opendev
v0.1.0

Know if your SaaS is ready to launch.

Paste a URL. Get one prioritised report: what is broken, how serious it is, why it matters, and how to fix it.

Public URL only. No repository, no credentials, no integration.

What a scan covers today

Availability

DNS, HTTPS, redirects, and the status your visitors actually get.

6 checks

Security posture

Headers, source maps, and privileged keys in your bundle.

10 checks

Performance & quality

Load metrics, console errors, broken links, mobile.

no checks yet

SEO & sharing

Titles, canonicals, Open Graph, robots, sitemap.

8 checks

24 checks run on every scan. Anything OpenDev cannot verify is reported as Unknown, never as passed.

Every finding answers four questions

Illustration below — not a real scan.

Criticalsecurity
A privileged Supabase key is exposed in your JavaScript
A key that bypasses row level security is readable by anyone who opens your bundle.
/_next/static/chunks/main-4f9c.js:1
sb_secret_••••••••••••••••  (sha256:9f3c1a…)

How to fix. Move the key to a server environment variable, rotate it in the Supabase dashboard, and redeploy.

Passing checks are shown tooSo is anything we could not verify

Non-intrusive by design

OpenDev only looks at what any browser could already see. No exploitation, no credential guessing, no load testing. Your report is private to your account unless you choose to share it.

OpenDev — Is your SaaS ready to launch?