reviewmy / Coverage

Whatever built it, we review it.

The review runs against the rendered page, so the stack does not matter. The repository half is where the toolchain does, these are the ones we read natively, and the ones we do not.

  • Claude
  • Codex
  • Cursor
  • Lovable
  • GitHub
  • Supabase

What reviewmy does with each of these, how to connect it and what it does not do, is on integrations.

Native

Read directly, with no export step.

Coding agents

Read the outstanding requests and close them over MCP.

  • Claude Code
  • Codex
  • Cursor
  • GitHub Copilot
  • Windsurf

App builders

Connect the exported repository and the code pass comes with it.

  • Lovable
  • v0
  • Bolt
  • Replit
  • Base44

Repos, data and hosts

Where file-and-line links point, and where deploys are noticed.

  • GitHub
  • GitLab
  • Supabase
  • Vercel
  • Netlify

Stacks and platforms

Reviewed from the rendered page, no plugin, no build hook.

  • Next.js
  • Astro
  • WordPress
  • Webflow
  • Shopify

Marks belong to their owners and identify the tools reviewmy reads.

Requirements

What a page needs for the review to work.

  • Publicly reachable

    The proxy fetches the page as an anonymous visitor. Anything behind a login is out of reach, because we never send cookies upstream.

  • Not behind a hard bot wall

    Some WAFs see a datacentre IP and serve a challenge instead of the page. Paste the URL first, the free audit tells you in seconds whether it renders.

  • Server-rendered pages review best

    We review the HTML your server sends. A single-page app that builds itself in the browser sends a near-empty shell, so we tell you that rather than reviewing the shell.

  • Repository access is optional

    Read-only GitHub access adds the file and line to each finding. Without it, the same review runs on the served page alone.

Not covered

Things we will not pretend to do.

Native mobile apps

There is no rendered page to review. A marketing site for an app is fine; the app itself is not.

Authenticated flows

Checkout, dashboards and anything past a login. We cannot see them, and a review that guessed would be worse than none.

Penetration testing

The security lens is a screening pass against OWASP categories. It is not an engagement and should not be sold as one.

Paste a URL and find out in thirty seconds.

If your page cannot be reached, the free audit says so before you pay anything.