What is AtRisk?
AtRisk is a security scanner for apps built with AI coding tools like Cursor, Bolt, and Lovable. Paste a live URL to run over 100 checks and get a ship or block score. Connect GitHub for repo audits and pull request reviews, and hand each fix prompt to your coding agent.
Top Features:
- URL scans: over 100 checks cover headers, exposed secrets, redirects, and AI surfaces.
- Linked findings: live site issues are matched to the source file in your repo.
- PR reviews: qualifying pull requests get automatic checks for secrets, dependencies, and auth.
Use Cases:
- Pre-launch checks: scan a vibe-coded prototype before sharing it with real users.
- Key leaks: catch API keys committed to code or exposed in browser bundles.
- Deploy gating: fail CI builds when open critical risks remain in the codebase.
Who Can Use AtRisk?
- Non-technical founders: check AI-built apps for risks without learning security testing first.
- Indie developers: get ranked findings and fix prompts for Cursor or Claude Code.
- Small dev teams: review every pull request for risk and block unsafe production deploys.
Pricing
- Free Preview (free): an account shows finding counts, but the details stay blurred.
- Starter ($19 per month): launch price, normally $39, with 30 URL scans and 40 PR reviews.
- Pro ($39 per month): launch price, normally $59, with 250 scans and a CI gate.
Pros and Cons
Pros:
- One inbox: live URL, repo, and pull request findings sit in one place.
- Agent-ready fixes: paste-ready prompts and MCP access suit any AI coding workflow.
- Read-only scans: checks only touch public surfaces, so nothing on your site changes.
Cons:
- Paywalled details: full evidence and fix prompts need a Starter or Pro plan.
- No autofix: it suggests fixes but never opens fix pull requests itself.
- On-demand only: scans do not run on a schedule, so you start each one.
FAQs:
1) Do I need GitHub to start?
No, a public URL is enough, and repos can be connected later.
2) Is it a penetration test?
No, scans are read-only and never exploit or write to your app.
3) Does it work with Cursor?
Yes, copy fix prompts or pull findings in through MCP.
4) What is the ship or block score?
It turns the results of over 100 checks into one release signal.
5) Does it autofix code?
No, you or your coding agent apply fixes, then rescan.