All 74 checks
ShipReady runs 74 deterministic checks across six areas of a production deployment. Each is evidence-based — reported only when the condition is observed directly, never inferred — and each has a page explaining what it means and how to fix it.
Generated from the scanner itself, so this list is always exactly what runs against your site.
Security53 checks
Headers, secrets, database access, cookies, CORS and information disclosure.
- Anthropic API Key Exposedcritical
- AWS Access Key Exposedcritical
- Cloudinary API Secret Exposedcritical
- Database Connection String Exposedcritical
- Exposed environment file (.env)critical
- Firebase Realtime Database is publicly readablecritical
- Firebase Storage bucket is publicly listablecritical
- GitHub Token Exposedcritical
- Groq API Key Exposedcritical
- Hugging Face Token Exposedcritical
- Missing rlscritical
- npm Access Token Exposedcritical
- OpenAI API Key Exposedcritical
- Perplexity API Key Exposedcritical
- Private Key Exposedcritical
- PyPI API Token Exposedcritical
- Replicate API Token Exposedcritical
- Resend API Key Exposedcritical
- SendGrid API Key Exposedcritical
- Slack API Token Exposedcritical
- Stripe Secret Key Exposedcritical
- Supabase Service Role Key Exposedcritical
- Anyone can sign up with an email address they do not ownhigh
- Exposed .git Directoryhigh
- Exposed docker-compose filehigh
- HTTP is not redirected to HTTPShigh
- Mapbox Secret Token Exposedhigh
- Missing Content-Security-Policy headerhigh
- Overly Permissive CORS with Credentialshigh
- Potential Secret or Private Token Exposedhigh
- Session Cookie Missing 'HttpOnly' Flaghigh
- Session Cookie Missing 'Secure' Flaghigh
- Slack Incoming Webhook URL Exposedhigh
- Stripe Restricted Key Exposedhigh
- Tls certificate expiringhigh
- Directory Listing Enabledmedium
- Error page leaks a stack tracemedium
- Exposed Debug or Config Endpointmedium
- GraphQL introspection is enabled in productionmedium
- Missing or permissive X-Frame-Options headermedium
- Missing Strict-Transport-Security headermedium
- Public Supabase Storage bucketmedium
- Server still accepts a deprecated TLS versionmedium
- Session Cookie Missing 'SameSite' Attributemedium
- Session Cookie Uses 'SameSite=None' Without 'Secure'medium
- Exposed .DS_Store filelow
- Exposed JavaScript Source Maplow
- Invalid Referrer-Policy valuelow
- Missing or invalid X-Content-Type-Options headerlow
- Missing Referrer-Policy headerlow
- Response header discloses a software versionlow
- Strict-Transport-Security is missing includeSubDomainslow
- Weak Strict-Transport-Security max-agelow
Email6 checks
SPF, DKIM, DMARC and MX records for the sending domain.
AI Exposure5 checks
AI tooling files deployed by accident and provider keys reaching the browser.
Production Readiness5 checks
Metadata, crawlability and launch signals.
SEO & AI Visibility3 checks
Whether search engines and AI assistants can find, crawl and cite your site.
Payments2 checks
Payment provider configuration, including test keys left on a live domain.
Run all 74 against your site
ShipReady scans up to ten pages and reports what it finds, with a paste-ready fix for each. Free, no signup.
Scan my site