Drop a GitHub repo. We scan for the 15 vulnerabilities that vibe-coding tools leak most — exposed keys, missing RLS, open CORS, dangerous innerHTML — and translate them into plain English with copy-paste fixes.
const key = "sk-proj-abc123…"
createClient(url, SERVICE_ROLE)
{ "Access-Control-Allow-Origin": "*" }password: "admin"
Drop a GitHub URL. We pull files through the GitHub API — nothing to install.
Static analysis + Anthropic Claude catch the classics vibe-coding tools leave behind.
Zero critical/high findings? Get a public badge URL and embed it on your launch page.
These are the issues we see over and over in Lovable, Bolt, v0, and Cursor output. If you can paste a repo, you can find them before your users do.
Free while in beta. Sign up, paste a repo, and ship with confidence.
Get started →