Example Report. This is a demonstration of the report format. These findings do not represent a real application.

Production Readiness Report

yourapp.example

Scanned October 2, 2026 at 1:12 AM·Next.js

Strong

Launch readiness

Fix high-priority issues before launch

Report confidence

High

No major externally observable production issues were detected within the completed checks.

2 high-priority findings worth reviewing.

An engineer can review the findings with you and prioritize what actually matters.

What we found

Your application scored 90/100 and falls into the Strong range — a measure of production readiness within the scope of this external audit, not a security guarantee.

No confirmed critical issue was detected, but 2 high-priority findings should be reviewed before you increase traffic. The most important issue relates to content security policy is not configured.

This external audit cannot verify backend authorization, database permissions, or server-side secrets, so a code-level audit would provide additional confidence.

What we'd fix first

  1. 1

    Content Security Policy is not configured

    High·confirmed·Fix Before Launch
  2. 2

    Production error responses expose implementation details

    High·strong signal·Fix Before Launch
  3. 3

    Production source maps are publicly accessible

    Medium·confirmed·Fix Soon

Good news

  • No server-side secret patterns were detected in client-delivered code.
  • No uncaught JavaScript errors were observed during the tested page load.
  • No sensitive files (.env, .git) were exposed at the common paths checked.
  • HTTPS is correctly enforced.
  • TLS certificate is valid.

7 of 7 findings

HighConfirmedFix Before LaunchConfiguration

Content Security Policy is not configured

Information ExposureConfigurationQuick fix

What we observed

No Content-Security-Policy header was returned on the 4 pages included in this scan.

Why this matters

A well-configured CSP reduces the impact of certain browser-based injection attacks.

Affected pages: 3

Recommended action

Introduce a CSP gradually — start in report-only mode, then tune it to your app's real resources before enforcing.

HighStrong signalFix Before LaunchSecurity

Production error responses expose implementation details

Information ExposureModerate

What we observed

An error response appears to include a framework stack trace.

Why this matters

Stack traces reveal file paths and dependencies — reconnaissance material for targeted attacks.

Recommended action

Enable production error handling so users see a generic page and details go to your logs.

MediumConfirmedFix SoonSecurity

Production source maps are publicly accessible

Information ExposureQuick fix

What we observed

2 JavaScript source maps were reachable at public URLs.

Why this matters

Source maps make it easier to read your minified code. A disclosure concern, not a direct compromise.

Recommended action

Disable source-map output for production builds, or restrict access at the hosting layer.

MediumConfirmedFix SoonReliability

3 application resources failed to load

AvailabilityModerate

What we observed

While loading the scanned pages, 3 sub-resource requests returned 404.

Why this matters

Broken resources degrade the UI and can indicate stale references left from rapid iteration.

Evidence

404/images/hero-v2.png
404/api/legacy/config

Recommended action

Review the failing requests and remove or fix the references.

LowConfirmedImprovementPrivacy

Referrer Policy is not explicitly configured

Information ExposureConfigurationQuick fix

What we observed

No Referrer-Policy header was returned on the scanned pages.

Why this matters

Full URLs (which can contain identifiers) may be sent to third-party sites users navigate to.

Recommended action

Add Referrer-Policy: strict-origin-when-cross-origin.

InformationalConfirmedInformationalThird-Party Exposure

Third-party services detected

ConfigurationModerate

What we observed

Detected integrations: Stripe, Supabase, Google Analytics, Sentry.

Why this matters

Not a problem by itself — this is your external dependency surface.

Evidence

paymentsStripe
backendSupabase

Recommended action

Review the list and remove any service you no longer use.

InformationalConfirmedInformationalThird-Party Exposure

Authentication surface detected

ConfigurationModerate

What we observed

Auth provider(s): Supabase.

Why this matters

Whether authorization and session handling are correct can't be confirmed externally.

Recommended action

Have authentication and authorization logic reviewed at the code level.

What we couldn't verify

  • This audit evaluates externally observable behavior and does not prove the application is secure. It does not review source code, backend authorization, database policies, private infrastructure, or authenticated workflows unless separately authorized.
  • The external scan cannot verify: Backend authorization rules, Database permissions and Supabase RLS, Server-side secrets handling, Payment webhook verification, Private dependencies and business logic, Internal architecture.

External checks can't verify everything

Because this application uses Stripe, Supabase, Google Analytics and backend services, a code-level review can verify authorization rules, database access, secrets handling, and server-side validation.

The code audit can inspect

  • authentication logic
  • authorization
  • database access
  • Supabase RLS
  • secrets handling
  • server/client boundaries
  • API validation
  • payment logic
  • webhook verification
  • dependencies
  • technical debt
  • test coverage

Let's make it production-ready.

We'll review your findings, understand what's blocking you, and tell you what we recommend fixing first.

Methodology & disclaimer

This audit evaluates externally observable production behavior only. It does not attempt to exploit, bypass, or gain unauthorized access, and cannot see server-side code, private data, or infrastructure. Findings marked “Strong signal” or “Requires verification” should be reviewed before being treated as confirmed. Anything resembling a secret is stored and displayed in redacted form only. A clean external scan does not guarantee the application is free of vulnerabilities.

Retained until November 1, 2026. Scoring v1.0 · Scanner v1.0 · Report v1.0

A little context first

Four quick questions so the right engineer reviews your findings.

Where are you right now?
Roughly how many active users?
Are payments live?
What is your biggest concern?

How is this score calculated?

Each category starts at 100 and is reduced based on the confirmed and potential production issues we found. More serious and higher-confidence findings have a larger impact; uncertain observations count for much less.

The overall score is a weighted blend of the categories we could evaluate (Security counts most). Categories we couldn't cover are shown as Not enough data — missing coverage is never treated as a pass.

Confirmed critical issues cap the overall score regardless of the average, so a serious problem can't hide behind otherwise good results.

The score reflects production readiness within the scope of this external audit — it is not a guarantee that the application is secure.

Scoring model v1.0

Example Report · VibeCheck