AI CODE AUDIT
If AI wrote most of your code, I'll read all of it, line by line.
In one to two weeks I read all of it, and you get it in writing: what will cause trouble now, and what will in six months. Every finding comes with the file and the line, and how much work it takes to fix. The price is fixed, and it doesn't change along the way.
- Is it safe now?
- Can you keep building on it?
Mihály Tari · 20 years shipping software, web and mobile.
Request an audit ↓It's not just you
-
55.8%
A 2026 study checked 3,500 AI-written code samples from seven models with formal verification, a method that proves mathematically that a class of flaw cannot occur. More than half had at least one proven vulnerability, and the best model scored a D.
Broken by Default, arXiv:2604.05292, 2026 -
81%
That's the share of security teams who don't know where their developers use AI. The same survey also looked at how many companies had AI-generated code in their codebase, and 100% of them did.
Cycode, State of Product Security in the AI Era 2026 -
2,500%
That's the rise in software defects Gartner expects by 2028. The reason they give is that more software now gets built by people who aren't developers, with tools that assemble an app from a description.
Gartner, Predicts 2026, as quoted by ArmorCode
Two questions I put to the code
-
01
What will hurt now
Security and reliability, meaning everything that can break today, or lose data today.
- Passwords and keys committed to the code repository, or readable from the browser
- Login and authorisation that's only half wired up
- Unchecked input wherever data comes in from outside
- Missing rules about who may read which row in the database (this is called RLS)
- Paths where data can be lost: migrations, deletes, race conditions
-
02
What will hurt in six months
Maintainability, meaning everything that makes the next feature take twice as long as it should.
- Structure that breaks at the next feature
- Duplicated code, and code nothing calls any more
- Tests that are missing, or only look like tests
- Leftover placeholders, the half-finished bits nobody went back to
- Anything that slows the team down before anyone notices
What I typically find
This list comes out of the sample report and my earlier audits, and the severity column says how urgent a finding is rather than how common.
| Finding | Severity | What it means in your system |
|---|---|---|
| A secret in the repo, or in code shipped to the browser | critical | Anyone who sees the code or the browser's network log can call outside services in your name. |
| Authorisation that only exists in the UI | critical | A hand-built request gets around it, so one customer can see or delete another's data. |
| No row-level rules on the database (RLS) | high | The key that ships to the browser reaches every row, and I find this most often in Supabase and Firebase projects. |
| Unchecked input where injection is possible | high | A query, a shell command, a template or a prompt with user text inside. |
| A migration or delete with no way back | high | After one bad release there is nothing left to restore the data from. |
| Tests that do not test | medium | The automated check is green, but the test only asks whether the function returns something. |
| Duplicated code, and code nothing calls | medium | Nothing breaks because of it, but the next feature takes twice as long. |
What you get
-
01
A one-page summary
I write this one for whoever doesn't read code. It opens with a sentence on where the system stands, then says how many findings there are, how serious they are, how much work they take to fix, and what happens if nobody touches them.
-
02
The full report
This one is for the developers. Every finding carries the file and the line so nobody has to go looking, with a concrete scenario of how it would bite, then the fix and roughly how many hours it takes. At the end I set out the order I'd tackle them in.
-
03
Optional: half a day with your team
I walk your team through the report, finding by finding, on your own code. The half day is there so next time you can spot this kind of thing without me.
SAMPLE REPORT
So you can see what you get, I did the same to my own code: 50,000 lines, written in a week, mostly with AI. I published the report as it came out, with the flaws it found in my work.
Why not just ask the AI?
You can ask Claude or Cursor to review its own code, and it's worth doing. The table shows what that review doesn't see.
| Aspect | AI self-check | This audit |
|---|---|---|
| What it sees | The file you hand it, and as much as fits in one go. | The whole repo and the history of every change, including secrets committed long ago and left there. |
| What it finds | What it knows from its training, though it often misses the bug it wrote itself. | What can actually be exploited in your system, with a concrete scenario. |
| Order | A long list, everything equally important. | Severity, an estimate in hours, and an order to tackle them in. |
| Who is accountable | Nobody. | Me, by name and on an invoice, and the sample report shows in advance what to expect. |
| Price | Your subscription. | €970, fixed. |
If you're not sure where you stand: thirteen questions, two minutes, nothing stored. Self-check →
Price
€970
1–2 weeks, fixed price
- Half a day with your team
- €280
Four hours at my usual €70 an hour, and only if you want it.
When this is not the price
- More than one repo. A monorepo counts as one.
- Above roughly 150,000 lines.
- A web app and a mobile app together.
If any of these is true, you get a different fixed price in writing before the audit starts, and it doesn't change once it's running.
What it is not
This isn't a penetration test, a security certification, ISO or SOC 2 compliance. If you need one of those, I'll say so and point you to the right people.
How it goes
-
01
You give access
Read access to the repo is enough. If you want an NDA — a confidentiality agreement — first, I'll sign one.
-
02
I read
That takes one to two weeks. I have a few scripts that flag places worth a look, but I write every finding by hand: the evidence, how it would bite, the fix, and how long it takes. At the end of the third business day I send a short status note with the first findings, so you can see what is coming; if that shows you it is not what you expected and you stop the work in writing, the deposit comes back.
-
03
You get
You get the one-page summary and the full report, and if you asked for the half day, I put a date on it.
What comes after the audit
The audit is a report, and the work can end there. If you want, I'll take it further.
-
01 · Audit
€970, 1–2 weeks. That is what this page describes.
-
02 · Fixes
In the order the report sets out, at a fixed price. With a team it runs as a Project, and if you built the app on your own, as a rescue.
-
03 · Support
From €1,100 a month, no notice period, if you want someone looking at the code every month.
Who this is for
- You have a team, and AI wrote most of the code in the last few months.
- An investor, an enterprise customer or a security questionnaire is asking for something you can't show today.
- The product works, but every new feature ships slower than the last.
- You build in TypeScript, JavaScript, Python or React Native.
Not for you if
- you built an app alone and it's stuck. Someone has to finish it, and a report won't get that done. Vibe coding rescue →
- security is all you care about, and the live system needs to be attacked too. Security audit →
- you need certification, ISO or SOC 2. This is the wrong tool for that, and my reply says who to ask.
Questions
- How large a codebase do you take?
- One repository, and a monorepo — several projects kept in one repo — counts as one. The audit is time-boxed, so I read what I think matters, and the report says what I didn't get to.
- Do you need to run the system?
- No. I read the code and the history of every change. A test environment helps, but I don't need one.
- Does my code go into an AI?
- Yes, through Claude Code into Anthropic's API. Model training is switched off on my account, so nothing is trained on it and it's deleted after 30 days. If that doesn't work for you, the audit is done without AI, for €420 more and in 2–3 weeks. I've written up the details on a separate page. How I work with AI →
- What do you build with?
- TypeScript and JavaScript are where I go deepest: React, Next.js, Node, Astro, with Postgres, Supabase or Firebase underneath. Python and mobile — React Native, Expo — work too. If yours is something else, tell me, and my reply says whether I'll take it.
- Who owns the report?
- You do. Keep it internal, or hand it to an investor or a customer. I only talk about it publicly if you agreed to that in advance.
- Do you fix things, or only report?
- The audit is a report, and your team can do the fixes from it, which is the idea. If you'd rather I did them, I quote that separately at a fixed price. What comes after the audit ↑
- Do you sign an NDA?
- Yes, if you want one, and your own is fine too.
- How is this different from a penetration test?
- A pentest tries to break into the running system from outside. I read the code from inside, so I also see what holds today but will cause trouble in six months. If security is all you care about, and you want the live system checked too, there's a separate audit for that. Security audit →
- We're not a technical team. Will we understand it?
- The one-page summary is written for you. The full report is for the developers, and you don't need to follow it.
- I'm not a company. I built an app and it's stuck.
- Then someone has to finish the app, and a report won't do that. Vibe coding rescue →
- How do I pay?
- In two steps. I ask for 30% of the price as a deposit once I have access: €291 on the €970 price. The remaining 70% is invoiced when the report is delivered. At the status note at the end of the third business day you can stop the work in writing; then I refund the deposit in full and there's nothing more to pay. After that the deposit stays, and silence isn't a stop. I'm a VAT-exempt sole trader in Hungary, so there's no VAT on top and the listed price is the total.
Request an audit
Send a link to the repo or the product, and a few sentences on why the audit has come up now. I reply within two business days, telling you whether I'll take it and when I can start.
or email me directly: contact@mihalytari.com
or call me: +36 30 179 8852
Before sending, please read the privacy notice .