AI builders make it easy to ship a web app quickly. The follow-up work is less visible: checking what a normal visitor can see after launch.
I built Malinois for that narrow problem. You paste a URL for an app you own or have permission to test, and it runs non-invasive checks for public security headers, exposed configuration, client-side secrets, and data-store references. The report explains what it found in plain language. It does not exploit anything or scan private networks.
The first check is free and does not require a login. If you choose ongoing monitoring afterward, it checks the same public surface weekly.
I would value candid feedback from people who run AI-built apps:
• Is the report specific enough to act on?
• Which checks are useful, and which could be noisy or misleading?
• Would you use this for an app you actually operate?
For the first 20 owner-verified apps, there is one app of weekly monitoring for 30 days, with no card and no automatic billing. This is a limited feedback program, not a claim of traction.
Try the free owner-authorized check: https://malinois.app/?src=indiehackers&lang=en#scan