Solo builders ship underdeveloped products and get themselves into trouble.
CanIShip is an automated pre-launch audit for web applications. Paste your URL, describe what your app does, and receive a structured audit report with a ShipScore and a verdict — cleared, or hold until specific defects are fixed. No SDK. No installation. Three free audits a month, always.
- URL
- myapp.com
- Auditor
- Claude + Playwright
- Duration
- 14m 32s
- Layers complete
- 10 of 10
- Findings
- 3 critical · 7 minor
10 layers. 100+ discrete checks.
Playwright navigates every declared flow. Unresponsive controls, dead ends, and broken redirects are logged with screenshot evidence.
Missing loading states, absent error messages, silent failures — friction that does not break the app but breaks the user.
axe-core injection across all pages. Violations are classified by severity with WCAG criterion reference and remediation.
Lighthouse against LCP, CLS, FCP, TBT, INP. Render-blocking resources, unoptimised assets, and Time to Interactive flagged.
OWASP headers audit. Routes accessible without authentication. Sensitive data in source or URL. Mixed content and HTTPS enforcement.
Every internal href crawled. All network responses monitored via Playwright intercept — 4xx/5xx that the UI silently swallows.
Title, meta description, canonical, Open Graph, sitemap.xml, robots.txt — every signal search engines use to index or reject.
Real 375px viewport. Horizontal overflow, unclickable touch targets, missing viewport meta, and layout breaks at WCAG 2.5.5.
AI-powered analysis of the business model itself. Flags fake engagement, platform ToS violations, unregulated regulated industries, and legal grey areas — with an advisory score separate from the ShipScore.
Paste your public GitHub repo URL and Semgrep scans your actual source code — catching hardcoded secrets, SQL injection patterns, insecure crypto, and prototype pollution a runtime audit cannot see. Code is cloned, scanned, and deleted immediately.
How CanIShip differs from other tools
| Criterion | CanIShip | Other QA tools |
|---|---|---|
| Setup required | None. Paste a URL. | SDK, CLI, or browser extension |
| Input | Plain English + URL | YAML config or code annotations |
| Output | Report a founder reads | Report a QA team reads |
| Covers | 10 layers, 100+ checks | Usually 1–2 layers per tool |
| Business risk score | Included | Not included |
| Forward roadmap | Included | Not included |
| Price | From €0 | From $49–500/month |
Scope of this audit
Within scope: functional navigation, accessibility to WCAG 2.1 AA1, Core Web Vitals2, OWASP security headers3, broken links, console errors, SEO, mobile readiness at 375px against the WCAG 2.5.54 touch-target minimum, and an AI-powered business risk assessment. Ten layers in total, including an optional source code SAST scan.
Outside scope: manual penetration testing, load testing, screen-reader user testing, or auth-gated flows beyond provided test credentials. The business risk score is advisory — it flags grey areas but does not constitute legal advice. For regulatory obligations, supplement with qualified legal review.
Cadence: each audit is a fresh snapshot. Re-run after fixes to measure improvement — Builder and Studio plans retain full history with score differential between runs.
Audit tariff
| Free | Builder — €19/mo | Studio — €49/mo | |
|---|---|---|---|
| Audits per month | 3 | 15 | Unlimited |
| Scan depth | Quick (~5 min) | All depths | All depths |
| Full 10-layer report | |||
| Business risk score | |||
| Forward roadmap | |||
| History + score diffs | |||
| Self-hosted (Docker) | |||
| API access | |||
| Start free | Start Builder | Start Studio |
Frequently asked questions
“A product does not ship because it is finished. It ships because someone checked.”
File an audit. Receive a structured report. Know exactly what to fix before your users find it.