PushFix

Early access. Find what is broken before your users do. Your first review is free, no card and no source access. Start free

Ship your AI-built app
with more confidence.

Test your staging app automatically. Find broken pages, reproducible bugs and security issues, then re-test after every fix.

opens like a visitorno source access · staging-first

  • Free during early access
  • No credit card
  • Staging-first
  • Evidence for every finding
staging.yourapp.com
3 critical7 high12 mediumconfidence-aware
CriticalPF-SEC-SECRET-002

Live API key exposed in the browser bundle

confidence
0.97
GET /_next/static/chunks/main-8f2c.js 200
"sk_live_51H…" found in shipped JavaScript
verification: read-only identity call → authenticated
Evidence: http-responseOWASP A02:20213 repro steps
HighPF-SEC-AUTHZ-004

Another account's records readable by changing an ID

Signed in as the test customer role, requesting invoice 1002 returned invoice 1001's data with HTTP 200.

MediumPF-VIBE-011

Placeholder copy still present on /pricing

Template tokens and dummy pricing are reachable on a public route.

What you get

Automated testing that stops at a fix list

PushFix opens your staging app the way a visitor would, then hands you the problems it can prove, ranked by how much they matter.

Test the running app, not the code

One review follows your links, sitemap and robots rules, loads pages in a real browser, and watches the console, the network, headers, DNS and TLS. Nothing is installed and no repository is read.

Every finding comes with proof

The URL, the response, the values observed, the steps to reproduce and a severity, so you can tell a fact from a guess and fix the worst thing first.

Re-test after you fix it

Run the same environment again and PushFix reports what is fixed, what came back and what is new, along with the movement in your score.

Built for the stack you already ship with

Next.jsReactVueSvelteRemixAstroNuxtExpressNestJSFastAPI
DjangoRailsLaravelSupabaseFirebasePostgreSQLMongoDBVercelNetlifyRailway
The story

AI handed everyone a codebase. Nobody handed them a reviewer.

Generation optimises for the happy path. The gaps surface later, in front of real users.

01

Placeholder copy in production

Lorem ipsum, “Company Name”, TODO markers and dummy pricing, still live on your homepage.

CONTENT-001Placeholder or Lorem Ipsum Text · highRuns today
02

Auth that exists only in the UI

The admin button is hidden from the role, but the endpoint behind it never checks. Hiding a control is presentation, not permission.

SEC-AUTHZ-012Authorization Enforced Only in the UI · criticalNeeds a test login
03

Test logins and keys still shipped

A seeded admin account and sandbox credentials, still readable by anyone who opens the JavaScript.

SEC-SECRET-003Hardcoded Credentials in Client Code · criticalRuns today
04

Flows that break past the first click

Signup works from a clean state, then the next step answers 404 because that route was never built.

FUNC-002Broken Link · mediumRuns today

3 of these four run in today's engine. The auth check needs a signed-in test account, so it is named here rather than quietly implied.

Check your app against these
Why PushFix

You are already choosing between these

Every builder weighs the same options. Here is what each one actually gets you, and where PushFix fits in.

Instead of

Asking the AI to review its own code

It wrote the code, so it reasons about what it meant to do rather than what actually ships. It will happily describe a login flow that returns a 404.

PushFix

PushFix reads the running app from the outside: real responses, real headers, real bundle contents.

Instead of

A linter, or a Lighthouse score

Each one sees a single dimension, and none of them can tell you whether the admin endpoint actually checks the role.

PushFix

Security, SEO, accessibility, performance, content and launch readiness judged together and ranked by severity.

Instead of

Booking a manual QA pass

Weeks of scheduling, a subjective write-up, and no reliable way to reproduce it against the same build next month.

PushFix

A review in minutes, every finding carrying evidence and a fix prompt, and re-runs that are directly comparable.

Instead of

Shipping, then watching support tickets

Your users find the breakage, on production, and you hear about it as a bug report or a refund request.

PushFix

You find it on staging first, from a prioritised list, before anyone else ever sees it.

How it works

From a link to a fix list

Six stages, and you only have to do the first one.

  1. 01

    Point us at an environment

    Add a staging, preview or test URL and answer a few questions about your app. No agents to install, no repository access, no test scripts to write.

  2. 02

    We validate scope before touching anything

    Host scope, excluded paths, request budgets and rate limits are fixed up front. Every audit begins by validating its own environment.

  3. 03

    We crawl and discover

    Routes, links, sitemaps, forms, API endpoints and the JavaScript bundle: the same surface a real user and a curious visitor would see.

  4. 04

    We run the catalogue

    The engine runs every deterministic check it can prove from outside your app, then lists the checks still being built instead of quietly passing them.

  5. 05

    Every finding carries evidence

    A URL, the response, the observed values and reproduction steps, plus a confidence score so you can tell a fact from an inference.

  6. 06

    You fix, we re-verify

    Re-run the same environment and PushFix confirms what is fixed, what regressed and what is genuinely new.

By the numbers

Ten families of checks on one severity scale, so an exposed key and a broken meta tag are ranked against each other instead of living in five separate tools.

Catalogue
284

checks in one versioned catalogue

Security
136

of them are security checks

Families
10

review families on one severity scale

Profiles
3

profiles: quick, standard and full

What one review covers

Everything you need to review before launch

One review covers the whole surface: the security review, the launch checklist, the SEO pass and the accessibility audit you were going to do separately.

Coverage you can trust

147 of 284 checks run today

The engine executes every deterministic check it can prove from outside your app, and every report states exactly which checks ran, which the safety policy skipped and which are still being built. A check that did not run is never counted as a pass, so a clean result means clean.

147 execute today137 still being built

Why the rest is not running yet

  • Needs rendered layout or interaction in a browser84
  • Needs a signed-in account23
  • Needs AI judgement18
  • Needs a request we will not send without your permission12

Security

136

Nine sub-families, led by access control. Most serious bugs in generated apps are missing ownership checks and exposed secrets, not exotic exploits.

  • Authorization and access control22
  • Headers and transport20
  • Secrets and credential exposure15
  • Infrastructure and configuration15
  • API behaviour15
  • Session lifecycle13
  • Injection indicators13
  • Privacy and data flows9
  • Client-side sinks9

Vibe-code failure modes

26

The ways generated software specifically breaks.

SEO

16

Titles, metadata, canonical tags, robots, sitemaps and structured data.

Production readiness

16

Favicons, web manifest, domain hygiene, error pages, monitoring hooks.

Functional

16

Status codes, links, forms, navigation and failure handling.

UI and layout

15

Layout integrity, responsive breakpoints, overlapping and clipped content.

Accessibility

14

Keyboard paths, focus order, contrast, semantics and announcements.

Compliance

14

Cookie banners, consent, disclosures and required legal affordances.

Content

12

Placeholder copy, template tokens and runtime values leaking into pages.

Performance

12

Core Web Vitals, payload size, compression and caching.

Versioned & auditable

Every check is externally observable and kept forever. Retired checks are never deleted, so an old report still reproduces exactly as it was sent.

Browse the catalogue
Inside the review

Not one generic score. Four disciplines.

Pick an area to see what actually gets examined. Every finding in every group is traceable back to the observation that produced it.

Evidence over opinion

A finding you can act on, not a vague warning

Automated review is only useful if you can verify it. Every finding states exactly what was observed and how confident the check is.

  • Stable, citable IDs such as PF-SEC-AUTHZ-004
  • Severity, affected surface and impact scope
  • The response, the observed values and reproduction steps
  • OWASP and ASVS references where they apply
  • A suggested fix you can paste straight into your AI tool

Confidence is not decoration

A missing security header is a fact. A judgement about whether a layout looks broken is an inference. PushFix reports them differently, so you always know which is which.

  • Directly observed

    A 404, a missing header, a broken image

    0.92
  • Verified live

    A leaked credential confirmed still active

    0.97
  • AI-inferred

    Interpretation and prioritisation

    ≤ 0.60

The ceiling is enforced when a check is defined and again when a finding is composed, so an AI-inferred result can never claim the certainty of an observed one.

Issues

17 open
3 critical7 high7 medium
All 17Security 9Vibe-code 3SEO 2A11y 3
  • PF-SEC-SECRET-002Security

    Live API key exposed in the browser bundle

  • PF-SEC-AUTHZ-004Security

    Another account's records readable by changing an ID

  • PF-VIBE-011Vibe-code

    Placeholder copy still present on /pricing

  • PF-SEO-003SEO

    Every provider page shares one title tag

  • PF-A11Y-007Accessibility

    Date picker cannot be reached with a keyboard

Sample findings from our own demo workspace. Each row opens the evidence behind it, and keeps the same ID on every run.

Why it stays useful

A review you come back to, not a one-off PDF

The first review tells you where you stand. The ones after it tell you whether you are winning.

Score over time

78+37

Seven re-runs on the same environment. The score is what moved; the findings behind it are what you fixed.

  • 12
    Fixed
  • 2
    New
  • 1
    Regressed
Safe by design

It reviews your app without risking it

Automated testing against a live product has to be boring. PushFix is built so the worst case is a handful of read-only requests, not a broken environment.

  • Staging-first: production targets are flagged and tested conservatively.
  • Request budgets: 3 requests/second, 20 per check and 1,500 per audit.
  • At most 5 authentication attempts per account, then it stops.
  • Irreversible paths such as delete-account and payment capture are never exercised.
  • Injection is reported as indicators only: a weakness is proven to exist, never exploited.
  • No load testing, no brute force, no social engineering, no denial of service.

Not a penetration test. Automated, external and non-destructive by design. PushFix reports what automated review can prove with evidence.

Risk tiering across the catalogue

Every check declares how disruptive it is. An unrecognised check defaults to the stricter tier, never the looser one.

  • Passive59

    Reads only what any visitor receives

  • Safe-active207

    Sends its own read-only requests

  • Invasive6

    Writes only to records it created

Anything that writes requires explicit opt-in and dedicated test accounts. 278 of the 284 checks never change a single record.

Profiles

Choose how deep the review goes

Profiles change the capabilities available to an audit, not just the number of checks: browser, API, authenticated roles, visual diffs and AI.

Quick

120 checks run

A first pass over a small site: headers, secrets, SEO, content, accessibility signals and performance.

No AI spend

Standard

143 checks run

Adds more of the security catalogue and a deeper crawl, so more of the running app is exercised.

No AI spend

Full

Deepest
147 checks run

Every deterministic check the engine can execute today, drawn from the 284-check catalogue. The number grows with each release.

Deepest available today

Who it is for

Anyone shipping software they did not write line by line

Solo builders and indie hackers

You shipped fast with an AI builder and you want to know what is broken before you post the link. One review, a prioritised list, copy-paste fixes.

Agencies and freelancers

Hand clients a review instead of a promise. Evidence-backed findings show what you checked, what you found and what you fixed.

Product and platform teams

Vibe-coded prototypes move into production. PushFix becomes the regression gate that keeps the shortcuts away from real users.

What is live, and what is next

Built in the open, shipped in order

PushFix is in early access. This is the honest list: what you can use today, and what is still being built.

  1. Shipped

    Accounts, projects and environments, guided intake, the crawler, the deterministic engine and the 284-check catalogue, with findings, evidence, severity scoring, re-run comparison and shareable HTML reports.

  2. Growing

    More executable checks every release, so the engine covers more of the catalogue without you changing anything.

  3. Next

    The browser engine for rendered layout, keyboard and responsive checks, plus API testing and authenticated testing with dedicated test accounts.

  4. Later

    AI exploration on the Full profile, PDF export, scheduled monitoring and CI integration.

Pricing

Start free, upgrade when you need depth

The free review is genuinely free and needs no card. Paid plans are for regular reviews, larger sites and more projects. Current numbers live on the plans page.

Free

No card, one review

A first pass on a small site, so you can see exactly what a PushFix report looks like.

Starter

For one project

Regular reviews with regression comparison between runs, so you can watch the score move.

Pro

Popular

For volume and depth

More projects, larger sites and the deepest deterministic profile available today.

Questions

The things people ask before their first review

Do you need access to my source code?

No. PushFix only looks at what a visitor or a signed-in user can see: pages, markup, bundle contents, network traffic, headers, DNS and TLS. Nothing is read from your repository and nothing is installed in your app.

Should I test staging or production?

Staging, preview or a test environment, always. PushFix detects production-looking URLs, warns you and stays conservative there. Active security testing belongs on an environment where breaking something does not affect real users.

Will testing break my application?

The catalogue is built so that it cannot. 71 checks are purely passive, 207 send their own read-only requests, and only 6 write anything, always to disposable records the audit itself created and only with explicit write consent.

What will PushFix never do?

No destructive payloads, no denial-of-service or load testing, no brute-forcing beyond the configured attempt cap, no social engineering, no contacting real users, and nothing at all against hosts you have not authorized. The full list ships with every report.

Do I have to give you credentials?

Only for the checks that need a signed-in view, and only if you want them. Add a dedicated test account on the project's Logins screen and the next review signs in with it and checks what that account can reach. Email and password works today, and so does a one-time code when your app accepts a fixed code for a test account, as a staging code usually does. A magic link or single sign-on has to be completed by you, so those accounts are recorded and the area behind them stays unreviewed. Without an account, those checks are listed as skipped, never guessed at.

How do you verify a leaked secret is real?

For a small allow-list of credential types that expose a read-only identity endpoint, PushFix makes a single non-mutating call and records only whether it authenticated. It never touches an endpoint that could write, send or cost money, and it only runs with active-testing consent.

What does a finding actually contain?

A stable ID, severity, the affected surface, the evidence that produced it, reproduction steps, an explanation of why it matters, a confidence score and a suggested fix you can hand straight to your AI tool.

Is PushFix a penetration test?

No, and it does not replace one. It is automated, external and non-destructive. It finds the classes of problem that automated review can prove and reports them with evidence; a manual penetration test goes further into business logic and chained exploits.

Do all 284 checks run on my site?

Not yet, and the report never pretends otherwise. The catalogue holds 284 checks; the deterministic engine executes the subset that can be judged from outside the app today, and it lists the rest as skipped, with the reason. A check that did not run is never counted as a pass, which is why a clean PushFix report is worth more than a clean score from a tool that guesses.

How is this different from asking my AI tool to review its own code?

The tool that wrote the code reasons about intent. PushFix looks at what actually shipped: the responses, headers, bundle contents and pages a visitor receives. That is the difference between an account of the code and a statement about the running product.

What does it cost?

Your first review is free and needs no card. Paid plans exist for regular reviews, larger sites and more projects, and past a plan's allowance you keep auditing at the plan rate rather than being blocked. The plans page has the current numbers.

From early users

They found it before their users did

PushFix is used by solo builders and small teams who write with an AI assistant and review late. This is the kind of thing that comes back.

We pushed at eleven at night and the pricing page still said “Company Name” with lorem ipsum underneath. I had read that section so many times that I had stopped seeing it. It was fixed ten minutes after the report came back.
Sarah Bennett
PushFix found our checkout key sitting in a client bundle. It gave me the exact chunk URL and the line it was on, which is the only reason I believed it instead of assuming a false positive.
Daniel Meier
Nobody on the team had clicked the password reset link since launch. It returned a 404. One finding, and it paid for the year.
Ana Rodrigues
Our date picker could not be reached with a keyboard at all. We would never have caught that ourselves, because all four of us work with a mouse.
Marcus Bell
Every provider page had the same title tag. PushFix said it was a duplicate-title problem and listed the pages, so I fixed it in one commit instead of guessing at metadata for a week.
Elena Novak
The recheck is what convinced me. Fix the thing, hit recheck, and it either comes back verified or shows me the same evidence again. No guessing about whether the fix actually landed.
Cian Murphy
Start today

Ship fast.
Check it before your users do.

Point it at your staging site. The first review is free, and your source code is never read.

Worst case, a review finds nothing and you have spent ten minutes learning your app is clean.

Prefer to look around first? Compare plans