CheckVibeCodeCheckVibeCode

Ship fast.
Don't ship broken.

CheckVibeCode scans the app you just vibe-coded — exposed keys, missing RLS, broken SEO, and pages AI can't see — and tells you exactly what to fix.

No install. No agent. Just a URL — free, no card required.

49

scanners

378+

checks run

<60s

to first result

Live
78/ 100

yourapp.com

12 issues found · 1 critical

+6 since last scan

  • Security

    3

    2 exposed keys · no RLS on 1 table

  • SEO

    4

    Missing meta on 4 pages

  • AEO

    2

    Not cited by ChatGPT or Claude

  • Performance

    3

    LCP 4.1s on mobile

A real scan result, redacted from a live report

Beyond the scan.
Watch it, defend it, get it found.

A clean report is just the start. CheckVibeCode keeps watch on your live site and gets verified apps in front of AI.

AEO scanner

See what AI says about you.

Buyers now ask ChatGPT, Claude, and Perplexity what to use. CheckVibeCode scans your site the way an answer engine reads it, and shows you exactly why you're getting left out of the answer.

Run an AEO scan
AI Assistant
Which security scanner should I use?

Know exactly when someone's trying to hack you.

Watch real attacks hit your live site the moment they happen: credential stuffing, scraping, and injection probes, each with the attacker's IP and an instant alert.

Live threats · last 24hMonitoring
185.220.101.4 Credential stuffingAlerted

Know exactly when your site goes down.

60-second uptime probes with instant down-and-recovery alerts and a public status page. You hear it from us, not from an angry customer.

status.yourapp.comOperational
90 days99.98% uptime

The full website health stack.
One scan.

Every level runs against your live site. No agents, no code changes.

Browse all 378+ checks across 49 scanners

Seven levels, one report.

100+ security probes, crawl and Core Web Vitals runs, uptime and compliance checks. Ranked by impact, each with a fix.

78

yourapp.com

Overall health · 3 to fix

Live
  • Security

    Headers, keys & RLS

    See more ›
  • SEO

    Crawl, sitemap & meta

    See more ›
  • AEO

    AI-engine citations

    See more ›
  • Performance

    Core Web Vitals & uptime

    See more ›
  • Domain

    WHOIS, DNS & takeover risk

    See more ›
  • Compliance

    Privacy & cookie consent

    See more ›
  • Accessibility

    WCAG 2.2 AA & EAA signals

    See more ›

GitHub. Supabase. Every MCP client.

Scan any stack out of the box, connect GitHub and Supabase for deeper audits, and pull findings into Claude, Cursor, or any MCP client.

Bolt
v0v0
Lovable
Replit
Cursor
Windsurf
GitHub
Vercel
Next.js
Supabase
Claude
VS Code

Works with the tools you already vibe-code in.

Built for developers.
The report is just the start.

Wire CheckVibeCode into the way you already work.

checkvibecode mcp

$ claude mcp add checkvibecode -- npx -y @checkvibecode/mcp-server

✓ Connected. 10 tools available.

> run_scan yourapp.com

security 92 seo 88 aeo 76 · 12 findings

$

MCP Server

10 tools. Run scans and pull findings from Claude, Cursor, or any MCP client.

yourapp/webSecretsSAST

Repo scanning

Connect GitHub and scan the code behind the site: SAST, secrets, dependencies.

MonitoringDaily

Daily monitoring

CheckVibeCode re-checks your site on a schedule and emails you the moment your score gets worse.

security-reportDownload

Exports

Every report as PDF and Markdown, built for handoffs and paper trails.

Domain health88/100
TLS certificatevalid · 74d

Domain health

Registration runway, registrar locks, DNS resilience, and certificate expiry — caught before they bite.

SCORE OVER TIMEJun 28 – Jul 14

Scan history & diffs

Every scan is kept. Watch the score recover as things break and get fixed.

Shipping weekly

7 new scanners
in the last month.

The threat surface for vibe-coded apps moves fast. So do we — new checks, deeper crawls, and more answer engines, every week.

  1. New scanner

    Git History Secret Scanner — finds credentials that were committed then deleted, still live in your history

  2. New scanner

    AI Tooling Configuration Scanner — API keys in committed MCP configs, and servers auto-run from unpinned packages

  3. New scanner

    Dependency Supply Chain Scanner — lockfile integrity, install-time scripts, dependency-confusion exposure

  4. New scanner

    GitHub Actions Supply Chain Scanner — workflow script injection, untrusted-code execution, exposed self-hosted runners

  5. Improved

    Leaked keys are now verified against the issuer, so a report says "this key still works" instead of "this looks like a key"

Follow along on the blog
Aadarsh

Hey, I'm Aadarsh!

I shipped my first real app in a weekend — a prompt, a Supabase project, a deploy, done. Two days later someone DM'd me a screenshot of my service key sitting in the client bundle.

So I went looking for something that would just tell me what was broken. Everything was either an enterprise security suite with a sales call attached, or an SEO dashboard with forty tabs. I didn't want to learn a product. I wanted a list.

That's the whole idea behind CheckVibeCode. Paste a URL, wait under a minute, get 378+ checks across 49 scanners — leaked keys, missing RLS, dead meta tags, pages ChatGPT can't read — sorted by what will actually bite you, with the fix sitting right next to it.

Security, SEO, AEO, performance and uptime all live in one scan because to me they were never separate questions. They were one question: is my app okay right now?

I'm one person shipping this every week, and I read every reply. If you build fast with AI and want something double-checking behind you, this was built for you.

Scan my app

Free, no card. Or say hi on X.

Simple pricing, real limits.

Start free with one full audit. Upgrade to unlock every fix, daily re-scans, and room for more projects and clients.

Free

One full audit, no card

$0

Free forever · no card

See every score. Fix one on us.

  • 1 full audit · 378+ checks
  • All 7 levels scored
  • 1 finding unlocked + fix
  • 1 project · 1 repo
  • Apex uptime + status page

Starter

For solo makers shipping fast

$24/month

billed monthly · save 30% annually

The full report, re-run every day.

  • 1 project · 1 repo
  • 10 scans / mo + daily auto-scan
  • Every finding + paste-ready fix
  • GitHub + Supabase code scans
  • Dependency & supply-chain scan
  • SEO & AEO scans
  • Regression alert emails
  • PDF + Markdown exports
  • 1 API key + MCP server
  • 3 uptime monitors + status page
Most popular

Pro

For growing products & multi-repo projects

$49/month

billed monthly · save 30% annually

Deep Scan + live attack alerts.

  • 5 projects · 5 repos each
  • 250 scans / mo + daily auto-scan
  • Deep Scan — crawl + semgrep SAST
  • Live threat detection + attacker IPs
  • Every finding + paste-ready fix
  • GitHub + Supabase code scans
  • Dependency & supply-chain scan
  • SEO & AEO scans
  • PDF + Markdown exports
  • 5 API keys + MCP server
  • 5 uptime monitors + status page

Max

For agencies delivering audits to clients

$99/month

billed monthly · save 30% annually

Unlimited scans. White-label. Resale.

  • 25 projects · 25 repos each
  • Unlimited scans + daily auto-scan
  • Deep Scan + live threat detection
  • White-label reports — your brand
  • Commercial resale & client delivery
  • Every finding + paste-ready fix
  • GitHub + Supabase code scans
  • Dependency & supply-chain scan
  • SEO & AEO scans
  • PDF + Markdown exports
  • 25 API keys + MCP server
  • 10 uptime monitors + priority support

Full breakdown of every limit on the pricing page.

Frequently Asked Questions

Have another question? Reach out on Twitter or by email.

Is it safe to scan a live site?

Yes. Every check is a read-only probe of what your site already serves publicly — the same requests a browser or a search crawler makes. Nothing is written, submitted or changed, and the traffic is no heavier than a handful of page views.

What does a scan check?

One pass runs 378+ checks across seven levels — Security (exposed secrets and .env files, open storage buckets, missing headers, CORS and CSP, auth and injection surface), plus SEO, AEO, Performance, Domain, Compliance and Accessibility. You get one overall score, a per-level breakdown and every finding with the evidence behind it.

What is AEO, and why does it matter?

Answer Engine Optimization — whether ChatGPT, Claude, Perplexity and Google's AI answers can crawl, understand and cite your site when someone asks about your space. The AEO scanner reads your site the way an answer engine does and shows exactly what is keeping you out of the answer.

Do I need to install anything?

No. Paste a URL and the scan runs against your live site in about a minute. Connecting GitHub for source-level scanning — SAST, dependency and webhook-signature checks — is optional and read-only.

What do threat detection and monitoring watch for?

On paid plans CheckVibeCode keeps watching after the scan: it flags credential stuffing, scraping and injection probes hitting your live site — each with the attacker's IP and an instant alert — and runs 60-second uptime probes with down-and-recovery alerts and a public status page.

What do paid plans add?

The free scan shows your scores and one taster finding. Paid plans unlock every finding with paste-ready fixes, continuous threat detection, uptime monitoring, scheduled daily re-scans and API access. Plans scale with how many projects and scans you run.

How often can I scan?

Free includes one full scan. Paid plans re-scan automatically every day plus a monthly pool of manual scans (10 on Starter, 250 on Pro, unlimited on Max), so regressions get caught the day they ship.

Shipping doesn't stop.
Neither does the watching.

A clean scan is a snapshot. The next deploy can undo it. CheckVibeCode keeps checking your live site so a regression reaches you before it reaches your users.

Daily re-scans

Emailed the moment your score drops

Attack alerts

Credential stuffing, scraping, injection probes

60s uptime probes

Down-and-recovery alerts + a status page

Scan now, watch after

First scan is free. Monitoring is on every paid plan.