Drop a GitHub repo or PR URL. We scan for the 30 vulnerabilities that vibe-coding tools leak most — exposed keys, missing RLS, open CORS, dangerous innerHTML — and translate them into plain English with copy-paste fixes.
const key = "sk-proj-abc123…"
createClient(url, ADMIN_KEY)
Access-Control-Allow-Origin → wildcard
password: "admin"
Drop a GitHub URL. We pull files through the GitHub API — nothing to install.
Static analysis + Anthropic Claude catch the classics vibe-coding tools leave behind.
Zero critical/high findings? Get a public badge URL and embed it on your launch page.
These are the issues we see over and over in Lovable, Bolt, v0, and Cursor output. If you can paste a repo, you can find them before your users do.
Free while in beta. Sign up, paste a repo, and ship with confidence.
Get started →