overview
total users
—
premium
—
total analyses
—
today
—
avg score
—
est. MRR
—
top products
loading…
category breakdown
loading…
Prelaunch Signups · — total
| # | Date | IP | |
|---|---|---|---|
| loading… | |||
users — —
| id | plan | status | reg ip | last ip | last login | analyses | joined | actions | |
|---|---|---|---|---|---|---|---|---|---|
| loading… | |||||||||
analyses — —
| user | product | category | country | budget | score | viability | ip | date |
|---|---|---|---|---|---|---|---|---|
| loading… | ||||||||
errors — 0 total · 0 last 24h · 0 client · 0 server
auto-refresh 5s
| time | src | type | message | user / ip | url |
|---|---|---|---|---|---|
| loading… | |||||
growth — last 30 days
new signups / day
analyses / day
score distribution
top categories
financials
MRR
—
ARR (12×)
—
Premium — $14.99
—
Free users
—
plan distribution
conversion funnel
key takeaways
computing…
conversion funnel — visitor → signup → analysis → premium
today: —
loading…
visitor → signup
—
signup → analysis
—
analysis → premium
—
visitor → premium
—
daily funnel — last 30 days
top referrers
| source | visits | unique |
|---|---|---|
| loading… | ||
top landing paths
| path | visits | unique |
|---|---|---|
| loading… | ||
cohort retention — % of signups still active on day N
active = login OR analysis on that day
total cohorts
—
day 1 retention
—
day 7 retention
—
day 30 retention
—
average retention curve — all cohorts pooled
retention heatmap — rows are cohorts, columns are days after signup
| loading… |
insights
geographic distribution — where your users come from · where they sell to
geoip-lite not installed — run npm install geoip-lite in your project, then restart the server.
user countries
—
visitor countries
—
target markets
—
geoip status
—
users by country — where signups come from
loading…
visitors by country — last 30 days, unique IPs
loading…
target markets — where your users sell their products
loading…
free quota usage — target list for premium upgrades
total signups
—
free users
—
hit limit
—
paying
—
conversion %
—
conversion funnel
loading…
🔥 hot prospects — hit free limit + active in last 30d · best upgrade targets
| last login | logins | analyses | best score | last category | actions | |
|---|---|---|---|---|---|---|
| loading… | ||||||
cold prospects — signed up, never analyzed
| signed up | logins | |
|---|---|---|
| loading… | ||
⚠ multi-account ips — possible abuse
| ip | count | emails |
|---|---|---|
| loading… | ||
✓ recent upgrades — conversion velocity · avg — days from signup
| plan | signed up | first analysis | analyses | |
|---|---|---|---|---|
| loading… | ||||
stripe — live payments · subscriptions · refunds
all-time revenue
—
last 30 days
—
today
—
active subs
—
past due
—
refunds total
—
recent payments — 0
| time | amount | customer | card | status | id | |
|---|---|---|---|---|---|---|
| loading… | ||||||
subscriptions — 0
| customer | status | amount | interval | started | next billing | cancels? | sub id |
|---|---|---|---|---|---|---|---|
| loading… | |||||||
refunds — 0
| time | amount | reason | status | charge |
|---|---|---|---|---|
| loading… | ||||
failed payments — 0
| time | amount | customer | reason |
|---|---|---|---|
| loading… | |||
api keys & costs — real-time spend per key
loading…
claude — detailed breakdown
all time
—
last 30 days
—
today
—
avg / call
—
gross margin 30d
—
daily cost — last 30 days (USD)
by model
| model | calls | in tok | out tok | cost |
|---|---|---|---|---|
| loading… | ||||
by endpoint
| endpoint | calls | cost |
|---|---|---|
| loading… | ||
top spenders — cost per user
| calls | in tok | out tok | cost | |
|---|---|---|---|---|
| loading… | ||||
recent calls (last 100)
| time | endpoint | model | in | out | cost | |
|---|---|---|---|---|---|---|
| loading… | ||||||
services & api costs — every external service Drop Sniper uses
est. monthly tech cost
—
all-time spend
—
net margin 30d
—
active services
—
loading…
cost forecast — MRR vs AI cost · 30 day projection
current MRR
—
current ARR
—
AI cost 30d
—
gross margin %
—
break-even users
—
30 day history + 30 day forecast (USD)
insights
category & product trends — what's analyzed · what's scoring high
top categories last 30 days — vs previous 30 days
| category | analyses | users | avg score | avg budget | trend |
|---|---|---|---|---|---|
| loading… | |||||
daily volume — top 5 categories
top recommended products (30d)
| product | count | avg score |
|---|---|---|
| loading… | ||
score distribution — all time
loading…
system health — uptime · memory · response times · errors
uptime
—
memory (RSS)
—
db size
—
req / hour
—
p95 response
—
5xx / hour
—
response time percentiles (last hour)
loading…
database tables
loading…
slowest endpoints (last hour)
| path | count | avg ms | max ms |
|---|---|---|---|
| loading… | |||
runtime info
loading…
login sessions — —
| time | kind | result | ip | browser | os | device | user agent | |
|---|---|---|---|---|---|---|---|---|
| loading… | ||||||||
security events — 0 total · 0 last 24h
refreshed on tab open
| time | event | ip | url | details |
|---|---|---|---|---|
| loading… | ||||
event type breakdown
loading…
audit log — every admin action, immutable record
total: —
| time | action | target | details | ip | admin |
|---|---|---|---|---|---|
| loading… | |||||
two-factor authentication — TOTP · Google Authenticator / Authy / 1Password
status
loading…
step 1 — scan with your authenticator app
generating QR…
Open Google Authenticator, Authy, 1Password, or Microsoft Authenticator and scan the QR code.
or enter manually
—
step 2 — enter the 6-digit code from your app
⚠ backup codes — save these now
Each backup code can be used once to log in if you lose access to your authenticator app. Store them in a password manager or print them. You will not see them again.
disable 2FA
Enter your current 6-digit code OR a backup code to disable 2FA. Disabling reduces account security significantly.
threat detection — automated suspicious activity flagging · 7 rules active
last hour
—
last 24h
—
unique ips 24h
—
total flagged
—
rule activity — flags per rule (all time)
showing: —
| time | rule | sev | ip | details | action |
|---|---|---|---|---|---|
| loading… | |||||
how it works
7 detection rules run automatically on every request + every 5 minutes in the background:
• Account flood — 10+ accounts from one IP in 1 hour
• Rapid burst — 3+ accounts from one IP in 10 minutes
• Credential stuffing — 3+ failed logins on different emails from one IP in 5 minutes
• Impossible travel — Login from different country within 5 minutes of last login (geo-IP)
• Analysis abuse — 50+ analyses from one user in 1 hour (scripted use)
• Bot UA — curl/wget/python-requests/scrapy/headless chrome user agents on auth endpoints
• High fail rate — 10+ failed logins from one IP in 1 hour (background sweep)
All detections deduplicated to 10 minutes per (rule, IP). Click "block IP" on any threat to add a permanent deny rule.
• Account flood — 10+ accounts from one IP in 1 hour
• Rapid burst — 3+ accounts from one IP in 10 minutes
• Credential stuffing — 3+ failed logins on different emails from one IP in 5 minutes
• Impossible travel — Login from different country within 5 minutes of last login (geo-IP)
• Analysis abuse — 50+ analyses from one user in 1 hour (scripted use)
• Bot UA — curl/wget/python-requests/scrapy/headless chrome user agents on auth endpoints
• High fail rate — 10+ failed logins from one IP in 1 hour (background sweep)
All detections deduplicated to 10 minutes per (rule, IP). Click "block IP" on any threat to add a permanent deny rule.
webhook monitor — stripe + resend delivery + signature verification
today total
—
today failed
—
invalid sig 7d
—
avg latency
—
by source (7 days)
| source | total | success | avg ms |
|---|---|---|---|
| loading… | |||
top event types (7 days)
| event type | count |
|---|---|
| loading… | |
recent deliveries (last 200)
| time | source | event type | event id | sig | status | ms |
|---|---|---|---|---|---|---|
| loading… | ||||||
background jobs — scheduled tasks · db backup · cleanup · weekly email
scheduled jobs
loading…
recent runs (last 100)
| started | job | status | duration | result / error |
|---|---|---|---|---|
| loading… | ||||
security audit — response headers grade · jwt secret rotation
security headers grade
—
header-by-header
loading…
⚠ jwt secret rotation
Rotate
• You suspect JWT_SECRET was leaked (e.g. accidentally committed to git)
• A laptop with the .env was stolen
• After a security incident, as a precaution
CRITICAL EFFECTS: All existing JWT tokens become invalid — every user including you must log in again. Server must be restarted manually for the new secret to take effect.
JWT_SECRET in .env. Use when:• You suspect JWT_SECRET was leaked (e.g. accidentally committed to git)
• A laptop with the .env was stolen
• After a security incident, as a precaution
CRITICAL EFFECTS: All existing JWT tokens become invalid — every user including you must log in again. Server must be restarted manually for the new secret to take effect.
feature usage — what users actually do · roadmap signal
usage by feature (last 30 days)
| feature | actions | unique users | heatmap |
|---|---|---|---|
| loading… | |||
daily — top 5 features
power users (last 30 days)
| user | plan | actions | features |
|---|---|---|---|
| loading… | |||
recent activity
| time | user | feature |
|---|---|---|
| loading… | ||
a/b tests — 50/50 split · conversion tracking · winner selection
create new test
active + archived tests
loading…
how to use
1. Create a test (e.g.
2. In your frontend, fetch
3. Render the variant based on the response. Each user gets a sticky assignment.
4. When the user completes the goal (e.g. signs up for premium), call
5. Watch this panel for conversion rates. Archive with a winner when confident.
pricing_v2).2. In your frontend, fetch
GET /ab/pricing_v2 — returns { variant: 'A'|'B', label: '...' }.3. Render the variant based on the response. Each user gets a sticky assignment.
4. When the user completes the goal (e.g. signs up for premium), call
POST /ab/pricing_v2/convert.5. Watch this panel for conversion rates. Archive with a winner when confident.
push notifications — browser push for operational alerts
loading…
subscribed browsers
| subscribed | browser | last used |
|---|---|---|
| loading… | ||
recent notifications sent
| sent | title | delivered | failed |
|---|---|---|---|
| loading… | |||
setup (one-time)
1. In terminal:
2. Generate VAPID keys:
3. Add the output to
4. Restart server. Then click "enable on this browser" above and accept the browser permission prompt.
5. Auto-fired events: payment received. Click "send test" to verify.
cd ~/Desktop/testapp && npm install web-push2. Generate VAPID keys:
npx web-push generate-vapid-keys3. Add the output to
.env:VAPID_PUBLIC_KEY=...VAPID_PRIVATE_KEY=...4. Restart server. Then click "enable on this browser" above and accept the browser permission prompt.
5. Auto-fired events: payment received. Click "send test" to verify.
ip access control — admin panel firewall
your current ip: —
add rule
active rules — deny rules always override · localhost always allowed
| type | pattern | description | added | by | actions |
|---|---|---|---|---|---|
| loading… | |||||
⚠ safety rules
• localhost (127.0.0.1) is always allowed regardless of rules
• Adding your first allow rule that doesn't cover your current IP is blocked to prevent lockout
• Deleting a rule that would orphan your IP is blocked
• CIDR supported: /8, /16, /24 (e.g. 203.0.113.0/24)
• Recommended setup: add an allow rule for your home/office/VPN IP first, then add deny rules for known bad IPs
• Adding your first allow rule that doesn't cover your current IP is blocked to prevent lockout
• Deleting a rule that would orphan your IP is blocked
• CIDR supported: /8, /16, /24 (e.g. 203.0.113.0/24)
• Recommended setup: add an allow rule for your home/office/VPN IP first, then add deny rules for known bad IPs
rate limit blocks — 0 total blocks
login blocks
—
admin blocks
—
general blocks
—
| time | limiter | ip | url | details | browser/os |
|---|---|---|---|---|---|
| loading… | |||||
top blocked IPs (last 30 days)
loading…
activity feed — —
loading…
broadcast — send mass email to user segments
compose
recent broadcasts
| sent at | subject | recipients | sent | failed |
|---|---|---|---|---|
| loading… | ||||
stripe coupons — discount codes for checkout
create new coupon
active coupons
| code | discount | duration | redeemed | expires | status | actions |
|---|---|---|---|---|---|---|
| loading… | ||||||
email analytics — resend delivery, open + click rates
📡 webhook setup: for real open/click rates, set
https://yourdomain.com/webhook/resend in your Resend dashboard. Without it, only sent/failed counts are tracked.
sent (all time)
—
sent 30d
—
delivery rate
—
open rate
—
click rate
—
daily volume — last 30 days
performance by template
| template | sent | delivered | opened | clicked | open rate |
|---|---|---|---|---|---|
| loading… | |||||
recent failures
| time | to | subject | error |
|---|---|---|---|
| loading… | |||
done-for-you lists curated picks for premium & agency tiers
Free → blocked · Premium → monthly TOP 5 · Agency → weekly TOP 10
// CREATE NEW LIST
all lists
| tier | period | label / title | items | status | created | actions |
|---|---|---|---|---|---|---|
| loading... | ||||||
// ITEMS
// NEW ITEM
// AGENCY MINI-DOSSIER
| # | product | category | score | viability | profit | avg price | actions |
|---|---|---|---|---|---|---|---|
| no items yet | |||||||
Guest / Free Analyses
Anonim (kayıtsız) ziyaretçilerin IP başına ücretsiz analiz kullanımı. Limit: 3/IP — kalıcı, sıfırlanmaz.
–
Unique IPs
–
Total analyses
–
Hit limit (3/3)
Usage by IP
| IP | Used | First seen | Last seen |
|---|---|---|---|
| Loading… | |||
Guest demo pool — misafirlere gösterilen ürünler (müşteri analizleri DEĞİL)
| Category | Product | Score | |
|---|---|---|---|
| Loading… | |||
Recent analyses
| When | IP | Category | Product | Score |
|---|---|---|---|---|
| Loading… | ||||
free quota usage conversion targeting · who's hitting the limit
total free
—
avg usage
— / 3
at limit
—
conversion pool
—
engagement
—%
usage distribution
at limit · hot conversion targets
| usage | resets | joined | action | |
|---|---|---|---|---|
| loading... | ||||
warm leads · 2 of 3 used
| usage | resets | joined | action | |
|---|---|---|---|---|
| loading... | ||||