/tools · ship check

Is your app ready to ship?

Ship Check is a Claude Code plugin. Point it at your deployed app and it checks eight categories from your own machine, grades the app, and tells Claude what to fix before you ship and what can wait. Made for apps built with Lovable, Replit, Bolt, v0, Cursor or Claude Code.

Runs on your machine and reads only what the public internet sees. Nothing is sent to 7IT. No account, nothing to set up.

Eight categories, one grade

Every category gets a score out of 100 and the app gets a grade from A to F; anything exposed right now caps it. The findings are ranked into two lists: fix before shipping (something is exposed or broken now) and fix soon (hardening, speed, accessibility, search).

Security

HTTPS and the http-to-https redirect, HSTS, Content Security Policy (and whether it still allows inline scripts), clickjacking and MIME-sniffing protection, referrer and permissions policy, cookie flags, mixed content.

every app
Secrets

A public JavaScript source map; on your own app, keys shaped like OpenAI, Anthropic, Stripe, GitHub, AWS or a Supabase service key in the code sent to browsers, reported by type and file, never the value.

every app, deeper on yours
Data exposure

An .env file, a .git folder, backups and admin tools, and what an anonymous visitor can read in the app’s Supabase or Firebase project: table and bucket names with row counts, never contents.

your own app
Email

SPF, DKIM and DMARC on the app’s own domain, so its mail lands and nobody can send as it. Skipped on shared addresses such as myapp.lovable.app.

every app
Performance

Time to first byte, HTML weight, compression, script weight, render-blocking scripts and caching. Google PageSpeed too, with your own key.

every app
Accessibility

Page language, image text alternatives, form labels, button and link names, zoom and landmarks. Contrast cannot be judged from outside, and the report says so.

every app
SEO

Title, description, canonical, link previews, a noindex left on from development, robots.txt and the sitemap.

every app
Reliability

Home page status, certificate validity and expiry, redirect chains, real 404s, and whether www and the bare domain both answer.

every app

Install

In Claude Code, add the marketplace and install the plugin. The check is one readable Node script inside the plugin, with no dependencies; it needs Node.js 18 or newer and nothing else.

  1. Add the marketplace and install
    /plugin marketplace add XLSV777/shipcheck /plugin install shipcheck@shipcheck
  2. Check an app

    Use the command, or just ask Claude whether your app is ready to ship. The report ends with a link to the full visual report: scores, the fix list with ready snippets for your platform, and a save-as-PDF button. The results travel inside the link, after the "#", which browsers never send to a server.

    /shipcheck:check myapp.com
  3. Unlock the deep checks on your own app

    The report prints an inert token. Add it to the home page as a meta tag (or as a file at /7it-verify.txt), deploy, and run the check again: Claude adds --owner, and the report includes exposed files, keys in the browser code and the database. Claude adds the token only when you say the app is yours.

    <meta name="7it-site-verification" content="7it-verify-...">
  4. Fix, then check again

    The fix command works through the findings in your repository, most severe first, and asks before every change. What lives outside the code (a key to rotate, a database policy, a DNS record) comes to you as exact steps.

    /shipcheck:fix

No Node? Any MCP client can use the hosted fallback, https://7it.co.il/mcp?set=shipcheck, which runs the public checks on 7IT’s server instead. Source and issues: github.com/XLSV777/shipcheck.

What a report looks like

In the terminal: the grade, a score per category, then plain words, most important first. The full report link opens the same results as a visual page. See the sample.

Ship Check 0.2.0 · app.example.com · 2026-10-04 · run on this machine, nothing sent to 7IT
Grade F (41/100) · 3 to fix before shipping · 8 to fix soon

  Security        61  ██████░░░░  2 issues
  Data exposure   20  ██░░░░░░░░  3 issues
  Secrets         75  ████████░░  1 issue
  Email           78  ████████░░  1 issue
  ...

Fix before shipping
   1. CRIT Data exposure: Anyone can read the table "profiles" (1,204 rows).
      Turn on Row Level Security for this table ...
   2. HIGH Secrets: A JavaScript source map is public. Stop publishing .map files ...
   3. HIGH Data exposure: Anyone can list the files in the bucket "avatars". ...

Fix soon
   4. MED  Security: No Content Security Policy. ...
   5. MED  Email: example.com has no DMARC record ...
   ...

Requests: 41 from this machine to app.example.com, xyz.supabase.co, plus public DNS. 3.2 s.
Full report: https://7it.co.il/tools/ship-check/report/#r=...
Not checked from outside: load and traffic spikes, scale limits, architecture, ...
A senior review covers these: https://7it.co.il/services/ai-built-apps/

What it sends, and what it never sends

The plugin is a Node script, a skill, two commands and a small local server for the optional fix key. It has no hooks. Every check runs on your machine.

Where the requests go
  • From your machine straight to the app you name, and to public DNS for its email records.
  • With --owner, on an app that carries the token: to the Supabase or Firebase project the app’s own code points at, read-only.
  • The report ends with the count of requests and the hosts they went to.
Sent to 7IT
  • Nothing, by a check: not the address, not the results, not your code.
  • The report link keeps the results after the "#", which browsers never send. Analytics on the report page records the address without it.
The optional fix key

Only if you set one, and only when /shipcheck:fix asks for the strict playbook: one request to 7it.co.il with the key, the finding ids (such as csp_missing) and the platform names (such as vercel). Never the app’s address or the report. 7IT counts uses per key and keeps no report.

What a deep check reads

The first 4 KB of well-known file paths, matched on shape and reported as a path; the app’s scripts in memory, with any key reported by type and file, never its value; table and bucket names with row counts, never a row. Nothing is written or kept.

Full detail: Privacy Policy.

Remove it

/plugin uninstall shipcheck@shipcheck /plugin marketplace remove shipcheck

If you added a verification token to your app, delete the meta tag or the /7it-verify.txt file. Nothing else is left behind.

Ship Check sees what the public internet sees. It is not a penetration test and cannot see pages behind a login; automated accessibility checks cover only part of WCAG. Load, scale, architecture, cost, backups and compliance are out of its sight; a senior review covers them. Prefer a browser? Run the app security check; the same ownership token unlocks its deep scan.