Early access. Find what is broken before your users do. Your first review is free, no card and no source access. Start free
Ship your AI-built app
with more confidence.
Test your staging app automatically. Find broken pages, reproducible bugs and security issues, then re-test after every fix.
- Free during early access
- No credit card
- Staging-first
- Evidence for every finding
Live API key exposed in the browser bundle
Another account's records readable by changing an ID
Signed in as the test customer role, requesting invoice 1002 returned invoice 1001's data with HTTP 200.
Placeholder copy still present on /pricing
Template tokens and dummy pricing are reachable on a public route.
Automated testing that stops at a fix list
PushFix opens your staging app the way a visitor would, then hands you the problems it can prove, ranked by how much they matter.
Test the running app, not the code
One review follows your links, sitemap and robots rules, loads pages in a real browser, and watches the console, the network, headers, DNS and TLS. Nothing is installed and no repository is read.
Every finding comes with proof
The URL, the response, the values observed, the steps to reproduce and a severity, so you can tell a fact from a guess and fix the worst thing first.
Re-test after you fix it
Run the same environment again and PushFix reports what is fixed, what came back and what is new, along with the movement in your score.
Built for the stack you already ship with
AI handed everyone a codebase. Nobody handed them a reviewer.
Generation optimises for the happy path. The gaps surface later, in front of real users.
Placeholder copy in production
Lorem ipsum, “Company Name”, TODO markers and dummy pricing, still live on your homepage.
Auth that exists only in the UI
The admin button is hidden from the role, but the endpoint behind it never checks. Hiding a control is presentation, not permission.
Test logins and keys still shipped
A seeded admin account and sandbox credentials, still readable by anyone who opens the JavaScript.
Flows that break past the first click
Signup works from a clean state, then the next step answers 404 because that route was never built.
3 of these four run in today's engine. The auth check needs a signed-in test account, so it is named here rather than quietly implied.
Check your app against theseYou are already choosing between these
Every builder weighs the same options. Here is what each one actually gets you, and where PushFix fits in.
Instead of
Asking the AI to review its own code
It wrote the code, so it reasons about what it meant to do rather than what actually ships. It will happily describe a login flow that returns a 404.
PushFix
PushFix reads the running app from the outside: real responses, real headers, real bundle contents.
Instead of
A linter, or a Lighthouse score
Each one sees a single dimension, and none of them can tell you whether the admin endpoint actually checks the role.
PushFix
Security, SEO, accessibility, performance, content and launch readiness judged together and ranked by severity.
Instead of
Booking a manual QA pass
Weeks of scheduling, a subjective write-up, and no reliable way to reproduce it against the same build next month.
PushFix
A review in minutes, every finding carrying evidence and a fix prompt, and re-runs that are directly comparable.
Instead of
Shipping, then watching support tickets
Your users find the breakage, on production, and you hear about it as a bug report or a refund request.
PushFix
You find it on staging first, from a prioritised list, before anyone else ever sees it.
From a link to a fix list
Six stages, and you only have to do the first one.
- 01
Point us at an environment
Add a staging, preview or test URL and answer a few questions about your app. No agents to install, no repository access, no test scripts to write.
- 02
We validate scope before touching anything
Host scope, excluded paths, request budgets and rate limits are fixed up front. Every audit begins by validating its own environment.
- 03
We crawl and discover
Routes, links, sitemaps, forms, API endpoints and the JavaScript bundle: the same surface a real user and a curious visitor would see.
- 04
We run the catalogue
The engine runs every deterministic check it can prove from outside your app, then lists the checks still being built instead of quietly passing them.
- 05
Every finding carries evidence
A URL, the response, the observed values and reproduction steps, plus a confidence score so you can tell a fact from an inference.
- 06
You fix, we re-verify
Re-run the same environment and PushFix confirms what is fixed, what regressed and what is genuinely new.
By the numbers
Ten families of checks on one severity scale, so an exposed key and a broken meta tag are ranked against each other instead of living in five separate tools.
checks in one versioned catalogue
of them are security checks
review families on one severity scale
profiles: quick, standard and full
Everything you need to review before launch
One review covers the whole surface: the security review, the launch checklist, the SEO pass and the accessibility audit you were going to do separately.
Coverage you can trust
147 of 284 checks run today
The engine executes every deterministic check it can prove from outside your app, and every report states exactly which checks ran, which the safety policy skipped and which are still being built. A check that did not run is never counted as a pass, so a clean result means clean.
Why the rest is not running yet
- Needs rendered layout or interaction in a browser84
- Needs a signed-in account23
- Needs AI judgement18
- Needs a request we will not send without your permission12
Security
136Nine sub-families, led by access control. Most serious bugs in generated apps are missing ownership checks and exposed secrets, not exotic exploits.
- Authorization and access control22
- Headers and transport20
- Secrets and credential exposure15
- Infrastructure and configuration15
- API behaviour15
- Session lifecycle13
- Injection indicators13
- Privacy and data flows9
- Client-side sinks9
Vibe-code failure modes
26The ways generated software specifically breaks.
SEO
16Titles, metadata, canonical tags, robots, sitemaps and structured data.
Production readiness
16Favicons, web manifest, domain hygiene, error pages, monitoring hooks.
Functional
16Status codes, links, forms, navigation and failure handling.
UI and layout
15Layout integrity, responsive breakpoints, overlapping and clipped content.
Accessibility
14Keyboard paths, focus order, contrast, semantics and announcements.
Compliance
14Cookie banners, consent, disclosures and required legal affordances.
Content
12Placeholder copy, template tokens and runtime values leaking into pages.
Performance
12Core Web Vitals, payload size, compression and caching.
Versioned & auditable
Every check is externally observable and kept forever. Retired checks are never deleted, so an old report still reproduces exactly as it was sent.
Browse the catalogueNot one generic score. Four disciplines.
Pick an area to see what actually gets examined. Every finding in every group is traceable back to the observation that produced it.
A finding you can act on, not a vague warning
Automated review is only useful if you can verify it. Every finding states exactly what was observed and how confident the check is.
- Stable, citable IDs such as
PF-SEC-AUTHZ-004 - Severity, affected surface and impact scope
- The response, the observed values and reproduction steps
- OWASP and ASVS references where they apply
- A suggested fix you can paste straight into your AI tool
Confidence is not decoration
A missing security header is a fact. A judgement about whether a layout looks broken is an inference. PushFix reports them differently, so you always know which is which.
- 0.92
Directly observed
A 404, a missing header, a broken image
- 0.97
Verified live
A leaked credential confirmed still active
- ≤ 0.60
AI-inferred
Interpretation and prioritisation
The ceiling is enforced when a check is defined and again when a finding is composed, so an AI-inferred result can never claim the certainty of an observed one.
Issues
17 open- CriticalVerified livePF-SEC-SECRET-002Security
Live API key exposed in the browser bundle
- HighOpenPF-SEC-AUTHZ-004Security
Another account's records readable by changing an ID
- MediumVerified fixedPF-VIBE-011Vibe-code
Placeholder copy still present on /pricing
- MediumOpenPF-SEO-003SEO
Every provider page shares one title tag
- LowOpenPF-A11Y-007Accessibility
Date picker cannot be reached with a keyboard
Sample findings from our own demo workspace. Each row opens the evidence behind it, and keeps the same ID on every run.
A review you come back to, not a one-off PDF
The first review tells you where you stand. The ones after it tell you whether you are winning.
Score over time
Seven re-runs on the same environment. The score is what moved; the findings behind it are what you fixed.
- 12Fixed
- 2New
- 1Regressed
It reviews your app without risking it
Automated testing against a live product has to be boring. PushFix is built so the worst case is a handful of read-only requests, not a broken environment.
- Staging-first: production targets are flagged and tested conservatively.
- Request budgets: 3 requests/second, 20 per check and 1,500 per audit.
- At most 5 authentication attempts per account, then it stops.
- Irreversible paths such as delete-account and payment capture are never exercised.
- Injection is reported as indicators only: a weakness is proven to exist, never exploited.
- No load testing, no brute force, no social engineering, no denial of service.
Not a penetration test. Automated, external and non-destructive by design. PushFix reports what automated review can prove with evidence.
Risk tiering across the catalogue
Every check declares how disruptive it is. An unrecognised check defaults to the stricter tier, never the looser one.
- Passive59
Reads only what any visitor receives
- Safe-active207
Sends its own read-only requests
- Invasive6
Writes only to records it created
Anything that writes requires explicit opt-in and dedicated test accounts. 278 of the 284 checks never change a single record.
Choose how deep the review goes
Profiles change the capabilities available to an audit, not just the number of checks: browser, API, authenticated roles, visual diffs and AI.
Quick
A first pass over a small site: headers, secrets, SEO, content, accessibility signals and performance.
No AI spend
Standard
Adds more of the security catalogue and a deeper crawl, so more of the running app is exercised.
No AI spend
Full
DeepestEvery deterministic check the engine can execute today, drawn from the 284-check catalogue. The number grows with each release.
Deepest available today
Anyone shipping software they did not write line by line
Solo builders and indie hackers
You shipped fast with an AI builder and you want to know what is broken before you post the link. One review, a prioritised list, copy-paste fixes.
Agencies and freelancers
Hand clients a review instead of a promise. Evidence-backed findings show what you checked, what you found and what you fixed.
Product and platform teams
Vibe-coded prototypes move into production. PushFix becomes the regression gate that keeps the shortcuts away from real users.
Built in the open, shipped in order
PushFix is in early access. This is the honest list: what you can use today, and what is still being built.
- Shipped
Accounts, projects and environments, guided intake, the crawler, the deterministic engine and the 284-check catalogue, with findings, evidence, severity scoring, re-run comparison and shareable HTML reports.
- Growing
More executable checks every release, so the engine covers more of the catalogue without you changing anything.
- Next
The browser engine for rendered layout, keyboard and responsive checks, plus API testing and authenticated testing with dedicated test accounts.
- Later
AI exploration on the Full profile, PDF export, scheduled monitoring and CI integration.
Start free, upgrade when you need depth
The free review is genuinely free and needs no card. Paid plans are for regular reviews, larger sites and more projects. Current numbers live on the plans page.
Free
No card, one review
A first pass on a small site, so you can see exactly what a PushFix report looks like.
Starter
For one project
Regular reviews with regression comparison between runs, so you can watch the score move.
Pro
PopularFor volume and depth
More projects, larger sites and the deepest deterministic profile available today.
The things people ask before their first review
Do you need access to my source code?
No. PushFix only looks at what a visitor or a signed-in user can see: pages, markup, bundle contents, network traffic, headers, DNS and TLS. Nothing is read from your repository and nothing is installed in your app.
Should I test staging or production?
Staging, preview or a test environment, always. PushFix detects production-looking URLs, warns you and stays conservative there. Active security testing belongs on an environment where breaking something does not affect real users.
Will testing break my application?
The catalogue is built so that it cannot. 71 checks are purely passive, 207 send their own read-only requests, and only 6 write anything, always to disposable records the audit itself created and only with explicit write consent.
What will PushFix never do?
No destructive payloads, no denial-of-service or load testing, no brute-forcing beyond the configured attempt cap, no social engineering, no contacting real users, and nothing at all against hosts you have not authorized. The full list ships with every report.
Do I have to give you credentials?
Only for the checks that need a signed-in view, and only if you want them. Add a dedicated test account on the project's Logins screen and the next review signs in with it and checks what that account can reach. Email and password works today, and so does a one-time code when your app accepts a fixed code for a test account, as a staging code usually does. A magic link or single sign-on has to be completed by you, so those accounts are recorded and the area behind them stays unreviewed. Without an account, those checks are listed as skipped, never guessed at.
How do you verify a leaked secret is real?
For a small allow-list of credential types that expose a read-only identity endpoint, PushFix makes a single non-mutating call and records only whether it authenticated. It never touches an endpoint that could write, send or cost money, and it only runs with active-testing consent.
What does a finding actually contain?
A stable ID, severity, the affected surface, the evidence that produced it, reproduction steps, an explanation of why it matters, a confidence score and a suggested fix you can hand straight to your AI tool.
Is PushFix a penetration test?
No, and it does not replace one. It is automated, external and non-destructive. It finds the classes of problem that automated review can prove and reports them with evidence; a manual penetration test goes further into business logic and chained exploits.
Do all 284 checks run on my site?
Not yet, and the report never pretends otherwise. The catalogue holds 284 checks; the deterministic engine executes the subset that can be judged from outside the app today, and it lists the rest as skipped, with the reason. A check that did not run is never counted as a pass, which is why a clean PushFix report is worth more than a clean score from a tool that guesses.
How is this different from asking my AI tool to review its own code?
The tool that wrote the code reasons about intent. PushFix looks at what actually shipped: the responses, headers, bundle contents and pages a visitor receives. That is the difference between an account of the code and a statement about the running product.
What does it cost?
Your first review is free and needs no card. Paid plans exist for regular reviews, larger sites and more projects, and past a plan's allowance you keep auditing at the plan rate rather than being blocked. The plans page has the current numbers.
They found it before their users did
PushFix is used by solo builders and small teams who write with an AI assistant and review late. This is the kind of thing that comes back.
We pushed at eleven at night and the pricing page still said “Company Name” with lorem ipsum underneath. I had read that section so many times that I had stopped seeing it. It was fixed ten minutes after the report came back.
PushFix found our checkout key sitting in a client bundle. It gave me the exact chunk URL and the line it was on, which is the only reason I believed it instead of assuming a false positive.
Nobody on the team had clicked the password reset link since launch. It returned a 404. One finding, and it paid for the year.
Our date picker could not be reached with a keyboard at all. We would never have caught that ourselves, because all four of us work with a mouse.
Every provider page had the same title tag. PushFix said it was a duplicate-title problem and listed the pages, so I fixed it in one commit instead of guessing at metadata for a week.
The recheck is what convinced me. Fix the thing, hit recheck, and it either comes back verified or shows me the same evidence again. No guessing about whether the fix actually landed.
Ship fast.
Check it before your users do.
Point it at your staging site. The first review is free, and your source code is never read.
Worst case, a review finds nothing and you have spent ten minutes learning your app is clean.
Prefer to look around first? Compare plans