---
title: "Live URL Scan | ShipSafe"
description: "Scan your deployed app, not just your source. ShipSafe fetches your live app and its client bundles to find missing security headers and secrets accidentally shipped to the browser."
doc_version: 2026-10-05
last_updated: 2026-10-05T09:33:19.711Z
canonical: https://ship-safe.co/docs/live-url-scanning
---

# Live URL Scan | ShipSafe

● Live URL Scan

# Scan the app you shipped.

A source scan reads your code. A live-URL scan reads what you actually deployed. Some of the worst leaks only exist in the built artifact: an API key inlined at build time lives in the JavaScript your users download, not in your repo. ShipSafe fetches your live app and checks for exactly that.

## What it checks

Every hosted Live URL scan — free or paid — runs these 6 checks. None of them read your source; they observe what your deployed app actually serves.

- Security headers — CSP, HSTS, clickjacking protection, nosniff, Referrer-Policy, version banners
- Cookie flags — Secure, HttpOnly, SameSite
- Error pages that leak internals — stack traces, directory listings
- CORS — whether any other site can read your responses
- Secrets shipped in your app's JavaScript — up to 20 of the files your homepage loads
- Source maps that expose your original code

For an origin your account has proven it controls — by serving a one-time token we issue at a fixed path on that exact domain — the hosted scan also requests:

- Files that should never be public — /.env, /.git, backups, /admin

Without that proof, the hosted scan never requests a path your app did not link to — those are guesses at addresses your app never served, not requests a browser would make. The [CLI and MCP](https://ship-safe.co/docs/dast-scanning), running from your own machine against a target you attest you own, check those paths unconditionally, alongside the rest of the runtime checks above.

## What this can't see

A live-URL scan only reads what your app serves over the network. It never sees:

- Your source code and dependencies — a repo scan reads those
- AI analysis of your login and data-access logic
- Whether a leaked key still works — that check only ever runs on your own machine

TIP· Why this matters for AI-built apps

Tools like Lovable, Bolt, and v0 often inline environment variables straight into the front-end bundle. The key is gone from your source after a refactor, but it is still downloadable from your deployed app. This scan is built to catch that.

## Run it from the web

On the [scan page](https://ship-safe.co/scan), switch the target toggle to **Live URL**, paste your deployed app URL, confirm you are authorized to test it, and scan.

## Run it from your editor (MCP)

The [MCP server](https://ship-safe.co/docs/mcp) exposes the same scan as a tool your AI agent can call:

AGENT

Copy

```text
shipsafe_scan_url
  url: "https://yourapp.com"
  confirmOwnership: true
```

NOTE· Read-only and bounded

ShipSafe makes read-only GET requests, like a browser loading your page — but they come from ShipSafe's own servers, not your browser, carrying a ShipSafe user-agent. Some sites' bot protection challenges that kind of traffic; see below for what that looks like. The scan never logs in, submits forms, or changes anything, and the request count and rate are capped. You must confirm you own or are authorized to test the target.

## When we can't fully reach your app

Two different things can stop a scan from seeing everything, and ShipSafe reports them differently rather than folding both into one vague failure.

HEADS UP· Blocked

If a site's bot protection (a Cloudflare or Vercel checkpoint, for example) answers in ShipSafe's place, nothing on your app was checked — this is not a clean result. It often clears within the hour after a few scans in a row. If it keeps happening, your host is configured to challenge automated requests to this address.

NOTE· Partial

If some checks reach your app and others do not — a slow response, a dropped connection mid-scan — the scan still completes. It names which checks did not reach your app, and that scan is not scored: no health ring, no public receipt, just a result you can re-run.

## Privacy

Fetched pages and bundles are analyzed in memory and are not stored. ShipSafe keeps only the findings (the type and location of each issue), not your app's content, and the live-URL scan sends nothing to any third-party AI provider.

[← PreviousRemote MCP Server](https://ship-safe.co/docs/remote-mcp)[Next →Live App Probing (DAST)](https://ship-safe.co/docs/dast-scanning)

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
