Live
GateTest status
Whether each surface is up right now, and what happened recently. Every state on this page is read from a probe that already runs against production — nothing is typed by hand, and a surface we cannot verify says so instead of showing green.
Partial degradation — some features are slower or limited.
checked 364s ago · refreshes every 30s
Components
Website
Serving requests on version 1.61.1.
OperationalHosted scans
1 scan could not complete after retries; 0 queued, 0 running.
DegradedScan worker
Idle — last job activity 9 days ago.
OperationalGitHub App webhooks
Last delivery accepted 9 days ago.
OperationalAPI
Responding; 2 optional integrations are not fully configured.
DegradedMCP hosted endpoint
Reachable; accepting connections from MCP clients.
OperationalPayments
Checkout and subscription updates working.
Operational
Running build
- Version
- v1.61.1
- Commit
- 4b63bada
- Built
- 2026-09-19 15:02 UTC
Incidents — last 14 days
Production deploy paused
No customer impactResolved
An automated deploy to production was refused by its own safety check after uncommitted changes were found on the server. The check worked as designed: production kept serving the previous build throughout, and no customer-facing surface changed. Deploys resumed once the server checkout was cleaned up.
Phishing e-mail sent through a shared e-mail provider account
No customer impactResolved
A third party obtained an e-mail-provider key belonging to the hosting platform's own service, on an account that also carried our sending domain, and used it to send phishing mail that spoofed one of our sender addresses. GateTest was a bystander: no GateTest system, key or customer data was involved, and no GateTest scan, sign-in, checkout or notification was affected. The compromised key was revoked and the account is being split so no other product's key can send as our domain again. If you received one of these messages, delete it; GateTest never asks for card or identity details by e-mail.
How this page is produced: the configuration readiness probe, the build stamp, the scan queue and a reachability check of the hosted MCP endpoint are read every 30 seconds and mapped to four states. The mapping is a pure function with its own tests, including one that feeds it hostile input and asserts no internal name reaches this page.
Something wrong that this page does not show? Trust & security → What shipped recently →