Checked by Advantage · 7 Sept 2026
getadvantage.appNext.js
100/100 · safety
Scored above 98% of the apps Advantage has checked on safetyn=225
7passed0to tighten0to fix

What we checked on getadvantage.app

Server secrets in the client bundlepass

We checked the HTML and first-party scripts and found no server-secret-shaped tokens.

Exposed backend config (Supabase / Firebase)pass

We didn't find an exposed Supabase/Firebase project config in the client bundle.

Publicly served .env / .gitpass

We probed /.env and /.git/config and neither was served publicly.

Security response headerspass

All 5 headers we check for were present.

Cross-origin (CORS) exposurepass

We didn't find a wildcard CORS policy on the main response.

HTTPS transportpass

Served over HTTPS with HSTS set.

Exposed source mapspass

We didn't find a publicly fetchable source map.

This badge links here

Checked by Advantage badge

We checked the things listed above and reported what we found. This is an observed check, not a security audit or a guarantee.

Fixed something since 7 Sept 2026? Run a fresh check → — a new report, a new badge.

Want this report and badge snippet in your inbox? We'll email the permanent link — nothing else.

The report stays fully visible right here without it — no spam, no list.

This is what an Advantage check looks like.

Run the same safety check on your app — free, no signup.

Check your app →