We review apps built with Lovable, Bolt, Cursor, Replit and Claude Code for the problems AI builders leave behind — open databases, leaked keys, fake payments — and give you the exact prompt to fix each one.
$750, fixed. Re-check included. No actionable findings, full refund.
AI builders ship fast. They also ship the same holes.
170+
of 1,645 Lovable apps scanned in February 2026 had databases anyone could read (VibeEval).
Tables without row-level securityThe public key in your site reads every row.
Secret keys in the browserStripe or AI keys bundled into JavaScript.
Webhooks that trust anyoneA fake "payment completed" marks orders paid.
Open AI and email endpointsStrangers run up your bill or send mail as you.
Admin checks in the browserOne console command opens the admin page.
Every finding comes with proof and a fix you can paste
This is a real excerpt from the sample report. Each finding leads with the consequence, cites the exact file and line, and ends with a prompt you paste into the tool you built with.
CRITICALDA-1
Anyone can read and change every booking
What can happen
Anyone who opens the website can copy its public database key and list every booking — home addresses and notes such as where the key is hidden.
Row-level security is never enabled for this table.
Fix prompt
Create a new Supabase migration that enables row level security on public.bookings and adds policies: customers can select and insert only rows where customer_id = auth.uid(); an assigned walker can select rows where walker_id = auth.uid(); no one can update price_cents or status or delete bookings from the client. Never use using (true) on this table.
Share your codeInvite us to the repository or send a zip. We only read it, and nothing runs against your live app.
We run 36 checks across 9 areasData access, secrets, payments, sign-in, abuse and cost, input handling, privacy, LLM features and production basics.
Get your report in 72 hoursEvery finding verified against your code, ranked, and paired with a fix prompt.
Fix, then we re-checkSend the new commit within 14 days and we re-run the affected checks at no charge.
One price, one deliverable
No retainers and no hourly billing. You get a verdict you can act on, the evidence behind it, and the prompts to fix it with the tools you already use.
Pilot pricing: our first five reviews are $390 in exchange for a short testimonial.
No. We review your code and configuration and verify each finding against the code; we never attack your live app. That makes the review fast and safe, and it catches the problems AI builders actually leave behind. If you process payments or health data at scale, plan a penetration test as well.
What access do you need?
Read access to the repository (GitHub, GitLab or a zip), plus an export of your database schema and policies if they live only in the Supabase or Firebase dashboard. Never production passwords.
What happens to my code?
We use it only for your review, process it with Anthropic's Claude with model training turned off, and delete our copy 14 days after delivery. We are happy to sign your NDA first.
Which tools and stacks do you cover?
Apps built with Lovable, Bolt, Cursor, Replit, v0 and Claude Code — typically React or Next.js with Supabase or Firebase, Stripe, and an LLM API.
Who does the review?
The review runs with AI tooling (Anthropic's Claude) against a fixed 36-check method. Every finding is then verified again against your code in a separate pass, and a person reads every report before it reaches you. You get evidence for each finding, not guesses.
What if you find nothing?
If the report has no actionable finding, you get a full refund.
Book a review
Email us your app's name, what it is built with, and when you plan to launch. We reply within one business day with a start date and a payment link.