● Live URL Scan
Scan the app you shipped.
A source scan reads your code. A live-URL scan reads what you actually deployed. Some of the worst leaks only exist in the built artifact: an API key inlined at build time lives in the JavaScript your users download, not in your repo. ShipSafe fetches your live app and checks for exactly that.
What it checks
Every hosted Live URL scan — free or paid — runs these 6 checks. None of them read your source; they observe what your deployed app actually serves.
- Security headers — CSP, HSTS, clickjacking protection, nosniff, Referrer-Policy, version banners
- Cookie flags — Secure, HttpOnly, SameSite
- Error pages that leak internals — stack traces, directory listings
- CORS — whether any other site can read your responses
- Secrets shipped in your app's JavaScript — up to 20 of the files your homepage loads
- Source maps that expose your original code
For an origin your account has proven it controls — by serving a one-time token we issue at a fixed path on that exact domain — the hosted scan also requests:
- Files that should never be public — /.env, /.git, backups, /admin
Without that proof, the hosted scan never requests a path your app did not link to — those are guesses at addresses your app never served, not requests a browser would make. The CLI and MCP, running from your own machine against a target you attest you own, check those paths unconditionally, alongside the rest of the runtime checks above.
What this can't see
A live-URL scan only reads what your app serves over the network. It never sees:
- Your source code and dependencies — a repo scan reads those
- AI analysis of your login and data-access logic
- Whether a leaked key still works — that check only ever runs on your own machine
Run it from the web
On the scan page, switch the target toggle to Live URL, paste your deployed app URL, confirm you are authorized to test it, and scan.
Run it from your editor (MCP)
The MCP server exposes the same scan as a tool your AI agent can call:
shipsafe_scan_url
url: "https://yourapp.com"
confirmOwnership: trueWhen we can't fully reach your app
Two different things can stop a scan from seeing everything, and ShipSafe reports them differently rather than folding both into one vague failure.
Privacy
Fetched pages and bundles are analyzed in memory and are not stored. ShipSafe keeps only the findings (the type and location of each issue), not your app's content, and the live-URL scan sends nothing to any third-party AI provider.