Sample: fictional app, not a real client. Example Bookings and bookings.example.com are made up, and every key shown is fake.

Sample report

A free check report for Example Bookings (fictional)

This is what the free check sends back once Aaron has reviewed it, in the same layout and the same words as a real report. Real reports are private: each is at its own unguessable link, and never indexed.

Download PDF PDF, 5 pages, 526 KB

How to read it

  • Most important first. Aaron puts what matters most to the business at the top, and the rest follow by severity. Each finding says what is wrong, what it means for you in one line, and the fix.
  • "Reviewed by Aaron". The scanner's results arrive within minutes, labelled "Automated results". Within two business days Aaron removes false positives, adds what the scanner cannot see, and the page updates at the same link.
  • Public surface only. Everything here comes from what the app serves to any visitor. The free check never reads private code; reviewing the code is the audit.

Sample · fictional app

bookings.example.com

Reviewed by Aaron Free check 6 October 2026 Version 2

Summary

Two things need fixing this week: a live Stripe secret key in the JavaScript every visitor downloads, and public source maps that hand out the app's original code. The rest fits into a normal sprint. One automated finding was removed in review: the Google Maps key in the bundle is restricted to this domain, as it should be.

Findings

  1. Critical Live Stripe secret key in the shipped JavaScript
    Business impact · Security exposure
    Anyone who opens the booking page can use this key to issue refunds, create charges or read your customers' payment records.
    Recommended fix
    Roll the key in the Stripe dashboard today, then move the deposit and refund calls into server-side code so the key never reaches the browser.
    Effort
    Hours
    Evidence
    • /assets/index-3e7a19c0.js: sk_live_…FAKE (107 chars)
  2. High JavaScript sourcemaps are public
    Business impact · Security exposure
    The app's original source, including the staff screens and the deposit logic, can be downloaded and read by anyone, which makes the app cheaper to copy and to attack.
    Recommended fix
    Turn off production sourcemaps in the build (Vite: build.sourcemap false), or upload them to the error tracker only, then redeploy.
    Effort
    Hours
    Evidence
    • /assets/index-3e7a19c0.js.map: served: 200, application/json, 3,412,880 bytes; source map shape
  3. Medium Customer email addresses in confirmation page URLs
    Business impact · Security exposure
    The booking confirmation puts the customer's email address in the page address, where analytics tools and any site the page links to can record it.
    Recommended fix
    Use the booking ID alone in the confirmation URL and look the email up on the server, then send Referrer-Policy: strict-origin-when-cross-origin.
    Effort
    Hours
    Evidence
    • /assets/index-3e7a19c0.js: the confirmation route builds /booking/confirmed?email=…
  4. Medium Error pages show a stack trace
    Business impact · Security exposure
    A mistyped address shows file paths, library versions and internal structure, which shortens the work of anyone probing the app.
    Recommended fix
    Turn off debug error pages in production and log the details server-side instead.
    Effort
    Hours
    Evidence
    • /.git/HEAD: not served, but the 500 error page carries a stack trace with file paths
  5. Medium No Strict-Transport-Security header
    Business impact · Fundraising and enterprise sales
    Enterprise security questionnaires ask for HSTS, so its absence is an easy point to lose in a vendor review, and a first visit over plain http can be intercepted.
    Recommended fix
    Add Strict-Transport-Security: max-age=31536000; includeSubDomains in the hosting platform's headers configuration.
    Effort
    Hours
    Evidence
    • https://bookings.example.com/: header absent on the root response
  6. Low 1.9 MB of JavaScript before the first screen
    Business impact · Revenue
    On a mid-range phone the booking page takes several seconds to appear, which costs bookings from paid traffic.
    Recommended fix
    Split the staff screens and the calendar library into lazily loaded routes so the booking page ships only what it draws.
    Effort
    Days
    Evidence
    • /: 5 scripts, 1,992,431 bytes decoded
  7. Low X-Powered-By header names the framework
    Business impact · Fundraising and enterprise sales
    The header tells anyone which framework runs the app, which shortens the search for a known weakness.
    Recommended fix
    Remove the X-Powered-By header (in Express: app.disable('x-powered-by')).
    Effort
    Hours
    Evidence
    • https://bookings.example.com/: X-Powered-By: Express

Not assessed

  • Data access: Data-access probes are not enabled

Versions

  • Version 2: Reviewed by Aaron, 6 October 2026 (shown)
  • Version 1: Automated results, 5 October 2026 · superseded

A professional review of the stated scope at the stated time. Not a security guarantee, penetration test or certification.

See your own app's report.

The free check costs nothing and commits you to nothing. It runs once you confirm your email and show the app is yours. To see what the paid audit found in the same app two weeks later, read the sample audit.