/tools · 7IT Guard · with Replit

Using Replit? 7IT Guard checks and watches your Replit app.

Replit builds, runs and publishes the app. 7IT Guard adds an outside look at what the published app serves: protections, exposed data, email and speed.

7IT is not affiliated with or endorsed by Replit. Replit is a trademark of its owner.

Get started now

Install it and run it, from where you work today.

  1. Open Claude Code

    Replit runs in your browser; Claude Code runs on your computer. Open it in a terminal, in VS Code or Cursor with the Claude Code extension, or in the Claude desktop app. (Cloud sessions in the browser do not load plugins you installed.) Source: code.claude.com

  2. Install 7IT Guard

    Add the marketplace and install the plugin. It needs Node.js 18 or newer and nothing else; no account.

    /plugin marketplace add XLSV777/7it-guard /plugin install 7it-guard@7it-guard
  3. Find your Replit app’s live address

    Open Publishing (under Replit Cloud in the Tools pane, or Publish at the top right of the Project Editor). Replit suggests a .replit.app address. Source: docs.replit.com The .replit.app name comes from the project name and can change if you unpublish and publish again; a custom domain stays put. Source: docs.replit.com

  4. Run the check

    Run the command with your address, or ask Claude: "Is my app at your-app.replit.app ready to ship?" You get a grade, a score per category, a ranked fix list and a link to the visual report.

    /7it-guard:check your-app.replit.app

Cursor, Codex and ChatGPT plugin listings for 7IT Guard are coming soon. Until then, Claude Code is the way in.

Unlock the deep checks

Show it is your app.

The deep checks run only on an app that carries your ownership token. The token is inert: it only proves you can change the app. The report prints it.

  1. Ask Replit Agent to add the meta tag the report printed to the head of the home page, or to serve the token at /7it-verify.txt, then publish again.

  2. Or open the file editor in the Project Editor and add it yourself. Where it goes depends on the stack (a Vite front end: index.html and the public folder). Source: docs.replit.com

  3. Run the check again. Claude adds --owner once you say the app is yours.

<meta name="7it-site-verification" content="7it-verify-...">
On Replit

What it catches on your stack.

7IT GuardBrowser protections and exposed files

Security headers, a public source map, settings files and backups a stranger could download.

7IT GuardData and keys

On your own app: keys in the code sent to browsers, and what an anonymous visitor can read in a Supabase or Firebase backend.

Guard Pro, opening soonWhat changed at each publish

Every deploy gets a snapshot: which security setting got weaker, worse first.

On an Autoscale deployment the app can scale down to zero when idle, and the first request after a quiet period can take a few seconds. A watch that checks every 5 minutes keeps it awake, so Guard Pro does not measure cold starts; it tells you this instead. Replit also offers its own uptime monitoring and a security scan before publishing; 7IT Guard is the outside view next to them. Source: docs.replit.com

After launch

Guard Pro keeps watching your Replit app.

Checks every 5 minutes from outside, what changed at every publish in plain words, bill blowup checks, provider outage alerts and the control room app on your phone. It opens soon.

Questions

Replit and 7IT Guard.

Replit already monitors my app. Why add Guard?

Replit tells you whether the app is online. 7IT Guard looks at what it shows the world: protections, exposed data, keys, email setup, and what changed at each deploy.

Can I run Claude Code inside Replit?

We have not verified that, so we do not suggest it. Run Claude Code on your computer (terminal, VS Code, Cursor or the desktop app) against the published address.

Which deployment type works?

Any that has a public address: Autoscale, Reserved VM or Static.