Free instant check · outside-in

Scan your AI-built site for the mistakes visitors can already see.

Paste a URL. We fetch the live public page and its scripts and report the AI-build problems that show from the outside - exposed keys, config leaks, dead buttons, template leftovers, and more - with a plain-English grade in seconds.

Read-only. We request your public page, its same-origin scripts, and a few standard paths (like /.env) to see if they are exposed. No intrusive exploitation, no login attempts, nothing changed on your site.
Scanning your site ...
  • Fetching the public page
  • Reading same-origin scripts
  • Probing for exposed config files
  • Checking references, headers, and markup
  • Compiling the report
Still working - this site is taking a little longer to answer.
!

We could not reach this site.

Check the address is spelled correctly and the site is publicly reachable. Private, local, and password-walled sites cannot be examined from the outside.

0 / 100
Outside-in report

Here is what your site shows.

Clean sweep. Nothing is leaking from the outside.
Sample report. The live scanner is not connected on this page yet, so this is an illustrative result showing the format. Once the scan function is deployed, this fills with a real check of your URL.
Most severe findings

Get the full report

We found more additional finding(s) plus the fix for each. Enter your email and we will send the complete outside-in report.

No spam. The report, and the free CLI that catches these in your code.
Thanks - the remaining findings are unlocked below, and the full report is on its way.

These are the symptoms visible from outside. The CLI catches the same failure classes in your code before you deploy - swallowed errors, dead references, invented columns, and the rest - and it is free.

$ npm install -g forgevalidators
See what the CLI catches