ismycodesafe.com

Every scan is free. Pay if you want the fix plan or repeat scans.

You enter a URL, confirm your email, and the findings show up. The report turns them into a fix list for your developer. The monthly plan runs the same scan again every month and emails you the results, so you don't have to remember to.

Free scan

$0

See what an attacker sees from the outside.

  • 200+ external checks on a public URL: SSL/TLS, security headers, open ports, exposed files, DNS and email records
  • Server and JavaScript library versions matched against known CVEs
  • A-F grade and the full list of findings
  • Results link sent to your email after you confirm it

Only scan sites you own or have permission to scan.

One-off report

$29 one time

Your scan, turned into a fix list you can hand to a developer.

  • Every finding with a CVSS score and its OWASP Top 10 category
  • Step-by-step fix instructions, with the config or code snippet where one applies
  • A prioritized action plan, ordered by what to fix first
  • PDF download
  • Written by Claude AI from your scan data

Bought from your scan results page. Needs a finished scan with a confirmed email.

AI Coding Safety Checklist

From $19 one time

For people shipping code from Cursor, Claude Code or Copilot.

  • Basic ($19): 62-item PDF checklist and a before-you-deploy guide
  • Pro ($49): adds 18 prompts for your AI assistant and a GitHub Actions workflow that runs on every PR
  • Team ($99): adds a 5-seat license and a 30-minute Q&A call
  • Lifetime updates, 14-day refund

Monthly scan

$25 / month

A fresh scan of your site every month, without remembering to run it.

  • One full scan of your site each month, run when the payment goes through
  • An email with the results after each scan
  • Cancel from the link in your welcome email; it runs to the end of the month you paid for

Billed monthly through Stripe.

Not sure which one you need? Book a free 30-minute call and bring your scan result.

Frequently Asked Questions

What does the monthly scan check?
The same external checks as the free scan: certificate, headers, ports, exposed files, DNS and email records, and software versions we can see from the outside. It works from the outside only, with no login and no access to your source code.
When does the scan run?
Each time the monthly payment goes through, starting with the first one. The results arrive by email when the scan is done.
Does the plan cover more than one site?
No. One subscription covers the site you subscribed from. For a second site, start a scan of that site and subscribe from its results page.
What's the difference between the $29 report and the monthly plan?
The report is one snapshot with a written fix plan for every finding. The monthly plan gives you a fresh scan and the list of findings every month, without the written fix plan.
How do I cancel?
Use the cancel link in your welcome email. You won't be charged again.