FlawPilot
Claude Code scanner

Claude Code edits across your repo. It doesn't check what your URL exposes.

Claude Code ships features from your terminal fast. External security posture is a different question. FlawPilot scans your live app from the outside: 13 tools, fast results, no setup required.

Free. No login. Works on any publicly accessible URL.

01

You prompt Claude Code

Add Stripe billing and an admin dashboard to my app.

02

Claude Code ships it

Next.jsNode.jsPythonGoLive
03

FlawPilot scans

3 findings
  • DNS misconfiguration - takeover risk
  • Missing security headers
  • Permissive CORS policy
13 tools
vulnerability scanning, DNS, TLS, headers, ports, and more
Fast results
scan-to-report in minutes
Plain English
findings, or full technical detail if you want it
Shareable
send your results to customers or your team
The gap between fast shipping and secure shipping

A great diff isn't the same as a hardened deployment.

Claude Code is a genuine accelerator: it plans, edits across files, runs commands, and ships working changes from your terminal. That velocity is the benefit.

The risk is what accumulates alongside that speed: configuration decisions under time pressure, dependencies added on suggestion, and API surfaces that looked clean in development.

External security posture - DNS, TLS, HTTP headers, email authentication, exposed ports - is separate from code quality and isn't something a code review catches. It's something an external scanner catches.

FlawPilot is that external scanner. It doesn't read your repo. It does exactly what an attacker or an enterprise security team would: hit your production URL and see what comes back.

What Claude Code left exposed

4
Security
HighSecurity

DNS misconfiguration and subdomain takeover

Subdomain takeover risk, dangling CNAME records, and misconfigured nameservers. These don't show up in a linter - they show up in an external scan.

HighSecurity

Cloud storage exposed to the public

Public access on storage buckets. One misconfigured bucket can expose your entire data layer.

HighSecurity

Missing HTTP security headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Missing headers are the most common finding across all app types.

MediumSecurity

Overly permissive CORS

A frequent finding in apps where the API layer was added quickly. We check your cross-origin policies for over-permissive configurations.

A real scan surfaces these the way an attacker or enterprise customer would - before they do.

How it works

External scan. Real results. Fast.

One URL in, a plain-English report out. Every step is bounded and observable, so you always know where you are.

Live pipeline
01
Enter your production URL
The URL where your app lives. No credentials, no code access, no integration to install.
02
13 tools run in parallel
Vulnerability signatures, security headers, TLS configuration, DNS checks, port scanning, email authentication, storage exposure, technology fingerprinting - all simultaneously, all against your live application.
03
Results in your preferred view
Founder view for a plain-English risk summary. Developer view for CVSS scores, tool attribution, and technical detail.
Done
What we scan

What FlawPilot checks on a Claude Code project

Claude Code apps span Next.js, Node, Python, Go, and more. Our scan is stack-agnostic: we check what's externally visible regardless of what's underneath.

Vulnerability Signatures

Nuclei matches your exposed endpoints and headers against 50,000+ known CVE patterns. Flags known vulnerabilities in the frameworks and libraries your stack exposes.

Security Headers

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy. Missing headers are the most common finding across all app types.

TLS / SSL Configuration

Certificate validity, cipher suite strength, protocol version, mixed content. The full TLS picture.

Email Authentication (SPF, DMARC, DKIM)

Checks whether your domain is protected against spoofing. Missing DMARC means anyone can send email as your company.

Open Ports and Exposed Services

What's listening on the public internet that shouldn't be. Development ports, internal APIs, and admin interfaces that followed the app to production.

DNS Configuration and Subdomain Discovery

Subdomain takeover risk, dangling CNAME records, misconfigured nameservers.

CORS Configuration

Cross-origin policies. Overly permissive CORS is a frequent finding in apps where the API layer was added quickly.

S3 and Cloud Storage Exposure

Public access on storage buckets. One misconfigured bucket can expose your entire data layer.

WAF Presence

Whether a web application firewall is in front of your app.

Technology Stack Fingerprinting

What your app reveals about its underlying stack to anyone who looks.

Cookie and Session Security

Secure, HttpOnly, and SameSite flags. Session fixation and cookie theft risks.

HTTP Request Behavior

Redirect chains, HTTP to HTTPS enforcement, response header hygiene.

Frontend HTML Checks

Inline script patterns, sensitive data exposure in rendered source.

Two views, one scan

You're technical. Your customers have their own security team. One scan serves both.

Every finding is written twice. Flip the toggle on your report to read it as a founder or as the developer who'll fix it - same scan, same data, two registers.

Simple, business-friendly explanations.

Missing security headers

Your site is missing headers that browsers use to block common attacks. In plain terms: a visitor’s browser can’t fully protect them on your site, which is an easy fix and a bad look in a security review.

Questions about scanning Claude Code-built apps

No. FlawPilot never touches Claude Code, your Anthropic account, or your codebase. It only checks publicly accessible signals on your deployed URL - the same things any browser or bot can already see.

Claude Code scanner

You ship fast. This check takes minutes.

External security posture is separate from code quality. FlawPilot gives you the outside-in view: what an attacker or enterprise customer sees when they hit your production URL.

Scan my app, free

No login. No credit card. Any publicly accessible URL.