Project health checks
Every issue Heygents' read-only Deep Scan looks for across real projects: what each check means, how often it shows up, and the exact steps to fix it.
Aggregated from 450 findings across 25 scanned projects. 62% of them have already been resolved. Median agent fix time: 2.7 minutes. Scan window 2026-06-27 to 2026-07-29.
There are 25 published checks. Each one answers a single question a developer actually searches for, explains the risk, and gives concrete fix steps.
Security
Admin routes and health endpoints reachable without login
High severity Seen in 17 of 450 scanned projects (4%).
Your Content-Security-Policy is not actually blocking anything
Medium severity Seen in 24 of 450 scanned projects (5%).
No HTTP security headers served (no HSTS, X-Frame-Options, or CSP)
Medium severity Seen in 9 of 450 scanned projects (2%).
Public endpoints have no rate limiting
High severity Seen in 21 of 450 scanned projects (5%).
Source maps and version headers exposed publicly
Medium severity Seen in 15 of 450 scanned projects (3%).
Secrets committed to git history and world-readable env files
High severity Seen in 25 of 450 scanned projects (6%).
Postgres tables with row-level security disabled or misconfigured
High severity Seen in 19 of 450 scanned projects (4%).
Production dependencies have known CVEs
High severity Seen in 33 of 450 scanned projects (7%).
Performance
Foreign key columns missing a covering index
Medium severity Seen in 14 of 450 scanned projects (3%).
HTML pages sent with cache-control: no-store
Medium severity Seen in 20 of 450 scanned projects (4%).
Anonymous visitors download megabytes of JavaScript they never use
Medium severity Seen in 32 of 450 scanned projects (7%).
HTML Pages Are Served Uncompressed, Wasting Bandwidth on Every Visit
High severity Seen in 11 of 450 scanned projects (2%).
Unpaginated Queries Are Loading Entire Tables on Every Request
High severity Seen in 14 of 450 scanned projects (3%).
Upgrade/Feature
SEO/Marketing
Meta descriptions are missing, truncated, or duplicated
Medium severity Seen in 19 of 450 scanned projects (4%).
Pages with no og:image render as blank cards when shared
Medium severity Seen in 28 of 450 scanned projects (6%).
No robots.txt or sitemap.xml in production
High severity Seen in 37 of 450 scanned projects (8%).
Site has no working analytics, so traffic is unmeasured
Medium severity Seen in 24 of 450 scanned projects (5%).
UI/UX Design
Maintenance
Build output, .bak files, and venvs are committed to git
Medium severity Seen in 8 of 450 scanned projects (2%).
Your production database has no working automated backup
High severity Seen in 31 of 450 scanned projects (7%).
Production is crash-looping and no one gets notified
Medium severity Seen in 16 of 450 scanned projects (4%).
There Are No Automated Tests, or No CI Pipeline Actually Runs Them
Medium severity Seen in 26 of 450 scanned projects (6%).
Committed migrations were never applied to the live database
High severity Seen in 14 of 450 scanned projects (3%).
Production Is Running Code That Was Never Committed to Git
High severity Seen in 26 of 450 scanned projects (6%).
Find this in your own projects, automatically
Heygents runs a read-only Deep Scan across every project you own, finds issues like this one, and hands you a ready-to-run fix an AI agent can execute and verify. A solo developer gets the audit, the backlog and the fix loop in one place.
Open Heygents →