/tools · 7IT Guard · with Bolt.new

Using Bolt? 7IT Guard checks and watches your Bolt app.

Bolt builds and hosts the app. 7IT Guard checks what the live app serves, from the outside, and Guard Pro keeps watching it after every publish.

7IT is not affiliated with or endorsed by StackBlitz. Bolt.new is a trademark of its owner.

Get started now

Install it and run it, from where you work today.

  1. Open Claude Code

    Bolt.new runs in your browser; Claude Code runs on your computer. Open it in a terminal, in VS Code or Cursor with the Claude Code extension, or in the Claude desktop app. (Cloud sessions in the browser do not load plugins you installed.) Source: code.claude.com

  2. Install 7IT Guard

    Add the marketplace and install the plugin. It needs Node.js 18 or newer and nothing else; no account.

    /plugin marketplace add XLSV777/7it-guard /plugin install 7it-guard@7it-guard
  3. Find your Bolt.new app’s live address

    In Bolt, click Publish at the top right, then Publish again. After about a minute a link appears in the chat: your site on a .bolt.host address. Source: support.bolt.new Published to Netlify instead (the option for new projects, and the default before August 14, 2025)? Use the Netlify address. Source: support.bolt.new

  4. Run the check

    Run the command with your address, or ask Claude: "Is my app at your-app.bolt.host ready to ship?" You get a grade, a score per category, a ranked fix list and a link to the visual report.

    /7it-guard:check your-app.bolt.host

Cursor, Codex and ChatGPT plugin listings for 7IT Guard are coming soon. Until then, Claude Code is the way in.

Unlock the deep checks

Show it is your app.

The deep checks run only on an app that carries your ownership token. The token is inert: it only proves you can change the app. The report prints it.

  1. Ask Bolt in the chat to add the meta tag the report printed to the head of the home page, or to serve the token as a file at /7it-verify.txt, then publish again.

  2. Prefer to edit it yourself? Switch from Preview to Code view. Where the tag goes depends on the framework Bolt chose for the project (for a Vite project: index.html and the public folder). In Safari, Code view is read-only. Source: support.bolt.new

  3. Run the check again. Claude adds --owner once you say the app is yours.

<meta name="7it-site-verification" content="7it-verify-...">
On Bolt.new

What it catches on your stack.

Guard Pro, opening soonThe site going offline at a usage limit

On Bolt hosting’s entry plan a site stops serving content once its monthly bandwidth or requests run out and stays offline until usage resets; with a spending cap, it pauses at the cap. Guard Pro notices within minutes that the app stopped answering. Source: support.bolt.new

Guard Pro, opening soon"Site not available" on Netlify

On Netlify’s credit-based plans every site pauses when the credits run out and visitors see a "Site not available" page. Guard Pro recognises that page and says what it means. Source: docs.netlify.com

7IT GuardMissing browser protections

Security headers, a public source map, mixed content: what any visitor’s browser receives.

7IT GuardExposed data and keys

On your own app: settings files, keys in the code sent to browsers, and what an anonymous visitor can read in a Supabase or Firebase backend.

After launch

Guard Pro keeps watching your Bolt.new app.

Checks every 5 minutes from outside, what changed at every publish in plain words, bill blowup checks, provider outage alerts and the control room app on your phone. It opens soon.

Questions

Bolt.new and 7IT Guard.

Does Bolt run 7IT Guard for me?

No. Bolt builds and hosts; you run 7IT Guard from Claude Code on your computer against the live address.

Which address do I check, .bolt.host or Netlify?

Whichever one visitors use. If you added your own domain, check that.

Will Guard Pro send traffic that uses up my plan?

Guard Pro asks for the home page every 5 minutes, a few small requests at a time, and never runs a load test. It counts toward requests like any visitor would.