https://shipreadyai.dev/compare/site-security-score

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# ShipReady vs SiteSecurityScore

A site-security grader that gives a URL a single score based on outside signals.

# ShipReady vs SiteSecurityScore
A site-security grader that gives a URL a single score based on outside signals.
Facts about SiteSecurityScore were read from their site on the dates shown. Tell us if something changed.
## Score or evidence
- **Them.** Presents a single overall score or grade for a URL as the headline output. Source: https://sitesecurityscore.com/ (read 2026-09-14).
- **Us.** No score, no grade, no badge. Every finding shows the request that produced it and the date it was read.
## What they show and what they keep
- **Them.** The score is shown on the site to anyone with the URL. Detail beyond the grade is not clearly gated on the pages read. Source: https://sitesecurityscore.com/ (read 2026-09-14).
- **Us.** The full free result is shown to anyone with the check id. Nothing is gated behind a paywall or an account.
## What they do to your app
- **Them.** Outside checks against the public URL. The pages do not describe signing in as your users or executing your database functions. Source: https://sitesecurityscore.com/ (read 2026-09-14).
- **Us.** Deterministic outside requests only. Never signs in, never executes a function on your database, never reads another account's data.
## What neither can see from outside
- **Rollback and recovery.** Whether you can put the previous version back, and how long that takes.
- **Error monitoring.** Whether a failure in production reaches a human rather than sitting in a log nobody opens.
- **Sign in and account flows.** Whether sign in, password or code reset, and session expiry behave under real use.
- **Rate limiting and abuse controls.** Whether a script can hammer your forms, sign up loop, or paid endpoints without being slowed down.
- **Key rotation.** Whether you can replace a leaked key quickly and know everywhere it is used.
- **Certificate expiry date.** Whether the certificate is close to expiring. A normal request proves the certificate is valid right now, and the runtime this check uses cannot read the expiry date from that request.
- **One account reading another account's data.** Whether a signed in account can reach another account's records by changing an id. ShipReady does not create accounts, sign in, or call your functions, so this cannot be answered from outside.
- **Payment handling.** Whether payment events are verified, replay safe, and matched to the right customer record.
- **Customer data handling.** Whether stored personal details are limited, deletable on request, and out of your logs.
- **AI feature controls.** Whether prompts, spend, and model output are bounded so one visitor cannot run up the bill.
- **Database row rules.** Whether the row rules behind the app actually stop one signed in account reading another's rows.
## Fixes
- **Them.** Grades and short explanations are shown. Public pages do not list per-builder fix prompts. Source: https://sitesecurityscore.com/ (read 2026-09-14).
- **Us.** Every finding carries five fix prompts for Lovable, Bolt, Base44, v0 and generic coding assistants, hand written per finding.
## Beyond security
  - Legal page links: them no, us yes
  - Email authentication: them no, us yes
  - Domain expiry: them no, us yes
  - Cookie flags: them no, us yes
  - Platform trust evidence: them no, us yes
  Source: https://sitesecurityscore.com/
## What happens next
- **Them.** Read the grade, share the score, and decide on remediation on your own. Source: https://sitesecurityscore.com/ (read 2026-09-14).
- **Us.** You can stop at the free check, or buy the Release Gate at $49 for the package, the Launch Review at $199 for a person, or the Hardening Sprint at $1,750 for the fix work.
## Competitor strengths
A single-number grade that is easy to hand to a non-technical stakeholder for a quick outside view of a URL.
## Choose them if
You want one easy grade to hand to a client or manager for a URL and you are not looking for evidence per finding or fix prompts you can paste back into a builder.
## Sources
- https://sitesecurityscore.com/

