Skip to main content
Reactll — AI & Software Engineering Reactor Technology

Free Security Check

Paste your address and see what anyone can already read from outside.

It only requests the page and the scripts that page loads, the same thing a browser does. No login attempts, no guessing at hidden files.

No signup · free

Security check

Tick the box below to enable the check.

What we found on

The full report

Want this as a report you can forward?

A PDF with every finding and what to do about it — the thing to hand to whoever pays for the fix. We read the same report before we reply, so if something here needs a person, you will hear from an engineer, not an automated sales email.

Your report is ready.

Download the PDF

An engineer reads the same findings. If anything in there is urgent, you will hear from us today.

What this check does, and what it refuses to do

It reads

  • The page you give us, and the scripts it loads from its own domain
  • Security settings your server sends: encryption, framing, content rules, cookie settings
  • Secret keys left public by mistake: Stripe, AWS, OpenAI, Anthropic, GitHub, Supabase service-role
  • Error details left on, readable source code files, PHP versions that no longer get updates, an old WordPress

It never

  • Guesses at admin paths or hidden files
  • Tries to log in, sends harmful input, or does anything like an attack
  • Touches your database or your users' data
  • Stores the findings longer than an hour, unless you ask for the report

We stop there on purpose. Everything above is already sent to anyone who opens your page; going further would be unauthorised access, whoever asked for it. The deeper checks — whether each user can really only see their own data, whether an automatic message between systems (a webhook) can be faked by sending it again — happen in the system review, with your permission and your credentials.

FAQ

Questions people ask before they run it

Yes. It requests your page and the scripts that page loads, exactly as a browser does, and reads what comes back. It does not guess at hidden files, try to log in, or send anything that could change your data. Everything it reports was already being served to every visitor.
The anon key is meant to be public, so seeing it in your site’s code is normal. It is only safe if row-level security (rules that let each user see only their own rows) is switched on for every table that holds user data — without it, the anon key can read everything. The service_role key is a different story: it ignores row-level security entirely and must never leave your server. This check tells you which one you have published.
Yes, in seconds. Anything sent to the browser can be read by anyone who opens the browser’s developer tools, and bots scan public site code for keys automatically. A Stripe secret key, an AWS key or an OpenAI key left in that code is misused within hours, not weeks.
The findings appear on screen before we ask for anything. With your email you get the same findings as a PDF you can forward to whoever pays for the fix, and it tells us something is worth a reply. An engineer reads it, not an automated sales system.
The result is held for an hour so the report can be generated, then it is gone. If you ask for the PDF we keep your name, email and the address you checked, because that is the enquiry. What we store and for how long is on our data protection page.
Its bot protection shows us a challenge page instead of your site, so there is nothing honest to report. That protection is doing its job. Send us the address and we will look at it with you instead.

Want more than an automated scan?

The check sees what anyone can read from outside. A system review reads the code, hosting and data behind it.

Book a Call 30 Minutes