VibeShield
Vibe code scanner · free

What is a vibe code scanner?

It's the tool that checks an AI-built app the way an attacker would — from the public URL — for the mistakes Lovable, Bolt, Cursor, and Replit apps ship most often. Paste your URL below for a free scan.

Why vibe-coded apps need a different scanner

Traditional SAST assumes a clean repo and CI. Vibe-coded products often fail in configuration and runtime: Supabase RLS left off in the dashboard, VITE_ / NEXT_PUBLIC_ secrets baked into the bundle, preview hosts sharing production keys. A vibe code scanner starts where the attacker starts — your live URL — then hands you a plain-English fix and a prompt you can paste back into your builder.

  • Exposed API keys and secrets in client JavaScript
  • Supabase tables readable without Row Level Security (row counts only)
  • Missing security headers, CORS mistakes, cookie flags
  • Exposed .env, .git, and backup files
  • Accessibility (WCAG) issues in a real browser
  • SEO & AEO: titles, meta, llms.txt, AI crawler access

Scan by the tool you built with

Platform pages target how people actually search — "Lovable security scanner", "Bolt app security", and so on.

Prefer a checklist? See the vibe-coding security checklist.

Free vs Pro vs Business

Free

$0

Instant security scan + Basic account with Security, Accessibility, and AI fix prompts.

Pro

$19/mo

Active attack checks, weekly monitoring, email alerts, white-label PDF/JSON, fix-everything prompt.

Business

$39/mo

Deploy webhooks, daily schedules, Slack/Discord/ClickUp, GitHub scans, API keys for CI.

Compare plans & upgrade

Common questions

What is a vibe code scanner?
A vibe code scanner is an automated security tool that probes a live AI-generated web app for failure modes common in apps built with Lovable, Bolt, Cursor, v0, and Replit — exposed API keys in the browser bundle, missing Supabase or Firebase access controls, weak headers, and open files. It runs against your public URL, no source code required.
How is VibeShield different from other vibe scanners?
Most vibe scanners only check security. Every signed-in VibeShield scan also audits accessibility (WCAG), SEO & AEO (whether ChatGPT, Claude, and Perplexity can find and cite you), and what your page ships (bundle & tech) — with copy-paste fix prompts for your builder.
Do I need a paid plan?
No. The free instant scan runs a passive security pass with no signup. A free Basic account unlocks Security + Accessibility and AI fix prompts. Pro ($19/mo) unlocks all four tools, PDF/JSON export, weekly monitoring, and white-label reports. Business ($39/mo) adds deploy scans, Slack/Discord alerts, and GitHub.
Is scanning safe on production?
Yes for the free/passive path — read-only requests to the same URL a visitor can load. Optional Pro/Business active checks send a small number of non-destructive probes; only enable those on apps you are authorized to test.