ProductChecks

We ask your app the questions a stranger would.

Anyone can try to open someone else’s order, change a price or download a backup. We ask your app 129 questions like that, in plain words.

Five of the worst things that can happen to your app.

None of them shows up when you click through your own app, so you wouldn’t know it’s there. They are five of the 129 questions we ask.

Severity up to Critical

Customers can read each other’s data.

Change one number in the address and someone else’s order opens. We follow every way into your app to see whether a customer can reach what isn’t theirs.

What it costs you
A stranger or another customer reads, changes or deletes data that is not theirs.
Why you won’t notice
Your own account only ever opens your own orders, so everything looks right to you.
All 27 questions
Severity up to Critical

Someone pays less than they should.

If the price comes from the browser, anyone can change it. We follow every checkout and payment message to see who decides what gets paid.

What it costs you
People get paid features for free or for less, or real payments fail to count.
Why you won’t notice
Your checkout shows the right price every time you try it yourself.
All 6 questions
Severity up to High

Strangers make your app work for them.

An AI feature that anyone can call runs up your bill. A request can even choose what your server runs. We check what a visitor can make your app do.

What it costs you
Anyone uses your app as a free AI service and runs up your provider bill.
Why you won’t notice
The feature works perfectly for you. You find out when the bill arrives.
All 24 questions
Severity up to Critical

Your site shows more than it should.

Old backups, forgotten files and open admin pages can be one address away, and scanners ask every site for them all day. We look for each one.

What it costs you
Your data, code or configuration is one download away.
Why you won’t notice
No page links to these files, so you never see them. Scanners don’t need a link.
All 34 questions
Severity up to Critical

Secrets sit in your code.

A key saved in your project goes wherever your code goes, and a key you deleted later still sits in its history. We read your repository for keys, and for libraries with known flaws.

What it costs you
Anyone takes the key from your site and runs up your AI or email bill in your name.
Why you won’t notice
Your app runs fine with the key inside, and nothing warns you that it is there.
All 38 questions

And it doesn’t stop at five.

A few more of the serious ones. Open any question to see what it means for your app.

You’ve seen 24 of our 129 questions.

Look up the rest

You decide how far we look.

Your address is enough to start. Say the app is yours and we try the doors a stranger would. Connect your code and we read how it works inside.

Check my app

16 questions in reach

What every visitor sees

  • Home page
  • Sign-in form
  • Scripts it loads
  • Certificate

One address away

Waits for your OK

Inside your code

Connect your repository

We only look.

Our checks only read. We don’t sign in, and we don’t send anything that changes your app.

Security at Vallit

What we do

  • Open your pages the way a browser does
  • Read what comes back
  • Read your repository

What we never do

  • Sign in to your app
  • Send a form
  • Submit a change

Every request we send says it comes from Vallit, and your reports stay in Frankfurt.

See what your app shows to anyone.

Start with a free check. You don’t even need an account to see your score.