
  • AI providers other than the ones above, or raw HTTP calls to an AI API.
  • Payment providers other than Stripe.
  • A Stripe signature check in shared middleware or a guard in another file. That handler may be flagged even though it is protected.
  • Whether an AI endpoint has a login or a rate limit.

What it covers for your app

Pick what you built with.

Secrets

Covered: Stripe, OpenAI, Anthropic, AWS and GitHub keys, in your files and git history

Covered: A Supabase service-role key, found as a JSON Web Token

Not covered: A Postgres DATABASE_URL connection string

Dependencies

Covered: package-lock.json, yarn.lock, pnpm-lock.yaml and bun.lock

Not covered: bun.lockb, the binary lockfile (commit the text bun.lock)

Not covered: devDependencies, skipped on purpose

Code

Covered: Supabase row-level security: open policies, RLS switched off, policies trusting user_metadata

Covered: Admin checks only in "use client" components, swapped IDs, server actions with no auth check

Covered: Server secrets in NEXT_PUBLIC_ variables

Covered: AI output run as code or SQL, or shown as HTML, and AI keys shipped to the browser

Covered: Stripe webhooks anyone can fake, and checkouts where the buyer sets the price

Configuration

Covered: Your Dockerfile, if you have one

Not covered: Vercel project settings

Where it stops

Secrets

  • Database connection strings: MongoDB, Postgres, Redis, AMQP.
  • Providers without their own rule, such as Postmark, PayPal, Vercel, Segment and Docker Hub. Only a key-named, random-looking value is flagged.

Dependencies

  • Development and test dependencies.
  • bun.lockb, and go.sum without go.mod.
  • Unpinned ranges in requirements.txt, and Maven versions set by a parent or BOM.
  • CocoaPods beyond the 8 pods on our own list.

Code and configuration

  • Ruby, Rust, Elixir, PHP and Objective-C code.
  • Docker Compose files. Helm, CloudFormation and ARM templates are not claimed.

Everything else

  • Your running app. Nothing is built, installed or run.
  • On an individual plan, a repository over 500 MB or 20,000 files: no git history for secrets, and code rules read the first 20,000 files. The report says so.

A clean report means these checks found nothing blocking on that commit. It is a good sign and never a guarantee.

Try it on your own code.

Scan free

One free check per repository. No card. Compare plans

Tuvio: an audit for the app you did not entirely write.

© 2026 CodexMotive Digital Solutions. Tuvio is a product of CodexMotive. Scanning reads your files; it never runs them.