What is a vibe code scanner?
It's the tool that checks an AI-built app the way an attacker would — from the public URL — for the mistakes Lovable, Bolt, Cursor, and Replit apps ship most often. Paste your URL below for a free scan.
Why vibe-coded apps need a different scanner
Traditional SAST assumes a clean repo and CI. Vibe-coded products often fail in configuration and runtime: Supabase RLS left off in the dashboard, VITE_ / NEXT_PUBLIC_ secrets baked into the bundle, preview hosts sharing production keys. A vibe code scanner starts where the attacker starts — your live URL — then hands you a plain-English fix and a prompt you can paste back into your builder.
- Exposed API keys and secrets in client JavaScript
- Supabase tables readable without Row Level Security (row counts only)
- Missing security headers, CORS mistakes, cookie flags
- Exposed .env, .git, and backup files
- Accessibility (WCAG) issues in a real browser
- SEO & AEO: titles, meta, llms.txt, AI crawler access
Scan by the tool you built with
Platform pages target how people actually search — "Lovable security scanner", "Bolt app security", and so on.
- Lovable security scanner
- Bolt security scanner
- v0 security scanner
- Cursor security scanner
- Replit security scanner
Prefer a checklist? See the vibe-coding security checklist.
Free vs Pro vs Business
Free
$0
Instant security scan + Basic account with Security, Accessibility, and AI fix prompts.
Pro
$19/mo
Active attack checks, weekly monitoring, email alerts, white-label PDF/JSON, fix-everything prompt.
Business
$39/mo
Deploy webhooks, daily schedules, Slack/Discord/ClickUp, GitHub scans, API keys for CI.
Common questions
- What is a vibe code scanner?
- A vibe code scanner is an automated security tool that probes a live AI-generated web app for failure modes common in apps built with Lovable, Bolt, Cursor, v0, and Replit — exposed API keys in the browser bundle, missing Supabase or Firebase access controls, weak headers, and open files. It runs against your public URL, no source code required.
- How is VibeShield different from other vibe scanners?
- Most vibe scanners only check security. Every signed-in VibeShield scan also audits accessibility (WCAG), SEO & AEO (whether ChatGPT, Claude, and Perplexity can find and cite you), and what your page ships (bundle & tech) — with copy-paste fix prompts for your builder.
- Do I need a paid plan?
- No. The free instant scan runs a passive security pass with no signup. A free Basic account unlocks Security + Accessibility and AI fix prompts. Pro ($19/mo) unlocks all four tools, PDF/JSON export, weekly monitoring, and white-label reports. Business ($39/mo) adds deploy scans, Slack/Discord alerts, and GitHub.
- Is scanning safe on production?
- Yes for the free/passive path — read-only requests to the same URL a visitor can load. Optional Pro/Business active checks send a small number of non-destructive probes; only enable those on apps you are authorized to test.