Example report
Every finding tells you where, why and how to fix it.
No vague warnings. This is what you see in Claude Code after a check, for a made-up app scored by the kit's own rules. The same report is saved in your project as a file.
/launch-check
- Wave 1 · Security · 1 problem
- Wave 2 · Database, Payments · 3 problems
- Wave 3 · Reliability, Legal · 1 problem
- Wave 4 · SEO, Speed and quality, Launch · 5 problems
Launch score39/ 100DON'T SHIP
A critical problem caps the score at 39.
2 critical2 high6 medium0 low
What this means
Do not launch yet. Any signed-in user can act as an admin, and the files your users upload can be opened by anyone. Both are quick to fix. After that, a payment can be counted twice and login will break on the live address.
Scores by area
Every area starts at 100 and loses points for each problem.
- Security801 problem
- Database801 problem
- Payments892 problems
- Reliability921 problem
- Legal100no problems
- SEO942 problems
- Speed and quality942 problems
- Launch971 problem
Fix these first
The critical and high problems, worst first.
- 1.
[critical] AUTH-01 Admin API trusts client-provided role
app/api/admin/users/route.ts:42
Why: The route reads the user's role from the request instead of looking it up. Any signed-in user can call it as an admin and read or change every account.
Fix: Read the role from the session on the server and refuse the request when it is not an admin.
Security · takes minutes
- 2.
[critical] STOR-01 Uploaded files are publicly readable
supabase/migrations/0004_storage.sql:11
Why: The uploads bucket is public, so anyone with a file's address can open it. Invoices and ID photos uploaded by your users are in it.
Fix: Make the bucket private and hand out short-lived signed links to the file's owner.
Database · takes minutes
- 3.
[high] HOOK-03 Webhook accepts duplicate events
app/api/webhooks/payments/route.ts:28
Why: Payment providers send the same event more than once. Each copy adds credits again, so one payment can be paid out several times.
Fix: Store the ID of every event you have handled and skip the ones you have already seen.
Payments · takes hours
- 4.
[high] DNS-03 Production callback points to localhost
.env.production:7
Why: After signing in, users are sent to an address that only exists on your laptop. Login will fail for everyone on launch day.
Fix: Set the callback address to your live domain here and in the login provider's dashboard.
Reliability · takes minutes
Fix these next
Medium and low problems.
[medium] HOOK-05 Webhook reports success even when it failed
Fix: Answer with an error when handling fails, so the provider sends the event again. (minutes)
[medium] NF-01 Missing pages answer with status 200
Fix: Return a real 404 for addresses that do not exist. (minutes)
[medium] ROBOT-02 There is no robots.txt
Fix: Add one that allows the public pages and names the sitemap. (minutes)
[medium] BUNDLE-01 A charting library loads on every page
Fix: Load it only on the dashboard page that draws charts. (hours)
[medium] MOB-02 The pricing table scrolls sideways on phones
Fix: Let the table stack into rows on narrow screens. (minutes)
[medium] LAND-02 The landing page never says who the product is for
Fix: Name the audience in the first screen. (minutes)
What looks good
- Legal: no problems found in the 41 checks that ran.
Next step
Run /launch-fix to fix the problems, worst first. Then run /launch-check again to see the new score.
8 of the 10 fixes take minutes, 2 take hours.
Full report saved to .launchreadykit/report.md
/launch-check
Find the problems before your users do.
Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.
41 agents · 440 checks · read-only audit · one-time payment