Features
Find it. Fix it. Keep it fixed.
Security and accessibility on Free. Pro unlocks SEO & AEO, Bundle, export, and weekly monitoring — Business adds deploy scans, Slack, and GitHub — so you can ship without handing attackers an easy win.
Find
What an attacker — or an answer engine — would see from your public URL alone. No login credentials, ever.
Exposed keys & secrets
FreeOpenAI, Stripe, AWS, Supabase service keys and more in your shipped JavaScript and page data.
Supabase Row Level Security
FreeWhich tables your public key can read — row counts only, never the data — plus sign-up settings.
Headers, cookies, CORS & HTTPS
FreeMissing CSP/HSTS, insecure cookies, permissive CORS, certificate and redirect problems.
Exposed files
Free.env, .git, backups and source maps that shouldn't be public.
Accessibility (Free) · SEO & AEO + Bundle (Pro)
FreeBasic includes WCAG 2.2 in a real browser. Pro unlocks on-page SEO plus AI visibility (llms.txt, AI crawlers) and Bundle & Tech — all four tools in one report.
Active checks
ProNon-destructive probes for SQL injection, XSS, open redirects and missing rate limits.
Fix
Plain-English findings, ranked by what to fix first — and prompts that fix them in the tool you build with.
Fix-now / fix-next priority
FreeEvery finding has severity, evidence, impact and a concrete fix.
AI fix prompts
FreeCopy a ready-made prompt for Lovable, Bolt, v0, Cursor or Claude Code.
Re-scan to verify
FreeOne click re-runs the scan and shows exactly what's fixed and what isn't.
Fix everything in one prompt
ProAll issues, most urgent first, in a single paste.
AI remediation assistant
BusinessAsk why a finding matters or how to fix it in your stack — using only that scan's evidence.
Monitor
Your app changes with every prompt. Catch the change that breaks something, not days later.
Weekly scheduled scans
ProRe-scan on a weekly cadence without lifting a finger. Email alerts on new critical/high issues.
Changes since last scan
ProNew, resolved and changed issues between project runs.
Score history
FreeSecurity, accessibility, SEO & AEO, and bundle scores over time (last 5 on Free, more on paid plans).
Daily schedules & deploy hooks
BusinessDaily re-scans, plus a webhook for Vercel, Netlify, or any CI after a successful deploy.
Slack, Discord & ClickUp alerts
BusinessChat and task alerts the moment a monitored scan finds a new critical or high issue.
Share & integrate
Show clients and users you take security seriously — and wire it into how you ship.
Share links & grade badge
FreeA public read-only report and an embeddable badge for your README or site.
White-label reports
ProYour name and logo on PDFs and share pages — and no VibeShield badge branding.
CI API keys
BusinessTrigger scans from any pipeline and fail the build on critical issues.
GitHub repo scanning
BusinessScan source and dependencies, and comment on pull requests.
CLI & VS Code extension
FreeScan localhost and your source code without leaving the terminal or editor.
See what your app is exposing — free
No signup for your first security scan.
Compare Free, Pro, and Business