For Base44

Base44 gives you a checklist. PeerRun gives you a verdict.

Base44's own instructions hand the testing job to you: a checklist, a button to see the app as a regular user, and a chat assistant that will help if you ask. That's honest of them. But it's still you, grading the thing you just described into existence.

Last verified 18 August 2026. We are not claiming to know what AI model Base44 uses internally. That is not something we know.

What Base44 actually is

You describe an app. Base44 hosts everything. Testing is still on you.

Base44's own instructions say: describe what you want to build, and it handles the design, the database, sign-ups, permissions, and hosting. Your app goes live right away on hosting Base44 runs for you. Underneath, it is a real codebase you can view and export, with a way to connect GitHub. Which AI model actually writes the code is not something we know, and we are not going to guess.

Once your app is generated, the checking Base44 documents is: a live preview, a manual testing checklist, and a button to see the app as a regular user. Its chat assistant can help if you ask. No written proof of testing is kept anywhere. There is also a separate Security Scan that looks across your whole app, including the database, for security problems. That is a scan of your code and data for weaknesses, not a record of anyone actually using the app.

Cited: Quick-start, security scan. PROMPT_TO_APP_PIPELINES Part 1 and 2; TARGET_ACCESS §3B.2.

Who can see your app is your choice

Public, Private, or Workspace-only. Sign-in is built in.

Public

Anyone on the internet can open the app. No account needed. Base44 automatically sets apps that look like landing pages to Public. Individual pages inside can still require sign-in.

Private

Only people you invite. Signing in is required. Until you grant us access, PeerRun sees a login screen, not your actual product.

Workspace-only

Signing in is required. Same rule applies: what's behind that wall stays Unknown, we never guess our way past it.

Cited: Managing access, login and registration. TARGET_ACCESS §3.1. We do not repeat third-party claims about "Private with self-signup." That claim is unverified in our notes.

An unusually complete export

What you see and what runs behind it can travel together.

On the Builder plan or higher, Base44 can export both your visible app and your database together, either by connecting GitHub or downloading a ZIP file. That is unusual. Most other builders we cover only export the part you can see, and leave your actual database and backend behind, connected to an outside service instead. A Base44 export can go further, when you actually hand that bundled backend over to us.

We won't promise the same depth of check every time. If all you give us is a public link, we can only see what anyone without an account can see. If you bring the full export, we can attempt more. Missing pieces are still BLOCKED or UNKNOWN, with the reason stated, never "your app is broken." We do not have a special integration with Base44.

Cited: GitHub local development, GitHub integration changelog. TARGET_ACCESS §5.7.

Honesty

What PeerRun will not be able to tell you

Signed-in and invite-only areas
Private, Workspace-only, and any page behind Base44's login screen stay Unknown until you grant us access.
A bot wall
Blocked, not broken. We have no way around it.
A checklist you already ticked yourself
We will not count your own ticks as evidence. Walking the app yourself is not the same as a signed PeerRun verdict.
What we do not claim
We don't know which AI model Base44 uses. There's no one-click importer. We are not saying their Security Scan is fake, it's a different job: checking your code and data for weaknesses, not proof someone used the app.

Questions people actually ask

Base44, specifically

I already saw the app as a user. Why do this again?

Because you're still the person who wrote the prompt and walked the checklist. PeerRun is a second opinion with an actual record of what it could see, including what stayed Unknown.

My app is Public. Isn't the link enough?

It's enough to load whatever any stranger can already see. Pages you've locked down and your login screen are still walls we can't get past alone. The export is how we reach the backend you actually built.

I am not on the Builder plan.

Then the GitHub and ZIP export may not be available to you. We won't invent a workaround for that. A Public link still gets us in the door. Consider upgrading, or copy out what the Code tab lets you copy, and bring that folder if you can.

Sources

What this page is allowed to say

  1. Base44 quick-start
  2. Managing access, login, security scan
  3. GitHub export. In-repo: TARGET_ACCESS §3.1, §5.7; PROMPT_TO_APP_PIPELINES Part 2

A ticked checklist is a feeling. A verdict is a record.

Sign in and bring the GitHub sync or the ZIP export.

We will not invent a pass. Anything behind your sign-in stays Unknown until you grant access. A robot-check is Blocked, not broken. The first look is on us.