One free check per repository. Then $1.99.
The free check flags open Supabase RLS, leaked keys and exploited packages. A paid check adds AI Review: it tells you which findings are real and writes a fix prompt that says what to change, what to leave alone, and how to check it worked. Pro keeps watching: up to 5 GitHub repositories scanned again every week, with an email only when a new High or Critical issue appears.
Scan freeWhat a paid check adds
Anyone signed in can read every user's data
supabase/migrations/0002_profiles.sql:12
The access rule on the profiles table allows any logged-in account to select any row. Someone signs up normally, opens the browser console, and reads every email address, phone number and Stripe customer id the app holds. No exploit needed: this is the database doing what it was told.
Blocks launch
Confirmed, not a false positive
Confirmed against the migration that created the policy: USING (true) matches every row, so any authenticated user can select any other user's profile.
- Change
- In supabase/migrations/0002_profiles.sql, drop the permissive select policy on profiles and create one restricted to the owner (auth.uid() = user_id).
- Keep
- Leave the insert and update policies alone; do not disable RLS on the table to make anything pass.
- Check
- Sign in as a second user and assert they cannot select the first user's row.
What Pro adds
- Your next prompt
- Adds a package, a migration, a route. The next weekly scan reads all of it.
- Packages you already ship
- A flaw found in one after you scanned shows up in the next weekly scan, with nothing changed on your side.
Nothing new, no email. Monitoring scans come on top of your 20 checks a month.
- Week 1 First scan done
- Week 2 No new High or Critical
- Week 3 No new High or Critical
- Week 4 1 new High or Critical, emailed
1 new High issue in example/demo-shop
The latest scan of example/demo-shop found issues we have not seen in it before.
- Vulnerable dependency
- 1
Prices
Pay as you go
Pro, billed monthly
Pro
$29.99/mo
Keeps watching up to 5 repos
Get Pro
- Every paid check includes AI Review. Prices are in USD.
- Buying asks you to sign in first, then goes straight to checkout.
- Repositories are unlimited on every plan.
- Monitoring scans don't count against Pro's monthly checks. A private repository needs a read-only GitHub token.
- Bought checks never expire. Pro's monthly checks lapse at renewal. Cancel Pro any time.
- Unused checks from a one-off pack are refundable within 14 days. Refund terms
What every check looks at
The same scanners on every plan, free or paid.
- Secrets
- 214 credential formats from 122 providers, plus private keys and JSON Web Tokens. Git history too.
- Dependencies
- Known vulnerabilities in 13 ecosystems. Development dependencies are skipped.
- Code
- 83 rules for mistakes that work fine until someone looks, plus 344 general rules at Low.
- Configuration
- Dockerfile, Kubernetes, Terraform, and 27 mobile checks.
Coming soon
Team
For a repository past what an individual plan fully scans: no file-count limit on code scans, secret scans across full git history, and seats and roles for a team.
Human review
Thirty minutes with an engineer, for the architectural finding no prompt can close.