AI handed everyone a codebase. Nobody handed them a reviewer.
Generation optimises for the happy path: the first click, the demo, the screenshot. The gaps surface later, in production, in front of real users. These are the failure modes we kept finding.
- Free during early access
- No credit card
- Staging-first
- Evidence for every finding
The ways generated software specifically breaks
284 checks exist in total, and 26 of them target these patterns directly. They are the reason PushFix was built.
The model fills every gap
Ask for a landing page and you get headlines, a pricing table and a testimonial. Some of it is real and some of it is a plausible placeholder. Nobody can tell which at a glance, and the placeholder ships.
The UI is the specification
If the prompt says “admin users can delete projects”, the model renders a button for admins. Whether the endpoint behind it re-checks the role is a second, separate question the model rarely answers.
Configuration arrives from the demo
Sandbox keys, a seeded admin login and sample customer rows are what made the demo work. They are left switched on because the app only ever ran in the happy path.
The second click was never tested
Signup works from an empty database. The moment a real record exists, the unique constraint fires, the flow loops, or the page 404s. The first run is not a test.
What these look like on the live site
Each of the four patterns above shows up as concrete, findable defects. These are the ones we see most.
Placeholder copy in production
Lorem ipsum, “Company Name”, TODO markers and dummy pricing still on the homepage, because the model filled the gaps and nobody replaced them.
Auth that exists only in the UI
The admin button is hidden from non-admins, but the endpoint behind it never checks the role. Hiding something is not authorizing it.
Test keys and demo data shipped
Sandbox API keys, a seeded admin login and sample customer records, all reachable from the browser bundle.
Flows that break on the second click
Signup works from a clean state, then 404s, loops or loses state the moment real data exists.
PushFix is not a code reviewer. It finds these by looking at the running app, the same way a visitor or a curious attacker would. See how that works.
Did any of these
ship with your app?
Enter a URL and PushFix will tell you which of these failure modes are present, with the evidence to prove it.
Prefer to look around first? Compare plans