VibeShield

Simple, transparent pricing

Every signed-in Basic scan covers Security and Accessibility. Pro and Business unlock SEO & AEO, Bundle & Tech, PDF/JSON export, and monitoring. Start free. Pro is $19 for active checks, weekly monitoring, and white-label reports. Business is $39 for deploy scans, GitHub, and team alerts.

Paid plans are sold by Paddle.com, our reseller and merchant of record. Prices in USD; tax may be added at checkout.

Compare plans

Basic is Security + Accessibility. Pro adds SEO & AEO, Bundle, export, and weekly monitoring. Business adds deploy scans, Slack, and GitHub.

FeatureBasicProBusiness
Scans / monthfalsefalsefalse
Projectsfalsefalsefalse
Scan tools included———
PDF / JSON export———
Public share link———
Active checks (SQLi, XSS, redirects, rate-limit)———
Weekly scheduled scans———
Daily scheduled scans———
Email alerts on new critical / high issues———
Slack / Discord alerts———
Deploy webhook scans (any CI)———
GitHub manual repo scanning———
GitHub PR comments & status checks———
API keys for CI / CD———
White-label reports & remove badge branding———
One-click 'fix everything' AI prompt———
Changes since your last scan———
AI remediation assistant———
AI Tech & CDN detection———

Questions

How does billing work?

Pro and Business are billed monthly by Paddle, our reseller and merchant of record — they handle your card, taxes and receipts. Cancel any time from Settings → Plan & billing → Cancel subscription; your plan stays on until the end of the month you've paid for.

What happens if I hit my scan limit?

You'll be asked to upgrade before starting another scan that month. Nothing you've already run is deleted or hidden — your existing reports stay available.

Can I change plans later?

Yes. Upgrade to Pro or Business any time from here or from Settings — you're redirected straight to checkout and the plan activates automatically once payment is confirmed.

Do active security checks do anything destructive?

No. Even Pro and Business active checks (SQL injection, XSS, open-redirect, rate-limit probes) are non-destructive by design — they never modify data, brute-force credentials, or attempt denial-of-service. Only run them against targets you're authorized to test.