decivo Scan
Your app works. What's beneath the surface?
Discover what an outside look reveals about your app — from security and privacy to technical issues worth investigating.
Your app's URL
Free · No sign-up · Results in your browser
Built with Lovable, Bolt, v0, Cursor or other tools? Take a closer look.
View sample results
Sample finding
No Content Security Policy is set
Injected third-party code can run unchecked in your users' browsers. The protection layer that prevents exactly this is missing.
Here's what you get.
Example using demo data
MediumSecurityRSC-SEC-003
No Content-Security-Policy
Injected third-party code can run unchecked in your users' browsers. The protection layer that prevents exactly this is missing.
HighLaw & privacyRSC-PRV-008
Tracking cookies set before consent
Your visitors' data leaves the site before they have consented. This is the most common cause of complaints and legal notices.
MediumAccessibilityRSC-ACC-003
Form fields without labels
Anyone ordering with a screen reader doesn't learn what these fields require. The core flow is not usable for these users.
Breakdown
- 5 × High — checks with a finding
- 8 × Medium — checks with a finding
- 3 × Low — checks with a finding
- 79 checked, no finding
- 38 need access
What we check.
Security
What does someone see who isn't logged in — and what can they do with it?
- Security headers
- Supabase & APIs
- Secrets in code
Privacy
Which services, trackers and third countries are in your app without you putting them there?
- GDPR Art. 13 · 44 ff.
- TDDDG § 25
- DDG § 5
- AI Act Art. 50
Accessibility
Can everyone use your app — and since the BFSG, do you have to prove it?
- BFSG · WCAG 2.2 AA
Architecture indicators
Can you tell from the outside whether the foundation holds — or whether the next feature breaks the one after?
- Soft 404
- Caching
- Rendering
Code indicators
Does the code show the typical patterns of AI-generated apps — duplicated logic, dead paths, missing error handling?
- Dependencies
- Build
- Patterns
We also show you what we can't see.
Our catalogue has 154 checks. From the outside — without access — up to 95 of them run. The rest is still in your report: as "needs access", not as "passed". We don't guess.
What we can prove from the outside
95 of 133 checks run without any access to your system.
How it's built — that needs access
With read-only repository access, 95 checks become 118 of 133. Free.
1. Public
From the outside, no access needed.
2. Domain ownership
You confirm via DNS record that the app is yours — we show the evidence we can't show without proof.
3. Repository
Read-only GitHub access. Now we see architecture, dependencies, implementation.
All three free.
The scan is free. If you'd like support interpreting or implementing the findings, you can arrange that separately. More
Then you don't get a red light. You get a plan.
- What we found — with evidence
- Why it matters, and for whom
- How urgent
- What to do
If you don't want to do it yourself: Vibe Code Rescue
We take over the critical parts, stabilise the app and bring it to a state you can safely build on. Scoping is credited.
See RescueQuestions
What you want to know first
Am I allowed to do this?
Only your own apps. The outside scan performs passive checks only — the same requests any browser makes on every visit. No attacks, no load.
What happens to my URL and the result?
The result is yours and lives in your browser — we don't file it under your name. We only keep what you trigger yourself: a shared permalink, an anonymous aggregate for our statistics (host as a hash, never the address) or a repository scan, whose data is deleted after 90 days.
What can't you see?
Everything behind the login and everything in the code — until you grant access. The report lists it as "needs access", not as "passed".
Do I have to buy anything afterwards?
No. Outside scan, domain ownership and repository scan are free. You only pay if you want a human to take a look.
How long does it take?
A few minutes. You watch the progress live.
My app isn't live yet or is password-protected.
Then go straight to the repository scan: read-only GitHub access, no deployment needed.
No repo. No call. A result in a few minutes.
We wanted to know how good AI-built apps really are. Now you can too.
What we found across hundreds of apps: the AI app radar