DevMeth

The pre-flight check for AI-built apps

Your AI says your app is secure. It says that every time.

DevMeth is the pre-flight check for AI-built apps: it scans your code and live URL for the 48 known AI-code failure patterns, explains each in plain English, and gives you a paste-ready fix prompt. Re-scan until it's green.

60 checks total — 48 security + 12 code-health (Rescue Report).

checks the 48 known AI-code failure patternsnot a penetration test or a security guarantee. Results in about 2 minutes, free.

Free scan runs 10 Critical checks, no signup. Your code is deleted after the scan by default — see how we handle your code.

How it works

01

Point it at your app

Paste a repo URL, upload a zip, or give us your live URL. No signup for the free scan.

02

We run 48 read-only checks

Across both the code and your live surface: secrets, exposed data, auth, input handling, dependencies, and your public web.

03

Plain-English findings + fix prompts

Each finding explains what's wrong, why AI tools cause it, and includes a paste-ready fix prompt for your AI tool.

04

Re-scan until it's green

Fix with one paste, re-scan to verify, and earn the verified badge when every known pattern is clear.

What a finding looks like

No CVE jargon — just what went wrong and the fix your AI tool can apply.

Sample report — what you'll get

Interactive sample

C1API keys and passwords are hardcoded in your source code

Critical

What we found

src/lib/keys.tssk-…a1b2 (OpenAI key, masked)

C6Your Supabase database is readable by anyone on the internet

Critical

What we found

table users1,204 rows readable anonymously · sample row masked

Sample — illustrative and masked exactly as a real report shows it. Run a free scan to see your own findings.

What we check — 48 security checks

See all →

Pricing

One-time, no subscription. 30-day refunds.

$0

Free Scan

  • 10 Critical checks, no signup
  • Count-only preview of the rest
  • Results in ~2 minutes
Start free scan
$59

Full Report

one-time

  • All 48 checks, full finding cards
  • Evidence + paste-ready fix prompts
  • 1 free re-scan
Starts with a free scan
$179

Launch Pack

one-time · most popular

  • Everything in Full Report
  • Rescue Report (AI tech-debt scan)
  • Unlimited re-scans until green
  • Verified badge

Already scanned? The Rescue Report ($59) works on any scan: dead code, copy-pasted blocks, hallucinated imports, untested routes — the AI tech-debt scan with a Debt Score.

Shipping from GitHub? The DevMeth GitHub App adds a check to every pull request — free on public repos, $19.99/mo per private repository. Install the GitHub App →

Your code, handled carefully

FAQ

What tools does it work with?

Any code can be scanned — Lovable, Cursor, Claude Code, Bolt, plain Next.js, plain Vite. Fix prompts are universal and work in Claude Code, Codex, Cursor, Copilot, and API models like DeepSeek or GLM.

What stacks does it check?

The core coverage targets supabase, firebase, prisma, nextjs, vite, cra, remix, and sveltekit, with anything-scan checks (secrets, deps, auth, input) for every project.

Is this a penetration test?

No. DevMeth checks the 48 known AI-code failure patterns —not a penetration test or a security guarantee. It's a pre-flight check of common AI-code failure patterns, not an adversarial security assessment.

I'm on Lovable and don't have a repo. Can I still check?

Yes. A live scan (your deployed URL) checks your public surface, including Supabase RLS and Firebase rules, without needing the repo. You just confirm by email.

Do I need an account?

No. The free scan needs no email. Paid reports are one-time purchases — we use your email for the report link and receipt, nothing else.

What happens to my code?

Scanned code is deleted after the scan by default. For re-scans (Launch Pack) you can opt into retention, which is encrypted and auto-purged after 30 days. Delete at any time from your report.

Can you read my secrets?

DevMeth never stores full secrets. Findings show only masked samples (prefix + last 4 characters). We never keep raw credentials, response bodies, or raw IPs.

How accurate are the findings?

A check only ships if it is always a real finding, and our precision harness enforces zero false positives on a clean fixture corpus. The machine decides what is a finding — the LLM only explains it.

What do I get with a paid report?

Full Report ($59): all 48 security checks with full cards, evidence, and fix prompts, plus 1 free re-scan. Launch Pack ($179): everything plus the Rescue Report (the AI tech-debt scan), unlimited re-scans until green, and the verified badge. Rescue Report ($59) is also available on its own.

What is the verified badge?

A public badge you can embed showing your app passed all known checks on a date and catalog version. It represents "all 48 patterns checked and clear", not a security guarantee.

What's the refund policy?

30 days, no questions. Email us and we'll refund a paid report in full.

Do you scan third-party apps I don't own?

No. You may only scan apps you own or are authorized to scan. Our acceptable-use policy and live-scan controls enforce authorization.