Free check

See what your app shows the world.

An automated check of your app's public surface, then a review by Aaron. It runs by itself once you confirm your email and show that the app is yours, it never reads private code, and it costs nothing.

Request a check

The address your users open. A platform address is fine.
One email goes here, asking you to confirm. Nothing runs until you do.

This form needs JavaScript to send. Turn it on and reload, or email aaron@anyfront.co with your app URL.

What is checked

Four things, all on your app's public surface: what it already serves to any visitor. The free check never reads or scans private code, and it does not need access to your repositories. Reviewing your code is the audit.

  • Exposed keys and secrets. API keys, tokens and service credentials shipped in the JavaScript your app sends to every browser.
  • Headers, HTTPS and CORS. Security headers, the move from http to https, and which other sites are allowed to call your app.
  • Versions on show. Framework and dependency versions your app gives away, which tell an attacker where to start.
  • Performance and uptime. Core Web Vitals and what your error pages show when something goes wrong.

Database access rules, such as Supabase tables open to the public, and sign-up settings are not part of the free check yet. Until they are, the report lists them as "Not assessed". The audit covers both.

The check reads with the same kind of requests a browser makes, at a gentle pace, and only from your app and the database host its own code names. It does not sign in, submit forms or change anything. Where a check cannot be run safely from the outside, the report says "Not assessed" rather than guessing. It is a first look, not a security guarantee: a clean result does not mean there are no problems.

When it runs

Only after two things: you confirm the request from the email you are sent, and ownership of the app is verified. Until both are done, nothing about your app is requested at all.

Ownership can be shown in any one of these ways:

  • Your email address is on the app's domain, such as you@acme.com for app.acme.com. Free-mail addresses and shared platform domains, such as lovable.app or vercel.app, do not count, because anyone can have one.
  • A DNS TXT record at _anyfront-check. followed by your app's host, holding a value shown to you after you confirm.
  • A meta tag or a file: a tag in your app's home page, or a file at /.well-known/anyfront-check.txt. This works on lovable.app, vercel.app, replit.app and other platform addresses.
  • A read-only repository invite, which Aaron accepts and records. It is used only to show the app is yours: nothing in the repository is read or scanned for the free check.

The confirmation page shows the exact values to add, and checks for them when you are ready.

What you get

  • "Automated results" within minutes. The scan runs automatically as soon as ownership is verified, and an email brings a link to your own private report page. Each finding has a severity, its business impact in one line, and the fix to make. See a sample.
  • "Reviewed by Aaron" within two business days. False positives are removed, notes are added, the page is updated, and you get a second email.
  • A PDF when you want one. Print the report, or save it as a PDF, from the page.
  • A link to book a call about the audit, if the findings make you want one. There is no obligation.

What happens to your data

  • A request that is not confirmed, or whose ownership is not verified, is deleted after 7 days.
  • Your report is deleted after 90 days, unless you keep it: the "Keep this report" button on its page moves it into an Anyfront account for the email you confirmed. Raw scan data is deleted after 90 days either way.
  • The report page has no analytics or trackers, and it is never indexed.
  • Nothing about you or your app is published without your written consent.

The privacy policy has the detail, and the terms cover the check itself.