For Cursor, Claude Code, Lovable, v0 & Replit builders

Your AI wrote the code.
Is your API key in it?

It compiles. It runs. You ship it. And somewhere in those 400 lines you did not read is an API key in the browser bundle, an endpoint anyone can call, or a database query a stranger can rewrite.

CodeRabbit reads every pull request before you merge it, and tells you in plain English what is exposed, what is broken, and what to change.

Free forever on public repos · 14-day trial on private ones · no credit card

CodeRabbit reviewed your pull request2 min ago
Critical · would have shipped
Service-role key committed to the client bundle

This key bypasses row-level security and ships to every browser that loads your site. Move it server-side and use the anon key here.

lib/supabase.ts
- "eyJhbGciOiJIUzI1Ni…service_role"
+ process.env.SUPABASE_ANON_KEY
High · missing check
This endpoint never checks who owns the order

It confirms the caller is signed in, then returns whatever id is in the URL. Any logged-in user can read every order in the table by changing one number.

2 issues found · 1 would have shippedReviewed automatically on open
Three real ones

"It works" and "it's correct" are different things

These are the bugs generated code produces most, and the review comment that catches each. Pick one — the code runs fine in every case.

lib/supabase.ts
3const supabase = createClient(
4 "https://xyzcompany.supabase.co",
5 "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...service_role",
6);
Why you would miss it: Assistants reach for whichever key is in your clipboard. The code runs perfectly either way, so nothing tells you.
CodeRabbitCritical
Service-role key committed to the client bundle

This is the service_role key, not the anon key. It bypasses row-level security, it ships to every browser that loads your site, and it is now in your git history. Rotate it, move it to a server-side environment variable, and use the anon key here.

Fix suggested inline — apply it in one click, or reply and ask why.
Review my code free

Free forever on public repos · 14-day trial on private ones · no credit card

The part that costs you

Most apps are not hacked. They are left open.

Almost nothing on this list is a clever attack. It is ordinary code that does exactly what it says and exposes something it should not — and it is the code an assistant writes most confidently, because it has never seen your database, your users or your auth.

Your API key in the browser
Assistants paste keys straight into the code. Anyone who opens dev tools on your site can read them.
Someone else runs up your bill, or reads your whole database.
Anyone can read anyone's data
The endpoint checks that you are logged in, but never that the record belongs to you. Change the id in the URL and you are reading someone else's.
The most common serious flaw in new apps, and the easiest to find from the outside.
User input pasted into a query
A search box wired straight into SQL. Type the right thing into it and the database does as it is told.
Data copied, deleted, or quietly changed.
User input rendered as HTML
A comment or profile field dropped onto the page unescaped, so a visitor's script runs in everyone else's browser.
Sessions and logins stolen from your own users.
Storage and CORS left open
A bucket set to public while debugging, or a policy that accepts requests from any site. It gets shipped and forgotten.
Uploads, invoices and private files indexed by a search engine.
Secrets in your git history
A .env committed once and removed later is still in the history, and still readable, forever.
Bots scan public repos for exactly this, within minutes of a push.
Every one of these is sitting in the pull request — if somebody reads it

That is the whole job. CodeRabbit reads each change against the rest of your repository, flags what is exposed, and says in plain English what to do instead — with your existing security linters running in the same pass.

It is not a promise that you will never be breached. It is the read-through nobody on a one-person team ever gets.

Check my repo freeFree on public repos · no card
Setup

Three steps, and nothing to configure

Connect your repo
Sign in with GitHub, GitLab, Bitbucket or Azure DevOps and pick a repository. Two minutes, no config file to write.
Open a pull request
Push the branch your assistant built. The review starts on its own, minutes later — you do not have to ask.
Read, ask, apply
Comments land on the exact lines. Apply a fix in one click, or reply and argue with it if you think it is wrong.

Works with GitHub, GitLab, Bitbucket and Azure DevOps, self-managed installs included. CodeRabbit describes itself as the most installed AI app on GitHub, with 17,000 customers across six million repositories — their figures, from their own site.

Who this is for

Anyone shipping more code than they can read

The less of your codebase you wrote by hand, the more this matters. These are the people it changes the most.

Solo founders
You are the whole engineering team, which means nobody has ever read your code but you — and you wrote half of it by accepting a suggestion.
Indie hackers
Shipping fast is the point. A review that runs itself is the only kind you will actually keep using past week two.
Small teams
One senior engineer reviewing everything is a bottleneck and a single point of failure. This takes the first pass off them.
Freelancers and agencies
You are handing code to a client. A leaked key or an open endpoint in their repo is your reputation, not theirs.
People learning to code
Comments explain why something is wrong, not just that it is. You can reply and ask — which is closer to a mentor than a linter.
Open-source maintainers
Reviews on public repositories cost nothing, forever. There is no trial to run out and nothing to cancel.
What changes

The difference it makes by the end of the first week

Before
You merge because it works, not because you checked
Secrets and keys get found by someone else, later
Nobody reads the pull request but you
You find out at 3am that an error was swallowed
After
Every PR gets a line-by-line read before it merges
Keys and open endpoints are flagged while you can still fix them
A second opinion on every change, minutes after you push
You can ask it why — and push back when it is wrong
Review my code free

Free forever on public repos · 14-day trial on private ones · no credit card

ChooseMyStack logoWhy we recommend CodeRabbit

We judge software on what it does, what it costs and who it suits. CodeRabbit earns the recommendation here for reviewing a change against the rest of the repository rather than the diff alone, for running on every major git platform including self-managed installs, and for being free on public repositories — so you can test it before it costs anything.

Recommended for
Solo foundersIndie hackersSmall engineering teamsFreelancers and agenciesOpen-source maintainersPeople learning to code

Disclosure: this page carries no prices — the full breakdown of every plan is on our CodeRabbit pricing page, read from CodeRabbit's own documentation and dated. If you sign up through our link we may earn a commission at no extra cost to you; it does not change what we recommend, and you are welcome to go to coderabbit.ai directly instead.

Straight answers

What people ask before they connect a repo

I'm not a senior engineer. Will I understand the comments?
That is the point of the chat. Every comment can be replied to — ask why it matters, or what the fix does, and it explains itself in the pull request. You are reading English, not a linter code.
Will it slow me down?
It reviews while you carry on. Nothing blocks, nothing waits for you, and you are not asked to fix everything it finds — a comment you disagree with gets waved through.
Does my code get used for training?
Read their terms for the tier you are on before you point it at private code, and ask them directly if it matters to you. Enterprise adds self-hosting, SSO and audit logging if the answer has to be no.
What does it cost to start?
Nothing. Public repositories are reviewed free with no time limit, and private ones get 14 days on any plan without a credit card — so there is nothing to cancel if you decide against it. Paid plans exist for private repos after that; we list every one of them on our CodeRabbit pricing page.

Put it on the repo you shipped this week

Connect it, open one pull request, and read what comes back. If it finds nothing, you have lost five minutes. If it finds a key in your client bundle, you will wish you had done it a month ago.

Review my code free

Free forever on public repos · 14-day trial on private ones · no credit card

© 2026 ChooseMyStack · Home · CodeRabbit pricing
Review my code free

Free on public repos · no credit card