DevMeth

The pre-flight check for AI-built apps

The AI code security scanner for AI-built apps

Your AI says it's secure. It says that every time. DevMeth is the pre-flight check: it scans your code and your live URL for the known ways AI-built apps fail — deterministic checks, plain-English findings, and a paste-ready fix prompt for each one. Not a pentest; a checklist of exactly the 48 failure patterns AI tools produce, run before you ship.

How it works

  1. Point it at a repo, upload a zip, or give it a live URL.
  2. The engine runs repo-side analysis plus read-only live probes — it never runs your code.
  3. You get a plain-English report: every finding with masked evidence and a fix prompt your AI tool can paste.
  4. Re-scan to verify fixes until green.

What it costs

The free scan runs the 10 Critical checks. Pricing is one-time — $59 Full Report, $179 Launch Pack — instead of a $5k pentest you don't need at this stage. Agencies: run it per client build before handover.

What the scanner checks

Six security themes plus the Rescue ruleset for AI tech debt — each hub lists every check in plain English.

10 checks

Secrets scanning for AI-built apps

Hardcoded API keys, committed .env files, secrets in client bundles and git history — 10 checks that catch what AI tools leak. Scan free.

12 checks

Authentication & access control, checked

Open admin pages, authless API routes, weak JWT secrets, IDOR, client-side role checks — 12 checks for the auth gaps AI tools leave behind.

10 checks

Input validation & injection checks

SQL injection, XSS, SSRF, path traversal, mass assignment — 10 checks for the input-handling bugs AI-generated code ships with.

8 checks

Web hardening before you launch

Wide-open CORS, live debug endpoints, exposed .git, stack-trace leaks, HTTPS and HSTS — 8 checks to run before an AI-built app goes live.

5 checks

Supabase & Firebase security checks

Supabase RLS left disabled, permissive policies, Firebase rules, browser-direct database access — 5 checks for hosted-backend exposure in AI-built apps.

3 checks

Dependency vulnerabilities & drift

Known CVEs in your dependency tree, framework CVEs with middleware-only fixes, and hallucinated packages that don't exist — 3 dependency checks.

12 checks

It works. But what did the agent leave behind?

Dead code, copy-pasted blocks, hallucinated imports, untested routes, drift — the 12-check AI tech-debt scan with a Debt Score and fix prompts.

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan