Anon key
The public browser key. Safe to publish, useless without rules behind it.
Learn
44 terms that turn up on a result or in the work around it. No jargon defined with more jargon. Each one links to the findings and incidents where it matters.
The public browser key. Safe to publish, useless without rules behind it.
One instruction that fixes several findings in a single pass.
The unguessable string that lets you attach an anonymous result to your account later.
The header that tells the browser which code it is allowed to run.
The three settings that decide how safely a cookie travels.
The ceiling that stops one visitor spending your month's budget in an hour.
The request failed, so there is no result for that item.
The header that decides which other sites may read your responses.
Something you told us, recorded as your statement rather than our finding.
Something the check worked out about your app without being told.
The record that tells receiving servers what to do when mail fails your checks.
The date your domain registration runs out, published in the registry.
The record that says this account paid for this thing.
The line of raw observation behind a finding.
An address that answers when it should not.
What your app quietly tells the internet about how it was built.
A ready instruction for the tool that built your app.
The rule that stops another site putting your app inside an invisible frame.
The $1,750 engagement that takes the top items from needs fix to fixed and re-verified.
The header that tells browsers to never speak to your site over plain HTTP again.
Doing the same thing twice has the same effect as doing it once.
The $199 review where a named person looks at what a URL cannot see.
A dated page saying what was observed, what was declared, and what nobody verified.
A secure page loading something over plain HTTP.
Named items nobody checked, listed rather than quietly dropped.
Something a check actually read from your published app, with the evidence attached.
Whether anyone can create an account, and whether the address has to be proved.
Text your app feeds to a model that the model treats as instructions.
The newer name for a public client key. Same rule: public by design, not a permission.
The rule that slows down whoever is asking too often.
The monthly option that keeps a current statement for teams shipping every week.
The $49 package that hands you the checklist and the guardrails to fix things yourself.
Putting the previous version back, quickly, when the new one is wrong.
The rule that decides which rows of a table an account may read or change.
A database function that runs with its author's permissions rather than the caller's.
The key that ignores every access rule. It belongs on a server and nowhere else.
Registering the package names AI tools invent, and waiting.
The file that turns your shipped bundle back into readable source.
The DNS record naming who is allowed to send email as your domain.
How out of date an observation is, stated rather than hidden.
The place uploaded files live, and the setting that decides who can read them.
One customer's data staying entirely out of another customer's account.
A published page that answers the security questions buyers ask.
Proof that the message really came from the service that claims to have sent it.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026