YoushippeditwithAI.Now see what it leaked.
Paste your URL. In minutes you get every missing header, open path, and leaked key name ranked from low to critical, each with a fix prompt your AI can run.
- No account to start
- Passive, read-only crawl
- Results in minutes
- leaked API keys in JS
- security headers & HTTPS
- .env, .git & backups
- Supabase / Firebase rules
- cookies & CORS
- vulnerable libraries
Findings
0 found · 0 locked
- Passive checks on every scan
- 40+
- Free scan, no card
- 1
- Lowest price per full scan
- $1.99
- Expiry on credits. Ever.
- 0
How it works
AI wrote the code. Nobody read the headers.
FixPrompt does the boring security pass your agent skipped, in about the time it takes to refill your coffee.
Paste your URL
Any public http(s) app. Localhost, private IPs, and cloud metadata endpoints are blocked.
We look, we don't touch
A real browser loads your pages and JavaScript bundles, reads headers, cookies, and public paths. One normal request each. No payloads.
Hand the fix to your AI
Copy one prompt into Claude Code, Codex, Cursor, or any LLM. It fixes every issue in priority order and tells you how to verify.
The report
The scary stuff is behind the lock.
Your free scan shows how many medium, high, and critical issues exist and what they're called. Unlock to get the evidence and the exact fix.
- Low findings open free after signup
- Medium → critical unlock for $9 per report, or use a credit for a full scan
- One prompt fixes everything — paste it into any AI coding agent
Missing X-Content-Type-Options
Add X-Content-Type-Options: nosniff at the edge or in middleware to stop MIME sniffing.
› Fix prompt: add nosniff to every response in middleware.ts…
Client bundle references a privileged key name
Content-Security-Policy not set
Compare
Cheaper than a pentest. Faster than a checklist.
Where FixPrompt fits next to the other ways to answer “is my app leaking?”
Price
Time to a report
Knows AI-built stacks
Supabase / Firebase hosts, key names in client bundles
Fix prompt per finding
One prompt for Claude Code, Codex, Cursor, or any LLM
Ranked low → critical
Passive, no exploit payloads
No subscription
Deep manual logic testing
We're honest: for that, hire a human
Pricing
Pay per scan. Keep the credits forever.
Your first scan is free. After that, packs make each full, unlocked scan cheaper than a coffee.
Tip: scan once, fix, then scan again to prove it's gone.
Best fit · Builder
$3.27per full scan
64% less than a $9 report unlock
Starter
$20
5 full scans · $4.00/scan
One app, scan before and after fixing
- Every severity unlocked, low → critical
- AI fix prompt per finding + one fix-everything prompt
- Re-scan after fixing to verify
- Credits never expire
Builder
Save 18%$49
15 full scans · $3.27/scan
Scan every deploy of a couple of apps
- Every severity unlocked, low → critical
- AI fix prompt per finding + one fix-everything prompt
- Re-scan after fixing to verify
- Credits never expire
Studio
Save 38%$99
40 full scans · $2.48/scan
Agencies and side-project collectors
- Every severity unlocked, low → critical
- AI fix prompt per finding + one fix-everything prompt
- Re-scan after fixing to verify
- Credits never expire
Fleet
Save 50%$199
100 full scans · $1.99/scan
Teams shipping many apps every week
- Every severity unlocked, low → critical
- AI fix prompt per finding + one fix-everything prompt
- Re-scan after fixing to verify
- Credits never expire
Only need one report? Unlock the scan you already ran for $9, straight from the report page.
One-time payments · no subscription · secure checkout
FAQ
Straight answers
Scope, the free scan, and exactly what you're paying for.
What does the free scan include?
One free scan per account. Low-severity findings are unlocked, with the explanation and a fix prompt. Medium and above stay locked until you buy credits or unlock that report for $9.
Is this a penetration test?
No. FixPrompt passively reads what any visitor's browser receives — pages, JavaScript bundles, headers, cookies, common public paths — plus public DNS records. It does not send exploit payloads or try credentials, and secret values it spots are never stored.
Which URLs can I scan?
Public http(s) URLs for apps you are authorized to assess. Localhost, private networks, and cloud metadata endpoints are blocked.
Do credits expire?
No. Packs are one-time purchases and credits never expire. You can also unlock a single report without buying a pack.
Which AI can use the fix prompt?
Any of them. The report gives you one fix-everything prompt (plus one per finding) written for any coding agent with access to your repo: Claude Code, Codex, Cursor, GitHub Copilot, Windsurf, Gemini CLI, Cline, Aider — or a chat model via OpenRouter, DeepSeek, or GLM. It knows your stack, says where to change what, and how to verify each fix.
$9 unlock or a credit pack — which should I buy?
The $9 unlock opens every finding on a report you already ran. A pack gives you full scans with everything unlocked from the start — ideal for scanning, fixing, and scanning again to confirm the fix. From 3 scans up, a pack is cheaper per report.
What happens right after I pay?
Checkout is secure and one-time. A $9 unlock opens the report as soon as your payment is confirmed. Pack credits land in your balance on the same confirmation and are spent one per new scan.
Find it before someone else does.
Paste a public URL. No account needed to start. Your first report is free.