Architecture check

Which endpoints reach your data
without authenticating?

Public repositories. No account, nothing installed, nothing stored.

What comes back

Not a score and not a summary. Every finding is an endpoint, the table it reaches, the path between them, and the rule it breaks — so you can open the file and check the claim yourself.

The engine is rule-based, so the same commit always produces the same verdict. If a repository is in a language or framework it cannot read, it says that instead of reporting a pass.

TypeScript
Express, Next.js App Router
Python
FastAPI
Schemas
Prisma, Drizzle, TypeORM, Mongoose

Try one

Already checked: 100 popular backends

Map your own backend

Import a repository as an editable architecture graph, or describe one in a sentence and compile it to TypeScript. No card required.

Run it where the code is

The extension puts this check on every GitHub repository you open — including the private ones, which never leave your machine.