FREE · NO SIGNUP · APACHE 2.0 · YOUR URL NEVER LEAVES OUR WORKER

Paste a URL. Get a security grade.

Free public scanner for AI-built web apps. Built for projects deployed from Lovable, Bolt, v0, Cursor, Replit, or Claude Code — but works on anything public. Takes about 30 seconds.

⏳ Public scanner goes live Jul 6, 2026. Until then, paste your URL and we'll email you the scorecard the day it's ready — plus a heads-up if anything serious turns up before then.

Here's what a scorecard looks like.

Below is the live scan of lictorai.com itself. We scan ourselves first, publicly. Our findings are public. That's the contract.

See the full scorecard for lictorai.com →

How it works.

1

You paste a URL.

Any public web app. No login, no GitHub install, no signup.

2

A Cloudflare Worker scans it.

Our 7-check Rust engine, compiled to WebAssembly, runs against your URL in about 30 seconds. The same engine that runs in /lictor-security-check and the Shield browser extension.

3

You get a letter grade.

A through F. Plus the 5 worst findings in plain English, with a 5-minute fix for each. Shareable. Re-runnable as you fix.

What we do with your scan.

It's free. Forever.

Lictor's core is open source under Apache 2.0. The scanner runs on Cloudflare Workers ($30/month at our projected volumes) and a domain (one-time). The audit corpus, the public scorecards, the leaderboard — all free.

If Lictor helps you ship a safer app, the world treats back the same:

For commercial use with continuous monitoring + Slack alerts + audit log export, Lictor for Teams is $19/month flat, unlimited seats. No per-seat pricing, ever. (Learn more on the home page.)