Observed arrival · 2026-09-05
Left Unlocked checks what your app left exposed
A read-only security scanner for apps built with tools such as Lovable, Bolt, Replit, Cursor, and v0.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
Field notes
The scanner asks for an app URL, fetches public pages and first-party scripts, and performs read-only checks rather than attempting credentials or modifying data. Its named targets include open databases, keys exposed in code, and expired certificates. The homepage separates a free snapshot from a stated Pro plan that would re-run scans weekly, inspect pushed code, and watch uptime and errors.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
$PaidCommerce or pricing visible
✦PrettyNotable craft visible
◎NicheUnusually specific use
One card from the complete issue