Skip to content

decivo Scan

Your app works. What's beneath the surface?

Discover what an outside look reveals about your app — from security and privacy to technical issues worth investigating.

Your app's URL

Free · No sign-up · Results in your browser

Built with Lovable, Bolt, v0, Cursor or other tools? Take a closer look.

View sample results
App interface with the technical layers behind it: code, servers, database — illustration

Sample finding

No Content Security Policy is set

Injected third-party code can run unchecked in your users' browsers. The protection layer that prevents exactly this is missing.

Here's what you get.

Example using demo data

  1. MediumSecurityRSC-SEC-003

    No Content-Security-Policy

    Injected third-party code can run unchecked in your users' browsers. The protection layer that prevents exactly this is missing.

  2. HighLaw & privacyRSC-PRV-008

    Tracking cookies set before consent

    Your visitors' data leaves the site before they have consented. This is the most common cause of complaints and legal notices.

  3. MediumAccessibilityRSC-ACC-003

    Form fields without labels

    Anyone ordering with a screen reader doesn't learn what these fields require. The core flow is not usable for these users.

See every check in the catalogue
5 × High — checks with a finding8 × Medium — checks with a finding3 × Low — checks with a finding79 checked, no finding38 need access
Iterate16 of 95 run checks flagged
Breakdown
  • 5 × High — checks with a finding
  • 8 × Medium — checks with a finding
  • 3 × Low — checks with a finding
  • 79 checked, no finding
  • 38 need access

What we check.

Security

What does someone see who isn't logged in — and what can they do with it?

  • Security headers
  • Supabase & APIs
  • Secrets in code

Privacy

Which services, trackers and third countries are in your app without you putting them there?

  • GDPR Art. 13 · 44 ff.
  • TDDDG § 25
  • DDG § 5
  • AI Act Art. 50

Accessibility

Can everyone use your app — and since the BFSG, do you have to prove it?

  • BFSG · WCAG 2.2 AA

Architecture indicators

Can you tell from the outside whether the foundation holds — or whether the next feature breaks the one after?

  • Soft 404
  • Caching
  • Rendering

Code indicators

Does the code show the typical patterns of AI-generated apps — duplicated logic, dead paths, missing error handling?

  • Dependencies
  • Build
  • Patterns

We also show you what we can't see.

Our catalogue has 154 checks. From the outside — without access — up to 95 of them run. The rest is still in your report: as "needs access", not as "passed". We don't guess.

What we can prove from the outside

95 of 133 checks run without any access to your system.

How it's built — that needs access

With read-only repository access, 95 checks become 118 of 133. Free.

  1. 1. Public

    From the outside, no access needed.

  2. 2. Domain ownership

    You confirm via DNS record that the app is yours — we show the evidence we can't show without proof.

  3. 3. Repository

    Read-only GitHub access. Now we see architecture, dependencies, implementation.

All three free.

The scan is free. If you'd like support interpreting or implementing the findings, you can arrange that separately. More

Then you don't get a red light. You get a plan.

  • What we found — with evidence
  • Why it matters, and for whom
  • How urgent
  • What to do

If you don't want to do it yourself: Vibe Code Rescue

We take over the critical parts, stabilise the app and bring it to a state you can safely build on. Scoping is credited.

See Rescue

Questions

What you want to know first

Am I allowed to do this?

Only your own apps. The outside scan performs passive checks only — the same requests any browser makes on every visit. No attacks, no load.

What happens to my URL and the result?

The result is yours and lives in your browser — we don't file it under your name. We only keep what you trigger yourself: a shared permalink, an anonymous aggregate for our statistics (host as a hash, never the address) or a repository scan, whose data is deleted after 90 days.

What can't you see?

Everything behind the login and everything in the code — until you grant access. The report lists it as "needs access", not as "passed".

Do I have to buy anything afterwards?

No. Outside scan, domain ownership and repository scan are free. You only pay if you want a human to take a look.

How long does it take?

A few minutes. You watch the progress live.

My app isn't live yet or is password-protected.

Then go straight to the repository scan: read-only GitHub access, no deployment needed.

No repo. No call. A result in a few minutes.

We wanted to know how good AI-built apps really are. Now you can too.

What we found across hundreds of apps: the AI app radar