Wolfix
myapp · scan completeRe-scanSettings

Your team has the full picture.

Eight blockers stand between you and your first paying customer. 23 issues to clean up at or after launch. 13 things you've already got covered.

myapp.lovable.app
scanned · 2 days ago
pre-revenue · taking payments soon
What each department asked

A department only reports on the checks it was able to run. The counts below are about the checks, not about your app — a check with no answer is unknown, not clear.

  • Legal asked all 12 of its checks. 4 of them could not reach an answer — that's unknown, not clear. asked 12 of 12 · answered 8
  • Security asked 4 of its 6 checks. 2 had no input to read: asked 4 of 6 · answered 2
    • error tracking — not asked: no result was recorded for this check.
    • data exposure — not asked: no Supabase project is connected.
  • Technology asked all 5 of its checks. asked 5 of 5 · answered 5
  • Brand asked all 6 of its checks. asked 6 of 6 · answered 6
  • Growth asked 4 of its 5 checks. 1 had no input to read: asked 4 of 5 · answered 4
    • SEO structured data — not asked: no result was recorded for this check.
  • Operations asked 5 of its 6 checks. 1 had no input to read: asked 5 of 6 · answered 4
    • onboarding flow — not asked: no result was recorded for this check.

Wolfix · summary

Here's where I'd start: Security 1 known vulnerability in a direct dependency (1 high). Security is flagging 22 known vulnerabilities in a direct dependency (2 critical, 11 high, 8 moderate, 1 low). Most fixes are queued and ready to generate. Tap any blocker to start.

Blockers

8 · fix before charging
blockerSecurity

1 known vulnerability in a direct dependency (1 high)

@clerk/nextjs@6.37.3 — 1 known vulnerability: - GHSA-w24r-5266-9c3c / CVE-2026-42349 (high) — Clerk has an authorization bypass when combining organization, billing, or reverification checks Fixed in 6.39.3. Remedy: upgrade @clerk/nextjs to 6.39.3 or later — npm install @clerk/nextjs@6.39.3.
from code
blockerSecurity

22 known vulnerabilities in a direct dependency (2 critical, 11 high, 8 moderate, 1 low)

next@15.5.12 — 22 known vulnerabilities: - GHSA-267c-6grr-h53f / CVE-2026-44575 (high) — Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes Fixed in 15.5.16.

- GHSA-26hh-7cqf-hhc6 / CVE-2026-45109 (high) — Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up Fixed in 15.5.18. - GHSA-2xp9-vwfh-vxw4 (critical) — Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used Fixed in 15.5.24. - GHSA-36qx-fr4f-26g5 / CVE-2026-44573 (high) — Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n Fixed in 15.5.16. - GHSA-3x4c-7xq6-9pq8 / CVE-2026-27980 (moderate) — Next.js: Unbounded next/image disk cache growth can exhaust storage Fixed in 16.1.7. - GHSA-492v-c6pp-mqqv / CVE-2026-44574 (high) — Next.js has a Middleware / Proxy bypass through dynamic route parameter injection Fixed in 15.5.16. - GHSA-4c39-4ccg-62r3 / CVE-2026-64646 (moderate) — Next.js: Unbounded Server Action payload in Edge runtime Fixed in 15.5.21. - GHSA-68g3-v927-f742 / CVE-2026-64648 (moderate) — Next.js: Cache confusion of response bodies for requests with bodies Fixed in 15.5.21. - GHSA-89xv-2m56-2m9x / CVE-2026-64649 (high) — Next.js: Server-Side Request Forgery in Server Actions on custom servers Fixed in 15.5.21. - GHSA-8h8q-6873-q5fj (high) — Next.js Vulnerable to Denial of Service with Server Components Fixed in 15.5.16. - GHSA-955p-x3mx-jcvp / CVE-2026-64643 (moderate) — Next.js: Unauthenticated disclosure of internal Server Function endpoints Fixed in 15.5.21. - GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (high) — Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades Fixed in 15.5.16. - GHSA-ffhc-5mcf-pf4q / CVE-2026-44581 (moderate) — Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces Fixed in 15.5.16. - GHSA-ggv3-7p47-pfv8 / CVE-2026-29057 (moderate) — Next.js: HTTP request smuggling in rewrites Fixed in 16.1.7. - GHSA-h64f-5h5j-jqjh / CVE-2026-44577 (moderate) — Next.js has a Denial of Service in the Image Optimization API Fixed in 15.5.16. - GHSA-m99w-x7hq-7vfj / CVE-2026-64641 (high) — Next.js: Denial of Service in App Router using Server Actions Fixed in 15.5.21. - GHSA-mg66-mrh9-m8jx / CVE-2026-44579 (high) — Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components Fixed in 15.5.16. - GHSA-p293-qw3h-jr36 / CVE-2026-75604 (critical) — Next.js: Unauthenticated Remote Code Execution on windows-hosted servers Fixed in 15.5.24. - GHSA-p9j2-gv94-2wf4 / CVE-2026-64645 (high) — Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname Fixed in 15.5.21. - GHSA-q4gf-8mx6-v5v3 (high) — Next.js has a Denial of Service with Server Components Fixed in 15.5.15. - GHSA-vfv6-92ff-j949 / CVE-2026-44582 (low) — Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting Fixed in 15.5.16. - GHSA-wfc6-r584-vfw7 / CVE-2026-44576 (moderate) — Next.js vulnerable to cache poisoning in React Server Component responses Fixed in 15.5.16. Remedy: upgrade next to 16.1.7 or later — npm install next@16.1.7.
from code
blockerSecurity

4 known vulnerabilities in a direct dependency (2 high, 2 moderate)

postcss@8.5.6 — 4 known vulnerabilities: - GHSA-6g55-p6wh-862q / CVE-2026-45623 (high) — PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments Fixed in 8.5.12.

- GHSA-fxqj-rqcc-2cmp / CVE-2026-69153 (moderate) — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset Fixed in 8.5.23. - GHSA-qx2v-qp2m-jg93 / CVE-2026-41305 (moderate) — PostCSS has XSS via Unescaped </style> in its CSS Stringify Output Fixed in 8.5.10. - GHSA-r28c-9q8g-f849 / CVE-2026-73646 (high) — PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure Fixed in 8.5.18. Remedy: upgrade postcss to 8.5.23 or later — npm install postcss@8.5.23.
from code
blockerSecurity

1 known vulnerability in a direct dependency (1 high)

sharp@0.34.5 — 1 known vulnerability: - GHSA-f88m-g3jw-g9cj (high) — sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 Fixed in 0.35.0. Remedy: upgrade sharp to 0.35.0 or later — npm install sharp@0.35.0.
from code
blockerSecurity

16 transitive dependencies with known vulnerabilities (27 high)

Transitive dependencies (pulled in by your direct dependencies) with known critical/high vulnerabilities: @clerk/backend@2.32.1 — 1 known vulnerability: - GHSA-w24r-5266-9c3c / CVE-2026-42349 (high) — Clerk has an authorization bypass when combining organization, billing, or reverification checks Fixed in 2.33.3.

Remedy: upgrade @clerk/backend to 2.33.3 or later — npm install @clerk/backend@2.33.3. @clerk/clerk-react@5.60.0 — 1 known vulnerability: - GHSA-w24r-5266-9c3c / CVE-2026-42349 (high) — Clerk has an authorization bypass when combining organization, billing, or reverification checks Fixed in 5.61.6. Remedy: upgrade @clerk/clerk-react to 5.61.6 or later — npm install @clerk/clerk-react@5.61.6. @clerk/shared@3.47.0 — 1 known vulnerability: - GHSA-w24r-5266-9c3c / CVE-2026-42349 (high) — Clerk has an authorization bypass when combining organization, billing, or reverification checks Fixed in 3.47.5. Remedy: upgrade @clerk/shared to 3.47.5 or later — npm install @clerk/shared@3.47.5. brace-expansion@1.1.12 — 2 known vulnerabilities: - GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 (high) — brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups Fixed in 5.0.7. - GHSA-mh99-v99m-4gvg / CVE-2026-14257 (high) — brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash Fixed in 5.0.8. Remedy: upgrade brace-expansion to 5.0.8 or later — npm install brace-expansion@5.0.8. browserslist@4.28.1 — 1 known vulnerability: - GHSA-c83g-rgw3-j3cx / CVE-2026-73089 (high) — Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM Fixed in 4.28.7. Remedy: upgrade browserslist to 4.28.7 or later — npm install browserslist@4.28.7. fast-uri@3.1.0 — 6 known vulnerabilities: - GHSA-7p8r-x3mc-p8w7 / CVE-2026-18446 (high) — fast-uri vulnerable to host confusion via backslash authority introducer Fixed in 2.4.4. - GHSA-f65p-4m7j-42xc / CVE-2026-75975 (high) — fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization Fixed in 2.4.5. - GHSA-jqff-g426-hqxp / CVE-2026-76172 (high) — fast-uri vulnerable to host confusion via percent-encoded scheme normalization Fixed in 2.4.5. - GHSA-q3j6-qgpj-74h6 / CVE-2026-6321 (high) — fast-uri vulnerable to path traversal via percent-encoded dot segments Fixed in 3.1.1. - GHSA-v2hh-gcrm-f6hx / CVE-2026-16221 (high) — fast-uri vulnerable to host confusion via literal backslash authority delimiter Fixed in 2.4.3. - GHSA-v39h-62p7-jpjc / CVE-2026-6322 (high) — fast-uri vulnerable to host confusion via percent-encoded authority delimiters Fixed in 3.1.2. Remedy: upgrade fast-uri to 3.1.2 or later — npm install fast-uri@3.1.2. fast-xml-parser@5.3.6 — 1 known vulnerability: - GHSA-8gc5-j5rx-235r / CVE-2026-33036 (high) — fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278) Fixed in 5.5.6. Remedy: upgrade fast-xml-parser to 5.5.6 or later — npm install fast-xml-parser@5.5.6. flatted@3.3.3 — 2 known vulnerabilities: - GHSA-25h7-pfq9-p65f / CVE-2026-32141 (high) — flatted vulnerable to unbounded recursion DoS in parse() revive phase Fixed in 3.4.0. - GHSA-rf6f-7fwh-wjgh / CVE-2026-33228 (high) — Prototype Pollution via parse() in NodeJS flatted Fixed in 3.4.2. Remedy: upgrade flatted to 3.4.2 or later — npm install flatted@3.4.2. js-cookie@3.0.5 — 1 known vulnerability: - GHSA-qjx8-664m-686j / CVE-2026-46625 (high) — JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection Fixed in 3.0.7. Remedy: upgrade js-cookie to 3.0.7 or later — npm install js-cookie@3.0.7. js-yaml@4.1.1 — 2 known vulnerabilities: - GHSA-2883-xcg3-v3hh / CVE-2026-84375 (high) — js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources Fixed in 4.3.2. - GHSA-5p4m-2wfm-xmqj (high) — JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported Fixed in 4.3.1. Remedy: upgrade js-yaml to 4.3.2 or later — npm install js-yaml@4.3.2. minimatch@3.1.2 — 3 known vulnerabilities: - GHSA-23c5-xmqv-rm74 / CVE-2026-27904 (high) — minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions Fixed in 10.2.3. - GHSA-3ppc-4f35-3m26 / CVE-2026-26996 (high) — minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern Fixed in 10.2.1. - GHSA-7r86-cg39-jmmj / CVE-2026-27903 (high) — minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments Fixed in 10.2.3. Remedy: upgrade minimatch to 10.2.3 or later — npm install minimatch@10.2.3. nanoid@3.3.11 — 2 known vulnerabilities: - GHSA-28wg-ghj8-5hjv / CVE-2026-67214 (high) — nanoid: non-secure generators can loop indefinitely with negative size Fixed in 3.3.16. - GHSA-2v37-7h3g-55p8 / CVE-2026-67213 (high) — nanoid: custom generators can loop indefinitely when size is zero Fixed in 3.3.18. Remedy: upgrade nanoid to 3.3.18 or later — npm install nanoid@3.3.18. picomatch@2.3.1 — 1 known vulnerability: - GHSA-c2c7-rcm5-vvqj / CVE-2026-33671 (high) — Picomatch has a ReDoS vulnerability via extglob quantifiers Fixed in 4.0.4. Remedy: upgrade picomatch to 4.0.4 or later — npm install picomatch@4.0.4. serialize-javascript@6.0.2 — 1 known vulnerability: - GHSA-5c6j-r48x-rmvq (high) — Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() Fixed in 7.0.3. Remedy: upgrade serialize-javascript to 7.0.3 or later — npm install serialize-javascript@7.0.3. undici@5.29.0 — 1 known vulnerability: - GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (high) — Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression Fixed in 6.24.0. Remedy: upgrade undici to 6.24.0 or later — npm install undici@6.24.0. ws@8.19.0 — 1 known vulnerability: - GHSA-96hv-2xvq-fx4p / CVE-2026-48779 (high) — ws: Memory exhaustion DoS from tiny fragments and data chunks Fixed in 5.2.5. Remedy: upgrade ws to 5.2.5 or later — npm install ws@5.2.5.
from code
blockerTechnology

Sentry detected without consent gate

Sentry (@sentry/nextjs) is detected as a direct dependency but the deterministic catalogue does not flag pre-consent error tracking. Error tracking libraries can capture PII and session data before the user accepts cookies, creating ePrivacy and GDPR consent violations.
from code
blockerTechnology

Logtail logging library detected without consent gate

Logtail (@logtail/browser, @logtail/node) is detected in dependencies.

Server-side logging libraries typically run before consent and can capture request metadata including IP addresses and user agents, which are personal data under GDPR. No deterministic rule flags pre-consent logging libraries.
from code
blockerTechnology

Vercel Speed Insights detected without consent documentation

Vercel Speed Insights (@vercel/speed-insights) is a direct dependency that collects performance telemetry.

Although primarily first-party, it can track user sessions and page views. The deterministic catalogue does not flag first-party analytics libraries that collect usage data before consent.
from code

Issues

23 · fix at or after launch
issueLegal

AI data processing disclosure required

LLM API usage detected — users should be informed that their data may be processed by AI systems.
from regulatory mapping
Generic template
free
  • Standard clauses, you fill in the gaps
  • Markdown download
  • Doesn't reference your actual stack
Tailored to your app
Pro · $19/mo
  • Covers Clerk
  • Hosted at myapp.wolfix.io/privacy
  • Updates when your stack changes
issueOperations

Decide which jurisdiction to incorporate in

You're not sure where to incorporate yet — the decision-helper artifact walks through Delaware vs UK Limited vs Estonia vs local options.
from regulatory mapping
issueLegal

No privacy policy link on the live site

No privacy policy link detected on the live site. Add a footer link to your privacy policy so users (and regulators) can find it.
from live app
issueLegal

No terms of service link on the live site

No terms of service link detected on the live site. Add a footer link to your ToS / terms of use.
from live app
issueOperations

No support / contact link on the live site

No support / help / contact link detected on the live site. Apple App Store guideline 2.1 requires one for mobile apps; web users will look for it too.
from live app
issueGrowth

No robots.txt — crawlers fall back to defaults

No robots.txt detected. Without it, crawlers follow defaults; you cannot disallow staging paths or signal a sitemap.
from live app
issueTechnology

No SPF record — outbound email will be junked

No SPF record found. Mail sent on your behalf will be rejected or junked by major providers (Gmail, Outlook).
from DNS
issueTechnology

No DKIM signing key — outbound email fails DMARC alignment

No DKIM record found at the common selectors. Outbound email will fail DMARC alignment and trip spam filters.
from DNS
issueBrand

No Open Graph social card — shared links render unbranded

No og:image detected.

Generate one from your brand kit and add it via <meta property="og:image"> so links render with a branded preview. Also reported as “No brand logo / OG image deployed — link previews are blank” — same underlying signal, merged here so it counts once. Also reported as “No Open Graph image — shared links render without a preview” — same underlying signal, merged here so it counts once.
from live app
issueGrowth

Adjust meta description length

Your meta description is 196 characters — aim for 70–160. Shorter descriptions feel thin; longer ones get truncated.
from live app
issueGrowth

Canonical URL mismatch

Canonical URL myapp.lovable.app does not match the scanned URL myapp.lovable.app. Confirm this is intentional — mismatched canonicals can de-rank the page.
from live app
issueGrowth

Add missing Open Graph tags

Missing OG tags: og:image. Add the full set so social platforms can render rich link previews.
from live app
issueGrowth

Complete the Twitter card

Twitter card is set (summary_large_image) but missing: twitter:image. Add the complete set for rich previews on X.
from live app
issueGrowth

Publish a sitemap.xml

No /sitemap.xml detected. Generate one and reference it from robots.txt — it helps search engines discover every page on your site.
from live app
issueGrowth

Add an HTTPS redirect

http://{host} did not respond with a clean redirect to https://. Make sure visitors landing on the http URL are forwarded to the secure version.
from live app
issueGrowth

Publish /llms.txt

No /llms.txt detected. Publish one (per llmstxt.org) so AI assistants can quickly understand what your product does and surface it in answers.
from live app
issueGrowth

Publish /llms-full.txt as well

Neither /llms.txt nor /llms-full.txt was found. We recommend publishing the richer /llms-full.txt variant so AI assistants get a deep map of your site.
from live app
issueGrowth

Add Organization JSON-LD

No JSON-LD schema with @type Organization, LocalBusiness, or SoftwareApplication detected on the homepage or /about / /pricing / /faq / /help. Add structured data so AI assistants and search engines can identify your business.
from live app
issueGrowth

Replace duplicate feature copy

Found 8 duplicate descriptions across feature/value-prop cards on the homepage (e.g. "fsa deadline in 30 days…"). Visitors notice when every card says the same thing — write a unique line per feature.
from live app
issueLegal

Copyright registration check: manual review required for "Myapp"

The US Copyright Office public catalog could not be queried automatically.

Copyright attaches at creation, but registration with the USCO enables statutory damages in infringement suits. Manually search the catalog for any conflicting registration.
from live app
issueTechnology

No mobile platform detected but benefits domain suggests eventual mobile need

Code scan shows no mobile dependencies (no React Native, Expo, or RevenueCat), yet the product is a family benefits concierge handling claims and health documents.

Users typically manage claims on mobile. If a future mobile app is planned, in-app subscription terms and App Store / Play Store data safety disclosures will be required. The deterministic catalogue only flags these when mobile SDKs are present.
from code
issueTechnology

AWS SDK detected but no HIPAA-covered subprocessor disclosures

Code includes @aws-sdk/client-s3 and @vercel/blob for file storage.

The product processes medical bills, EOBs, and benefits documents, which may contain Protected Health Information (PHI). If any documents are PHI, AWS and Vercel Blob must be listed as HIPAA Business Associates with signed BAAs. The deterministic catalogue does not detect cloud storage SDKs in the context of HIPAA or health data.
from code
issueTechnology

OpenAI SDK detected without AI-specific DPA or data retention terms

OpenAI (direct dependency) processes user-uploaded benefits documents and chat queries.

The deterministic AI_DATA_DISCLOSURE rule exists, but it does not verify whether AI vendors are covered by a Data Processing Agreement or whether input data retention policies (e.g., OpenAI zero-retention API tier) are documented for users. For benefits data, this is critical under GDPR Art. 28.
from code

Covered

13 · already in place
13 things passedNo cookie consent banner · DMARC policy published · MX records published · Favicon deployed · 9 more