waitlist · opening soon
See what your app shows to anyone.
For people who built an app with Lovable, Bolt, Replit or Supabase and never locked the door. ehopent shows the confirmed flaw with proof on your own domain, keeps what is still a suspicion apart, and gives you the fix step by step, ready for your AI.
GET https://seu-app.com/.env → 200 DATABASE_URL=post… (mascarado) ● CONFIRMED · critical proof: open the address in your browser ○ PROBABLE · high if confirmed database access rules not tested yet
Illustrative example. The secret is never shown in full.
How it will work
You paste the address
We only look at what any visitor already receives: the page, the public files and the code the browser downloads.
We show a real flaw
Confirmed, complete, with an address on your own domain so you can open it and see for yourself.
You decide the rest
The deep test only runs with your written permission, which you can revoke at any time.
What ehopent refuses to do
- Add confirmed and suspected together to make up a big number.
- Use countdowns, threats or short deadlines to rush you.
- Test anything on your app without a recorded permission.
- Say everything is safe. We say what we looked at, and what we did not.
Why this exists
- 45% of AI-generated code fails security tests.
- Veracode, 2025
- 63% of app-builder users cannot code.
- market research, 2026
- Across 5,600 apps analysed: more than 400 secrets and 175 cases of exposed personal data.
- Escape.tech, 2025