How it works
Deterministic checks, run in your browser
1. Your ZIP stays on your device
When you choose a ZIP, your browser reads it into memory and a background worker extracts relevant text files: source, package.json, app config, eas.json, Info.plist and Android manifests. Dependency folders (node_modules), build output, .git, Pods, images, fonts, audio and video are skipped. Uploaded code is never executed.
Your source code is analysed locally in your browser. Your project files are not uploaded to AppCheck.
2. Fingerprint
AppCheck lists the technologies declared in package.json — Expo SDK, Expo Router, Supabase, RevenueCat, AdMob, analytics SDKs, device permissions and more. Nothing is inferred beyond what is declared.
3. Applicable checks
The AppCheck Ship Standard v1.0 contains 68 checks across Security, Privacy, App Store Readiness and Monetisation. Only checks relevant to your project run — a RevenueCat check is not applicable to an app without RevenueCat — and the report shows exactly how many applied.
4. Confidence levels
- Confirmed — objective, deterministic evidence establishes the condition.
- High confidence — multiple strong signals indicate the issue.
- Review — something you should verify manually. Review items never reduce your score.
5. Ship Score
Every project starts at 100. Confirmed and High-confidence findings deduct points by severity: Critical 15, High 8, Medium 4, Low 2. The score is clamped between 0 and 100.
- 90–100 Ready to ship
- 75–89 Review before shipping
- 0–74 Not ready to ship
The AppCheck Ship Score measures conformity against AppCheck’s automated launch criteria. It does not guarantee platform approval, security, absence of bugs, or commercial success.
6. Fix Prompts
Each finding includes a Fix Prompt you can paste into Claude Code, Cursor, Codex or another assistant. It contains the rule, location, masked evidence and instructions to verify the change rather than assume it worked.