Skip to content

Compare

ShipReady vs Reeve

A research-led scanner that has published a large-scale sweep of AI-built apps.

Last updated 2026-09-14

Reeve price: Not stated on the public pages read. Results gating: Not stated on the public pages read.

Facts about Reeve were read from their site on the dates shown. Tell us if something changed.

RowReeveShipReady
Score or evidence
Reeve

The public write-up reports finding categories and counts across the sample rather than a per-app score.

Source: https://reeve.page/ (read 2026-09-14)

ShipReady

No score, no grade, no badge. Every finding shows the request that produced it and the date it was read.

What they show and what they keep
Reeve

The research report is public. The public pages do not describe a self-serve scan for arbitrary URLs.

Source: https://reeve.page/ (read 2026-09-14)

ShipReady

The full free result is shown to anyone with the check id. Nothing is gated behind a paywall or an account.

What they do to your app
Reeve

Automated outside checks at research scale. The pages do not describe signing in as your users or executing your database functions.

Source: https://reeve.page/ (read 2026-09-14)

ShipReady

Deterministic outside requests only. Never signs in, never executes a function on your database, never reads another account's data.

What neither can see from outside

Neither an outside scanner nor a public research report can prove these from a URL. They need code, account, runtime or operational access.

  • Rollback and recovery. Whether you can put the previous version back, and how long that takes.
  • Error monitoring. Whether a failure in production reaches a human rather than sitting in a log nobody opens.
  • Sign in and account flows. Whether sign in, password or code reset, and session expiry behave under real use.
  • Rate limiting and abuse controls. Whether a script can hammer your forms, sign up loop, or paid endpoints without being slowed down.
  • Key rotation. Whether you can replace a leaked key quickly and know everywhere it is used.
  • Certificate expiry date. Whether the certificate is close to expiring. A normal request proves the certificate is valid right now, and the runtime this check uses cannot read the expiry date from that request.
  • One account reading another account's data. Whether a signed in account can reach another account's records by changing an id. ShipReady does not create accounts, sign in, or call your functions, so this cannot be answered from outside.
  • Payment handling. Whether payment events are verified, replay safe, and matched to the right customer record.
  • Customer data handling. Whether stored personal details are limited, deletable on request, and out of your logs.
  • AI feature controls. Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill.
  • Database row rules. Whether the row rules behind the app actually stop one signed in account reading another's rows.
Fixes
Reeve

The report describes issue categories rather than per-builder fix prompts.

Source: https://reeve.page/ (read 2026-09-14)

ShipReady

Every finding carries five fix prompts for Lovable, Bolt, Base44, v0 and generic coding assistants, hand written per finding.

Beyond security
CapabilityReeveShipReady
Legal page links
Email authentication
Domain expiry
Cookie flags
Platform trust evidence

Source: https://reeve.page/ (read 2026-09-14)

What happens next
Reeve

Read the report and cross reference the categories against your own build.

Source: https://reeve.page/ (read 2026-09-14)

ShipReady

You can stop at the free check, or buy the Release Gate at $49 for the package, the Launch Review at $199 for a person, or the Hardening Sprint at $1,750 for the fix work.

Competitor strengths

A public research report that puts numbers on how AI-built apps fail at scale, which is useful evidence for anyone shipping in this category.

Source: https://reeve.page/ (read 2026-09-14)

Choose Reeve if

You want a public research report to reference when you make the case for taking launch checks seriously, and you are not looking for a self-serve URL scan.

How our checks map to theirs

Reeve's report scanned 30,998 AI-built apps and grouped the failures they saw. Our sixteen check groups line up with the same recurring categories: exposed keys and server credentials in client code (their leaked secrets), open database rules and readable rows (their access control failures), public storage buckets and Firebase collections (their exposed storage), missing security headers and transport issues (their transport misconfiguration), and open sign-up with no confirmation (their account controls). Where the report names a class of failure, our check names the same class in the finding it produces.

ShipReady statuses explained

Observed means an outside request produced direct evidence.

Declared means the app owner supplied the information.

Not verified means the item needs code, account, runtime or operational access.

Could not check means the attempt did not produce a reliable answer.

Sources read for this page

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026