2
0 Comments

Solo devs, I've been reviewing your products, some of you are not ok..

Trigger warning : this post WILL be pitching a product. it is both self-serving as well as serving you.

I've been doing the thing I probably should have warned you I was going to do. I've been running audits on products people post here. A lot of them (28 so far).

Folks, some of you are shipping things that should not be shipping. I know I know, these are mostly MVPs, but to hear you in your posts you sound so happy with it. and some of you really have nailed it (especciallly those with teams, and Dev-ops backgrounds, or engineering - your sites and products are really awesome and I sincerely wish I could get my products there) But I'm delusional, I know the limitations. For the rest you, I mean... you have missing security headers, exposed data surface, no HTTPS enforcement, Content-Security-Policy not configured, X-Frame-Options missing, the kind of stuff that makes an ISMS auditor physically uncomfortable. I spent the past few years doing information security consulting and keeping myself up to date (and that's not even my original career - I just fell in love with cybersecurity waaaay too late in my life).

I want to be clear: I'm not here to shame anyone. I'm exactly... well, almost exactly like some of you. Maybe around 75%.. "wow I can build a thing in my head", alone - with no 8-person full-stack team. It can be done over a couple of days (terrible statistic by the way; so many shit products), you're trying to get to market before you run out of motivation.. so, security headers are not the thing that keeps you up at night. I get it. But they should at least be on your list. (I don't mean to just harp on about security, there's many other things as well).

Here's roughly what I've seen across the audits I've run: like I said earlier, products above 90/100 are almost all built by engineers with teams. Products 75 and below are almost all solo builders. (in between is likely solo builders who probably spent loads of time on quality - well done you!) To be clear, the gap is not "intelligence" or "effort" (even though I just said that, but I mean in general). It's just that engineers have the muscle memory for this stuff and the rest of us don't.

(now the plug, but seriously, it'll help you) CanIShip has come a long way since I posted. The tool audited itself at 75/100 when I first launched. It's at 96 now (I fixed what it found on itself, which felt right). The reports are more detailed, the scoring is more calibrated, and I am still working on the Docker self-hosted option which I think will be great for those of us who can't send our app URLs to a third party service. That last one is in alpha, I'm not happy with it at the moment because I think it needs to be more feature rich.

If you've shipped something and haven't run a real QA pass on it, go do it. Use CanIShip, use something else, use a checklist, use whatever. Just run the check. In my ops world, a product that's live (and in your case collecting real users info and hopefully money) deserves to at least have the same quality gate you'd apply to anything physical before it leaves the warehouse. Otherwise you are just the Temu product quality of the app world, and once your credibility is hit, you can forget about future products doing well.

I built this for me. But like i said above, "I'm exactly... well, almost exactly like some of you. Maybe around 75% ":). So I figured, you also need help like me. It's at caniship.actvli.com. The free audit covers enough to tell you whether you have a problem. The builder version is where I tested most of you nd you landed at betwee 55-75. The studio version I used to test the products made by the engineers. (when I used studio on some of you.. well, it prompted me to write this (below 40 with a big "do not ship").

And if you're one of the products I audited that scored well, genuinely, good work. You care about the craft and it shows.

posted toAvatar for product CanIShip
CanIShip