Is your app ready to ship?
7IT Guard is a Claude Code plugin. Point it at your deployed app and it checks eight categories from your own machine, grades the app, and tells Claude what to fix before you ship and what can wait. Made for apps built with Lovable, Replit, Bolt, v0, Cursor or Claude Code.
Runs on your machine and reads only what the public internet sees. Nothing is sent to 7IT. No account, nothing to set up.
Eight categories, one grade
Every category gets a score out of 100 and the app gets a grade from A to F; anything exposed right now caps it. The findings are ranked into two lists: fix before shipping (something is exposed or broken now) and fix soon (hardening, speed, accessibility, search).
HTTPS and the http-to-https redirect, HSTS, Content Security Policy (and whether it still allows inline scripts), clickjacking and MIME-sniffing protection, referrer and permissions policy, cookie flags, mixed content.
every appA public JavaScript source map; on your own app, keys shaped like OpenAI, Anthropic, Stripe, GitHub, AWS or a Supabase service key in the code sent to browsers, reported by type and file, never the value.
every app, deeper on yoursAn .env file, a .git folder, backups and admin tools, and what an anonymous visitor can read in the app’s Supabase or Firebase project: table and bucket names with row counts, never contents.
your own appSPF, DKIM and DMARC on the app’s own domain, so its mail lands and nobody can send as it. Skipped on shared addresses such as myapp.lovable.app.
every appTime to first byte, HTML weight, compression, script weight, render-blocking scripts and caching. Google PageSpeed too, with your own key.
every appPage language, image text alternatives, form labels, button and link names, zoom and landmarks. Contrast cannot be judged from outside, and the report says so.
every appTitle, description, canonical, link previews, a noindex left on from development, robots.txt and the sitemap.
every appHome page status, certificate validity and expiry, redirect chains, real 404s, and whether www and the bare domain both answer.
every appInstall
In Claude Code, add the marketplace and install the plugin. The check is one readable Node script inside the plugin, with no dependencies; it needs Node.js 18 or newer and nothing else. Already have the 7Maps marketplace? It lists 7IT Guard too: /plugin install 7it-guard@7maps.
- Add the marketplace and install
/plugin marketplace add XLSV777/7it-guard /plugin install 7it-guard@7it-guard - Check an app
Use the command, or just ask Claude whether your app is ready to ship. The report ends with a link to the full visual report: scores, the fix list with ready snippets for your platform, and a save-as-PDF button. The results travel inside the link, after the "#", which browsers never send to a server.
/7it-guard:check myapp.com - Unlock the deep checks on your own app
The report prints an inert token. Add it to the home page as a meta tag (or as a file at /7it-verify.txt), deploy, and run the check again: Claude adds --owner, and the report includes exposed files, keys in the browser code and the database. Claude adds the token only when you say the app is yours.
<meta name="7it-site-verification" content="7it-verify-..."> - Fix, then check again
The fix command works through the findings in your repository, most severe first, and asks before every change. What lives outside the code (a key to rotate, a database policy, a DNS record) comes to you as exact steps.
/7it-guard:fix
No Node? Any MCP client can use the hosted fallback, https://7it.co.il/mcp?set=guard, which runs the public checks on 7IT’s server instead. Source and issues: github.com/XLSV777/7it-guard. Formerly named Ship Check.
Apps that talk to AI agents
If your app publishes an MCP server, a server that AI agents connect to, 7IT Guard finds it (a server card, an AI catalog or an answer at /mcp) and the report says whether it is on 7Maps, the public map of MCP servers, with a link to its page there.
The report links the server’s 7Maps page, where agents check whether it answers and what its tools can do before they connect. If the server is yours, verify ownership on 7Maps so agents see it is yours.
The report says so and points to the page where its owner can add it. The address is never sent to look it up: 7IT Guard compares a one-way code on your machine.
What a report looks like
In the terminal: the grade, a score per category, then plain words, most important first. The full report link opens the same results as a visual page. See the sample.
7IT Guard 0.3.0 · app.example.com · 2026-10-04 · run on this machine, nothing about the app sent to 7IT Grade F (41/100) · 3 to fix before shipping · 8 to fix soon Security 61 ██████░░░░ 2 issues Data exposure 20 ██░░░░░░░░ 3 issues Secrets 75 ████████░░ 1 issue Email 78 ████████░░ 1 issue ... Fix before shipping 1. CRIT Data exposure: Anyone can read the table "profiles" (1,204 rows). Turn on Row Level Security for this table ... 2. HIGH Secrets: A JavaScript source map is public. Stop publishing .map files ... 3. HIGH Data exposure: Anyone can list the files in the bucket "avatars". ... Fix soon 4. MED Security: No Content Security Policy. ... 5. MED Email: example.com has no DMARC record ... ... MCP server published by this app (for AI agents): https://app.example.com/mcp: not on 7Maps yet. Its owner can add it: https://7it.co.il/7maps/submit/ Requests: 42 from this machine to app.example.com, xyz.supabase.co, 7it.co.il, plus public DNS. 3.2 s. Full report: https://7it.co.il/tools/guard/report/#r=... Not checked from outside: load and traffic spikes, scale limits, architecture, ... A senior review covers these: https://7it.co.il/services/ai-built-apps/
What it sends, and what it never sends
The plugin is a Node script, a skill, two commands and a small local server for the optional 7IT key. It has no hooks. Every check runs on your machine.
- From your machine straight to the app you name, and to public DNS for its email records.
- With --owner, on an app that carries the token: to the Supabase or Firebase project the app’s own code points at, read-only.
- The report ends with the count of requests and the hosts they went to.
- Nothing about the app, by a check: not the address, not the results, not your code.
- Only when the app publishes an MCP server: one download of a small public 7Maps list, named by two characters of a one-way code, never the address. --no-7maps skips it.
- The report link keeps the results after the "#", which browsers never send. Analytics on the report page records the address without it.
Optional. One 7IT key will unlock both 7IT plugins, 7IT Guard and 7Maps; the setting names in each plugin stay as they are. 7IT Guard Pro is coming. Only if you set a key, and only when /7it-guard:fix asks for the strict playbook: one request to 7it.co.il with the key, the finding ids (such as csp_missing) and the platform names (such as vercel). Never the app’s address or the report. 7IT counts uses per key and keeps no report.
The first 4 KB of well-known file paths, matched on shape and reported as a path; the app’s scripts in memory, with any key reported by type and file, never its value; table and bucket names with row counts, never a row. Nothing is written or kept.
Full detail: Privacy Policy.
Remove it
/plugin uninstall 7it-guard@7it-guard
/plugin marketplace remove 7it-guardInstalled from the 7Maps marketplace? Use /plugin uninstall 7it-guard@7maps instead; the 7Maps plugin stays. If you added a verification token to your app, delete the meta tag or the /7it-verify.txt file. Nothing else is left behind.
7IT Guard sees what the public internet sees. It is not a penetration test and cannot see pages behind a login; automated accessibility checks cover only part of WCAG. Load, scale, architecture, cost, backups and compliance are out of its sight; a senior review covers them. Prefer a browser? Run the app security check; the same ownership token unlocks its deep scan.