@rampa-solutions/cli
v0.2.0
Published
The review before you launch: accessibility, security, privacy, legal and surprise-bill risks of a website, from your terminal or your AI editor (MCP).
Maintainers
Readme
rampa
The review before you launch. Accessibility, security, privacy, legal and surprise-bill risks of a website, from your terminal or from your AI editor.
npx @rampa-solutions/cli check https://your-app.comSeconds, no account. It reads your home page the way any visitor does and tells you, in plain words and with the fix ready to paste:
- API keys exposed in your public JavaScript (Stripe, AWS, OpenAI, Anthropic, Supabase
service_role, GitHub, Slack, …) - Public files that should not be:
.env,.git, backups, source maps - Missing security headers, with the config for Vercel, Netlify, Next.js, Cloudflare or nginx
- Session cookies without
Secure/HttpOnly, TLS certificate about to expire - Libraries with known CVEs (jQuery, Bootstrap, lodash, Next.js, …)
- Supabase/Firebase used from the browser (detection only, with the RLS policy to paste)
- Surprise-bill risks: images over 1 MB, self-hosted video, forms with no bot protection
- Legal basics: privacy policy, terms, cookie notice when selling to Europe, accessibility statement
Exit code 1 when something critical or high is found: use it in CI.
The full scan
npx @rampa-solutions/cli scan https://your-app.com --email [email protected]Rampa's free scan: WCAG 2.2 with axe-core on desktop and phone, one code fix verified in a real browser, site health, the review above and a PDF. A 6-digit code is emailed to you; paste it when asked. About 2-3 minutes. Three a day per site.
From Claude Code or Cursor (MCP)
claude mcp add rampa -- npx -y @rampa-solutions/cli mcpCursor, .cursor/mcp.json:
{ "mcpServers": { "rampa": { "command": "npx", "args": ["-y", "@rampa-solutions/cli", "mcp"] } } }Then: "review my site with Rampa before I deploy". Tools: rampa_check (passive review, seconds), rampa_scan_start / rampa_scan_verify / rampa_scan_status (the full free scan).
What it does not do
Everything is passive: GET/HEAD of what your site already shows any visitor, respecting robots.txt. No fuzzing, no login attempts, no reading your database. It is not a penetration test, not a certification and not legal advice. Deeper checks (for example whether your Supabase tables are readable with the anon key) run only on sites you verify as yours in your Rampa dashboard, with your written authorization.
Don't want your site reviewed by Rampa? Add Disallow: / for User-agent: Rampa in robots.txt, or write to [email protected].
MIT · https://rampa.solutions
