What we checked on getadvantage.app
We checked the HTML and first-party scripts and found no server-secret-shaped tokens.
We didn't find an exposed Supabase/Firebase project config in the client bundle.
We probed /.env and /.git/config and neither was served publicly.
All 5 headers we check for were present.
We didn't find a wildcard CORS policy on the main response.
Served over HTTPS with HSTS set.
We didn't find a publicly fetchable source map.
This badge links here
We checked the things listed above and reported what we found. This is an observed check, not a security audit or a guarantee.
Fixed something since 7 Sept 2026? Run a fresh check → — a new report, a new badge.
Want this report and badge snippet in your inbox? We'll email the permanent link — nothing else.
The report stays fully visible right here without it — no spam, no list.
This is what an Advantage check looks like.
Run the same safety check on your app — free, no signup.