Sample reportSecurity report

app.example.com

  • 12 pages crawled
  • 26 checks · 5 failed
Detected stackNext.jsVercelSupabase

5 issues found · 2 need fixing first

  • 1critical
  • 1high
  • 1medium
  • 2low
See what's locked
Exposed

Where your site is exposed

11 areas reviewed · 7 clean · 4 with issues

  • critical

    Leaked secrets & keys

    2/3 checks passed· 1 locked

  • high

    Security headers

    3/5 checks passed· 1 locked

  • medium

    Cookies & sessions

    2/3 checks passed· 1 locked

  • Low

    Information disclosure

    1/2 checks passed

PassedExposed files & source codeVulnerable librariesAuth postureCORSHTTPS & transportForms / CSRFThird-party scripts

1 critical · 1 high · 1 medium

Your report is ready. The serious part is locked.

  • What's wrong in all 3 locked findings
  • Evidence: the exact header, path, or script we saw
  • One prompt your AI (Claude, Codex, Cursor…) runs to fix it all

Secure checkout· One-time payment, no subscription· Credits never expire

Medium, high, and critical

3 findings — titles shown, details locked.

Low

2 low findings

Free to read once you create an account.

One prompt. Every fix.

Your AI fix plan is ready: 5 tasks

We wrote the fixes for your stack as one prompt. Paste it into the AI you already code with and it fixes everything in priority order, then tells you what to verify.

Claude CodeCodexCursorCopilotWindsurfGeminiDeepSeekany LLM
fix-plan.md

# Security fix plan for https://app.example.com

Detected stack: Next.js, hosted on Vercel, backend: Supabase

### 1. [CRITICAL] Client bundle references a privileged key name

### 2. [HIGH] Content-Security-Policy not set

### 3. [MEDIUM] Session cookie missing Secure flag

…and 2 more tasks

  • Passive only

    Normal page loads. No attack payloads, no load on your servers.

  • Secrets never stored

    If we spot a key, we record its type — never its value.

  • Private to you

    This report is tied to your browser or account. It isn't indexed.

Questions

Is this scan safe for my production site?

Yes. FixPrompt only makes the same GET requests a visitor's browser would, plus a few well-known paths like /.env or /.git/HEAD. It never submits forms, never sends exploit payloads, and never logs in.

What do I get when I unlock?

Every finding in full: what's wrong, the evidence we saw (header, path, or script), why it matters, and a fix written for your stack. Plus one prompt that tells your AI coding agent how to fix all of it and how to verify each change.

Is the $9 a subscription?

No. It's a one-time payment for this report through secure checkout. Credit packs are one-time too, and credits never expire.

Which AI tools does the fix prompt work with?

Any of them: Claude Code, Codex, Cursor, GitHub Copilot, Windsurf, Gemini CLI, Cline, Aider, or a chat model through OpenRouter, DeepSeek, or GLM. It's plain Markdown with no tool-specific syntax.

How do I know the fixes worked?

Re-scan after you deploy. Findings that are gone show up as fixed, and your grade updates.

Have another project? Scan another site