Is your app ready to ship?
Ship Check is a Claude Code plugin. Point it at your deployed app and it checks eight categories from your own machine, grades the app, and tells Claude what to fix before you ship and what can wait. Made for apps built with Lovable, Replit, Bolt, v0, Cursor or Claude Code.
Runs on your machine and reads only what the public internet sees. Nothing is sent to 7IT. No account, nothing to set up.
Eight categories, one grade
Every category gets a score out of 100 and the app gets a grade from A to F; anything exposed right now caps it. The findings are ranked into two lists: fix before shipping (something is exposed or broken now) and fix soon (hardening, speed, accessibility, search).
HTTPS and the http-to-https redirect, HSTS, Content Security Policy (and whether it still allows inline scripts), clickjacking and MIME-sniffing protection, referrer and permissions policy, cookie flags, mixed content.
every appA public JavaScript source map; on your own app, keys shaped like OpenAI, Anthropic, Stripe, GitHub, AWS or a Supabase service key in the code sent to browsers, reported by type and file, never the value.
every app, deeper on yoursAn .env file, a .git folder, backups and admin tools, and what an anonymous visitor can read in the app’s Supabase or Firebase project: table and bucket names with row counts, never contents.
your own appSPF, DKIM and DMARC on the app’s own domain, so its mail lands and nobody can send as it. Skipped on shared addresses such as myapp.lovable.app.
every appTime to first byte, HTML weight, compression, script weight, render-blocking scripts and caching. Google PageSpeed too, with your own key.
every appPage language, image text alternatives, form labels, button and link names, zoom and landmarks. Contrast cannot be judged from outside, and the report says so.
every appTitle, description, canonical, link previews, a noindex left on from development, robots.txt and the sitemap.
every appHome page status, certificate validity and expiry, redirect chains, real 404s, and whether www and the bare domain both answer.
every appInstall
In Claude Code, add the marketplace and install the plugin. The check is one readable Node script inside the plugin, with no dependencies; it needs Node.js 18 or newer and nothing else.
- Add the marketplace and install
/plugin marketplace add XLSV777/shipcheck /plugin install shipcheck@shipcheck - Check an app
Use the command, or just ask Claude whether your app is ready to ship. The report ends with a link to the full visual report: scores, the fix list with ready snippets for your platform, and a save-as-PDF button. The results travel inside the link, after the "#", which browsers never send to a server.
/shipcheck:check myapp.com - Unlock the deep checks on your own app
The report prints an inert token. Add it to the home page as a meta tag (or as a file at /7it-verify.txt), deploy, and run the check again: Claude adds --owner, and the report includes exposed files, keys in the browser code and the database. Claude adds the token only when you say the app is yours.
<meta name="7it-site-verification" content="7it-verify-..."> - Fix, then check again
The fix command works through the findings in your repository, most severe first, and asks before every change. What lives outside the code (a key to rotate, a database policy, a DNS record) comes to you as exact steps.
/shipcheck:fix
No Node? Any MCP client can use the hosted fallback, https://7it.co.il/mcp?set=shipcheck, which runs the public checks on 7IT’s server instead. Source and issues: github.com/XLSV777/shipcheck.
What a report looks like
In the terminal: the grade, a score per category, then plain words, most important first. The full report link opens the same results as a visual page. See the sample.
Ship Check 0.2.0 · app.example.com · 2026-10-04 · run on this machine, nothing sent to 7IT Grade F (41/100) · 3 to fix before shipping · 8 to fix soon Security 61 ██████░░░░ 2 issues Data exposure 20 ██░░░░░░░░ 3 issues Secrets 75 ████████░░ 1 issue Email 78 ████████░░ 1 issue ... Fix before shipping 1. CRIT Data exposure: Anyone can read the table "profiles" (1,204 rows). Turn on Row Level Security for this table ... 2. HIGH Secrets: A JavaScript source map is public. Stop publishing .map files ... 3. HIGH Data exposure: Anyone can list the files in the bucket "avatars". ... Fix soon 4. MED Security: No Content Security Policy. ... 5. MED Email: example.com has no DMARC record ... ... Requests: 41 from this machine to app.example.com, xyz.supabase.co, plus public DNS. 3.2 s. Full report: https://7it.co.il/tools/ship-check/report/#r=... Not checked from outside: load and traffic spikes, scale limits, architecture, ... A senior review covers these: https://7it.co.il/services/ai-built-apps/
What it sends, and what it never sends
The plugin is a Node script, a skill, two commands and a small local server for the optional fix key. It has no hooks. Every check runs on your machine.
- From your machine straight to the app you name, and to public DNS for its email records.
- With --owner, on an app that carries the token: to the Supabase or Firebase project the app’s own code points at, read-only.
- The report ends with the count of requests and the hosts they went to.
- Nothing, by a check: not the address, not the results, not your code.
- The report link keeps the results after the "#", which browsers never send. Analytics on the report page records the address without it.
Only if you set one, and only when /shipcheck:fix asks for the strict playbook: one request to 7it.co.il with the key, the finding ids (such as csp_missing) and the platform names (such as vercel). Never the app’s address or the report. 7IT counts uses per key and keeps no report.
The first 4 KB of well-known file paths, matched on shape and reported as a path; the app’s scripts in memory, with any key reported by type and file, never its value; table and bucket names with row counts, never a row. Nothing is written or kept.
Full detail: Privacy Policy.
Remove it
/plugin uninstall shipcheck@shipcheck
/plugin marketplace remove shipcheckIf you added a verification token to your app, delete the meta tag or the /7it-verify.txt file. Nothing else is left behind.
Ship Check sees what the public internet sees. It is not a penetration test and cannot see pages behind a login; automated accessibility checks cover only part of WCAG. Load, scale, architecture, cost, backups and compliance are out of its sight; a senior review covers them. Prefer a browser? Run the app security check; the same ownership token unlocks its deep scan.