Paste one .html.erb view and see the raw, html_safe, params and CSRF findings a Rails security review sends back. 26 rules. Runs in this page — the file is never uploaded, and there is no account.
Loaded with a sample view so you can see the output straight away. Paste your own over it — it stays in this browser tab.
raw, <%==, Time.now, <%-)One payment, no subscription. 7-day refund, no questions asked. The audit you just ran stays free and unlimited.
An assistant reads what you paste it. These 26 rules read every line of every view, in the same order, every time — and they carry the Rails-specific reason, not a general "sanitise your input". A model that has never seen your app/views cannot tell you that line 214 of _row.html.erb is the one printing params[:q] into an attribute.
A senior Rails contractor bills $80–$140 an hour in 2026, and a scoped web-application penetration test starts around $5,000. This page finds the same class of escaping and CSRF defect in one view for nothing.
Escaping defects are found by whoever looks first. If that is your security reviewer, it is a blocked release; if it is someone outside, it is a stored-XSS disclosure against a page your users are already loading.