30 checks to run on your own app before you take money through it. Each one shows you how to check it yourself — the SQL, the file to open, the page to load. Takes about ten minutes. No signup. Nothing gets sent anywhere, because there's no server behind this page.
A scanner hands you a list. It can't tell you which line is real, which is a false positive, and which is deliberate and has to stay or your app goes down. Working that out is the actual job. This page can tell you what to look at; it cannot tell you which of your findings is which — that part needs someone who reads your schema.
If you'd rather have someone go through your project and write you a verdict on every finding — all in writing, no calls:
See what the audit covers →SECURITY DEFINER function quietly carrying Postgres's default PUBLIC grant, which the build tool's own summary said hadn't happened. That story, and the two queries that caught it, are written up here.