Security and privacy decision
lock.pub
A competent developer can build and run a safe, passworded short-link service for one user with modest monthly hosting; existing open-source URL shorteners cover most core functionality so self-hosting or reusing them reduces work.
Visit website↗Not priced
No pricing page we fetched carried a figure, so there is nothing to compare against. The build side is still real.
$100one-off36 h to build
$25/mo3 h/mo upkeep
No published price to break even against.
No open-source build does this yet
Nothing published replaces this one, so a replacement starts from an empty file. Here is what it would have to cover.
What a replacement has to do
- Create passworded short links, store encrypted payload/metadata, verify password on access and redirect or show content, enforce expiration and access limits, provide a minimal creator UI to make/manage links.
What it still won’t have
- Polished multi-language UI and marketing content
- Browser extensions and ecosystem integrations
- High-availability, global scale and DDoS protection
- Built-in guides, blog content, and curated help articles
- Brand trust and existing user base
What remains hard
- Product polish and ongoing maintenance
First-year cost
No published price
lock.pub does not publish a price we could read, so there is nothing to compare against. What building costs is below.
Money you would actually spend
Time you would spend
—
What you would spend
What we assumed
The verdict above measures whether you could build it. This one is only about money.
Runnable build prompt
Build a minimal password-protected link shortener using: Node.js (Express) + TypeScript, Postgres, and a small React UI; deploy on a single $5–20/month VPS (or Heroku/DigitalOcean) with HTTPS (Caddy). Core features in scope: create short links with an optional password, store encrypted payload or password hash and metadata (expiry, max-views), serve redirect or content after password validation, track and display basic read receipts in a lightweight dashboard, background job to purge expired links. Out of scope: analytics dashboard with charts, browser extensions, multi-tenant billing, global scale or enterprise compliance. Require: server-side input validation, rate limiting, password hashing/encryption best practices, error handling for all endpoints, unit tests for API logic and integration tests for create->access flows, and deployment scripts (Dockerfile + simple run instructions).
How we checked
How the score was reached
- Build verdict base78
- Evidence score78
The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.
How scoring works →Integrity checks
What held up, and what did not.


