CodanopySecurity scanning for AI-generated apps
Security scan for AI-generated code

Your app shipped fast. Find out what it left open.

Point Codanopy at a repository and it runs a multi-analyzer static review plus an AI pass that reads across files. The scan itself is free, every time. You get a score, a summary, and a severity breakdown of everything found.

The scan is free. Every time.
Score, summary and severity counts cost nothing. Payment unlocks the explanations and the fixes — never the scan.
No account. No password.
There is no dashboard and no signup step. Your email is a delivery address, nothing more.
Your report has its own URL
Public but unlisted: anyone with the link can read it, search engines can't find it. Built to forward to a client.
$49 per report, one time
Not a subscription. Not per seat. One payment unlocks one report, forever.

What we look for

Secrets in source and history
API keys, tokens and private keys, including ones deleted from the working tree but still reachable in git history.
Known-vulnerable dependencies
Published advisories against your dependency tree, direct and transitive, across every ecosystem we detect.
Insecure patterns in your code
Debug modes left on, unparameterised SQL, permissive CORS, unsafe subprocess calls and weak hashing.
Configuration that opens the door
Container and infrastructure files are read for settings that expose more than you meant to.

What the AI pass finds that rules can't

Pattern matchers look at one file at a time. Most of the damage in an AI-generated app comes from how two files relate to each other — and that is structurally invisible to a rule.

Broken authorization and IDOR
The route checks that you're logged in, then hands back a record that belongs to someone else. Requires reading the handler and the query together.
Missing rate limits where it counts
Absence of a middleware is not a pattern. We look at which routes exist — login, signup, checkout — and which of them are unprotected.
Client-side trust of server-side logic
Price, role or quota decided in the browser and accepted by the API. Both halves look reasonable alone.
Prompt-injection surface
If your app calls an LLM, we trace where untrusted text enters the prompt and what the model is allowed to do once it's there.

Stacks supported

JavaScript / NodePythonPHPJavaKotlinScalaRustGoRuby.NET

Docker and Terraform files are detected and read for configuration issues. The stack is worked out from your files — you don't declare it.

Limits, stated plainly

20 MB
of scannable source per repo, and at most 5,000 source files.
50 MB
maximum ZIP upload size.
3 / hour
and 10 per day, per person. Enough to re-scan after a fix.

How the score works

Findings are weighted by severity into a score from 0 to 100, then given a letter. The same repo always scores the same way.

A
90 – 100
B
75 – 89
C
60 – 74
D
40 – 59
F
below 40
75maximum, hard ceiling

One CRITICAL finding caps the score at 75 — a B at best.

No amount of clean code buys back an A while a live secret is in your repo. If you see a B or lower with a CRITICAL present, the cap is why — and clearing that one finding is the fastest possible score change.

We would rather show you an honest C than a flattering A. A score you can game is a score a client can't trust.

Learn more

How it works
What happens between submitting your code and getting a report.
AI-generated code risks
The specific bug categories that recur in AI-generated apps, and why.
FAQ
Data handling, refunds, rate limits, and what happens to uploaded code.