Buying a SaaS or website? Know what's in the code before you close.
You're about to hand over real money for a codebase you didn't write, based on a Loom walkthrough and the seller's word. I'll scan the actual repo for what usually only shows up after close — leaked secrets, outdated/vulnerable dependencies, missing tests, and the kind of tech debt that turns a "clean" acquisition into a rewrite.
⚠️ This isn't hypothetical: an independent review of 18 AI-built SaaS apps bought on Acquire.com and Flippa found that every single one had at least one critical or high-severity finding within an hour of closing.
This is for you if:
- You're mid-negotiation or about to sign on a SaaS/website listing (Flippa, Acquire.com, MicroAcquire, or a private deal) and want a real look at the code, not just the seller's summary
- You can get read-only repo access or a code export before you wire the money
- You want a fast, narrow answer in 24-48 hours, not a multi-week financial/legal engagement
Not for you if:
- You need full financial/legal due diligence (revenue verification, contracts, IP transfer) — that's a different service, talk to an accountant or lawyer, or use the platform's own diligence offering
- The listing has no codebase to review (pure content/affiliate site with no custom code)
Pick a tier
$199
Scan + summary
- Automated scan for hardcoded secrets/API keys (including git history), outdated or known-vulnerable dependencies
- Plain summary: what's exposed, what's out of date, severity of each
- Turnaround: 24-48h
Pay $199
One-time. No subscription.
$349
Scan + manual verification
- Everything in Scan + summary, plus:
- Every finding manually checked by hand — no false-positive noise, only what's actually real
- Tech-debt read: test coverage, CI setup (or lack of it), how risky a future rewrite would be
- Prioritized fix list, ranked by what would actually block you from closing safely
- Turnaround: 24-48h
Pay $349
One-time. No subscription.
How it works
- Pay above, then send read-only access to the repo (GitHub read-only invite or a zip export) to iploskovitov@gmail.com — ask the seller for this before you close, most deal processes allow it
- I go through it — automated scan plus, on the Standard tier, manual verification of every finding
- You get the report back within 24-48 hours; access is dropped once it's done, nothing is kept or reused
This is a technical scan of the codebase — secrets, dependency risk, and tech debt — not a full financial, legal, or business due diligence, and not a guarantee that nothing else is wrong with the deal. It's meant to catch the kind of code-level risk that a revenue screenshot and a demo call can't show you.