Skip to main content
CanIShip — Pre-Launch Audit Report
Finding 00 — Summary

Solo builders ship underdeveloped products and get themselves into trouble.

CanIShip is an automated pre-launch audit for web applications. Paste your URL, describe what your app does, and receive a structured audit report with a ShipScore and a verdict — cleared, or hold until specific defects are fixed. No SDK. No installation. Three free audits a month, always.

Sample Audit Report
URL
myapp.com
Auditor
Claude + Playwright
Duration
14m 32s
Layers complete
10 of 10
Findings
3 critical · 7 minor
ShipScore™
61
Hold — fix required

10 layers. 100+ discrete checks.

FT
Functional tests

Playwright navigates every declared flow. Unresponsive controls, dead ends, and broken redirects are logged with screenshot evidence.

UX
UX friction

Missing loading states, absent error messages, silent failures — friction that does not break the app but breaks the user.

A11
Accessibility

axe-core injection across all pages. Violations are classified by severity with WCAG criterion reference and remediation.

PF
Performance

Lighthouse against LCP, CLS, FCP, TBT, INP. Render-blocking resources, unoptimised assets, and Time to Interactive flagged.

SEC
Security surface

OWASP headers audit. Routes accessible without authentication. Sensitive data in source or URL. Mixed content and HTTPS enforcement.

LNK
Broken links & network

Every internal href crawled. All network responses monitored via Playwright intercept — 4xx/5xx that the UI silently swallows.

SEO
SEO health

Title, meta description, canonical, Open Graph, sitemap.xml, robots.txt — every signal search engines use to index or reject.

MOB
Mobile readiness

Real 375px viewport. Horizontal overflow, unclickable touch targets, missing viewport meta, and layout breaks at WCAG 2.5.5.

BRK
Business risk

AI-powered analysis of the business model itself. Flags fake engagement, platform ToS violations, unregulated regulated industries, and legal grey areas — with an advisory score separate from the ShipScore.

SAST
Source code scan

Paste your public GitHub repo URL and Semgrep scans your actual source code — catching hardcoded secrets, SQL injection patterns, insecure crypto, and prototype pollution a runtime audit cannot see. Code is cloned, scanned, and deleted immediately.

How CanIShip differs from other tools

Comparison of CanIShip against other QA tools
CriterionCanIShipOther QA tools
Setup requiredNone. Paste a URL.SDK, CLI, or browser extension
InputPlain English + URLYAML config or code annotations
OutputReport a founder readsReport a QA team reads
Covers10 layers, 100+ checksUsually 1–2 layers per tool
Business risk scoreIncludedNot included
Forward roadmapIncludedNot included
PriceFrom €0From $49–500/month

Scope of this audit

Within scope: functional navigation, accessibility to WCAG 2.1 AA1, Core Web Vitals2, OWASP security headers3, broken links, console errors, SEO, mobile readiness at 375px against the WCAG 2.5.54 touch-target minimum, and an AI-powered business risk assessment. Ten layers in total, including an optional source code SAST scan.

Outside scope: manual penetration testing, load testing, screen-reader user testing, or auth-gated flows beyond provided test credentials. The business risk score is advisory — it flags grey areas but does not constitute legal advice. For regulatory obligations, supplement with qualified legal review.

Cadence: each audit is a fresh snapshot. Re-run after fixes to measure improvement — Builder and Studio plans retain full history with score differential between runs.

  1. 1. Web Content Accessibility Guidelines, Level AA — engine: axe-core (Deque), also used by Google and Microsoft.
  2. 2. Google Lighthouse — LCP, CLS, FCP, TBT, INP.
  3. 3. CSP, HSTS, X-Frame-Options, X-Content-Type-Options.
  4. 4. Target Size — mobile touch-target minimum, WCAG 2.5.5.

Audit tariff

Pricing comparison across Free, Builder, and Studio plans
FreeBuilder — €19/moStudio — €49/mo
Audits per month315Unlimited
Scan depthQuick (~5 min)All depthsAll depths
Full 10-layer report
Business risk score
Forward roadmap
History + score diffs
Self-hosted (Docker)
API access
Start freeStart BuilderStart Studio

Frequently asked questions

“A product does not ship because it is finished. It ships because someone checked.”

File an audit. Receive a structured report. Know exactly what to fix before your users find it.