reviewmy / Coverage
Whatever built it, we review it.
The review runs against the rendered page, so the stack does not matter. The repository half is where the toolchain does, these are the ones we read natively, and the ones we do not.

Codex



What reviewmy does with each of these, how to connect it and what it does not do, is on integrations.
Native
Read directly, with no export step.
Coding agents
Read the outstanding requests and close them over MCP.
- Claude Code
Codex- Cursor
GitHub Copilot
Windsurf
App builders
Connect the exported repository and the code pass comes with it.
- Lovable
v0- Bolt
Replit- Base44
Repos, data and hosts
Where file-and-line links point, and where deploys are noticed.
- GitHub
- Supabase
Vercel
Netlify
Stacks and platforms
Reviewed from the rendered page, no plugin, no build hook.
Next.js
Astro
WordPress
Webflow
Shopify
Marks belong to their owners and identify the tools reviewmy reads.
Requirements
What a page needs for the review to work.
- Publicly reachable, or your own gated page
The proxy fetches as an anonymous visitor, so a page behind somebody else’s login is out of reach. For a site you own, you can set a key we present on your own domains, which is how a dashboard or a console gets reviewed. We never send a visitor’s cookies or session either way.
- Not behind a hard bot wall
Some WAFs see a datacentre IP and serve a challenge instead of the page. Paste the URL first, the free audit tells you in seconds whether it renders.
- Server-rendered pages review best
We review the HTML your server sends. A single-page app that builds itself in the browser sends a near-empty shell, so we tell you that rather than reviewing the shell.
- Repository access is optional
Read-only GitHub access adds the file and line to each finding. Without it, the same review runs on the served page alone.
Not covered
Things we will not pretend to do.
Native mobile apps
There is no rendered page to review. A marketing site for an app is fine; the app itself is not.
Somebody else’s authenticated pages
Checkout and anything past a login we were not given a key for. We cannot see them, and a review that guessed would be worse than none. Your own gated pages are different: set a key on the project and we present it on your domains.
A flow that has no address
A wizard whose fourth step exists only because of the first three. We fetch a URL, so a step with no URL of its own is a step we cannot reach, whatever key we carry.
Penetration testing
The security lens is a screening pass against OWASP categories. It is not an engagement and should not be sold as one.
Paste a URL and find out in thirty seconds.
If your page cannot be reached, the free audit says so before you pay anything.