C1API keys and passwords are hardcoded in your source code
CriticalWhat we found
src/lib/keys.ts — sk-…a1b2 (OpenAI key, masked)
The pre-flight check for AI-built apps
DevMeth is the pre-flight check for AI-built apps: it scans your code and live URL for the 48 known AI-code failure patterns, explains each in plain English, and gives you a paste-ready fix prompt. Re-scan until it's green.
60 checks total — 48 security + 12 code-health (Rescue Report).
checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee. Results in about 2 minutes, free.
Free scan runs 10 Critical checks, no signup. Your code is deleted after the scan by default — see how we handle your code.
Paste a repo URL, upload a zip, or give us your live URL. No signup for the free scan.
Across both the code and your live surface: secrets, exposed data, auth, input handling, dependencies, and your public web.
Each finding explains what's wrong, why AI tools cause it, and includes a paste-ready fix prompt for your AI tool.
Fix with one paste, re-scan to verify, and earn the verified badge when every known pattern is clear.
No CVE jargon — just what went wrong and the fix your AI tool can apply.
What we found
src/lib/keys.ts — sk-…a1b2 (OpenAI key, masked)
What we found
table users — 1,204 rows readable anonymously · sample row masked
Sample — illustrative and masked exactly as a real report shows it. Run a free scan to see your own findings.
One-time, no subscription. 30-day refunds.
one-time
one-time · most popular
Already scanned? The Rescue Report ($59) works on any scan: dead code, copy-pasted blocks, hallucinated imports, untested routes — the AI tech-debt scan with a Debt Score.
Shipping from GitHub? The DevMeth GitHub App adds a check to every pull request — free on public repos, $19.99/mo per private repository. Install the GitHub App →
Any code can be scanned — Lovable, Cursor, Claude Code, Bolt, plain Next.js, plain Vite. Fix prompts are universal and work in Claude Code, Codex, Cursor, Copilot, and API models like DeepSeek or GLM.
The core coverage targets supabase, firebase, prisma, nextjs, vite, cra, remix, and sveltekit, with anything-scan checks (secrets, deps, auth, input) for every project.
No. DevMeth checks the 48 known AI-code failure patterns —not a penetration test or a security guarantee. It's a pre-flight check of common AI-code failure patterns, not an adversarial security assessment.
Yes. A live scan (your deployed URL) checks your public surface, including Supabase RLS and Firebase rules, without needing the repo. You just confirm by email.
No. The free scan needs no email. Paid reports are one-time purchases — we use your email for the report link and receipt, nothing else.
Scanned code is deleted after the scan by default. For re-scans (Launch Pack) you can opt into retention, which is encrypted and auto-purged after 30 days. Delete at any time from your report.
DevMeth never stores full secrets. Findings show only masked samples (prefix + last 4 characters). We never keep raw credentials, response bodies, or raw IPs.
A check only ships if it is always a real finding, and our precision harness enforces zero false positives on a clean fixture corpus. The machine decides what is a finding — the LLM only explains it.
Full Report ($59): all 48 security checks with full cards, evidence, and fix prompts, plus 1 free re-scan. Launch Pack ($179): everything plus the Rescue Report (the AI tech-debt scan), unlimited re-scans until green, and the verified badge. Rescue Report ($59) is also available on its own.
A public badge you can embed showing your app passed all known checks on a date and catalog version. It represents "all 48 patterns checked and clear", not a security guarantee.
30 days, no questions. Email us and we'll refund a paid report in full.
No. You may only scan apps you own or are authorized to scan. Our acceptable-use policy and live-scan controls enforce authorization.