The things people ask before their first review
If your question is not here, the contact page reaches a person who can answer it.
- Free during early access
- No credit card
- Staging-first
- Evidence for every finding
Do you need access to my source code?
No. PushFix only looks at what a visitor or a signed-in user can see: pages, markup, bundle contents, network traffic, headers, DNS and TLS. Nothing is read from your repository and nothing is installed in your app.
Should I test staging or production?
Staging, preview or a test environment, always. PushFix detects production-looking URLs, warns you and stays conservative there. Active security testing belongs on an environment where breaking something does not affect real users.
Will testing break my application?
The catalogue is built so that it cannot. 71 checks are purely passive, 207 send their own read-only requests, and only 6 write anything, always to disposable records the audit itself created and only with explicit write consent.
What will PushFix never do?
No destructive payloads, no denial-of-service or load testing, no brute-forcing beyond the configured attempt cap, no social engineering, no contacting real users, and nothing at all against hosts you have not authorized. The full list ships with every report.
Do I have to give you credentials?
Only for the checks that need a signed-in view, and only if you want them. Add a dedicated test account on the project's Logins screen and the next review signs in with it and checks what that account can reach. Email and password works today, and so does a one-time code when your app accepts a fixed code for a test account, as a staging code usually does. A magic link or single sign-on has to be completed by you, so those accounts are recorded and the area behind them stays unreviewed. Without an account, those checks are skipped rather than guessed at.
How do you verify a leaked secret is real?
For a small allow-list of credential types that expose a read-only identity endpoint, PushFix makes a single non-mutating call and records only whether it authenticated. It never touches an endpoint that could write, send or cost money, and it only runs with active-testing consent.
What does a finding actually contain?
A stable ID, severity, the affected surface, the evidence that produced it, reproduction steps, an explanation of why it matters, a confidence score and a suggested fix you can hand straight to your AI tool.
Is PushFix a penetration test?
No, and it does not replace one. It is automated, external and non-destructive. It finds the classes of problem that automated review can prove and reports them with evidence; a manual penetration test goes further into business logic and chained exploits.
Still deciding? See how PushFix compares to the tools you already use or ask us directly.
Answers are good.
A review is better.
Create a project, answer a few questions about your app, and get an evidence-backed review with copy-paste fix prompts.
Prefer to look around first? Compare plans