Ship fast.
Don't ship broken.
CheckVibeCode scans the app you just vibe-coded — exposed keys, missing RLS, broken SEO, and pages AI can't see — and tells you exactly what to fix.
No install. No agent. Just a URL — free, no card required.
49
scanners
378+
checks run
<60s
to first result
yourapp.com
12 issues found · 1 critical
+6 since last scan
Security
32 exposed keys · no RLS on 1 table
SEO
4Missing meta on 4 pages
AEO
2Not cited by ChatGPT or Claude
Performance
3LCP 4.1s on mobile
Beyond the scan.
Watch it, defend it, get it found.
A clean report is just the start. CheckVibeCode keeps watch on your live site and gets verified apps in front of AI.
See what AI says about you.
Buyers now ask ChatGPT, Claude, and Perplexity what to use. CheckVibeCode scans your site the way an answer engine reads it, and shows you exactly why you're getting left out of the answer.
Run an AEO scanKnow exactly when someone's trying to hack you.
Watch real attacks hit your live site the moment they happen: credential stuffing, scraping, and injection probes, each with the attacker's IP and an instant alert.
Know exactly when your site goes down.
60-second uptime probes with instant down-and-recovery alerts and a public status page. You hear it from us, not from an angry customer.
The full website health stack.
One scan.
Every level runs against your live site. No agents, no code changes.
Browse all 378+ checks across 49 scannersSeven levels, one report.
100+ security probes, crawl and Core Web Vitals runs, uptime and compliance checks. Ranked by impact, each with a fix.
yourapp.com
Overall health · 3 to fix
- See more ›
Security
Headers, keys & RLS
- See more ›
SEO
Crawl, sitemap & meta
- See more ›
AEO
AI-engine citations
- See more ›
Performance
Core Web Vitals & uptime
- See more ›
Domain
WHOIS, DNS & takeover risk
- See more ›
Compliance
Privacy & cookie consent
- See more ›
Accessibility
WCAG 2.2 AA & EAA signals
GitHub. Supabase. Every MCP client.
Scan any stack out of the box, connect GitHub and Supabase for deeper audits, and pull findings into Claude, Cursor, or any MCP client.
Works with the tools you already vibe-code in.
Built for developers.
The report is just the start.
Wire CheckVibeCode into the way you already work.
$ claude mcp add checkvibecode -- npx -y @checkvibecode/mcp-server
✓ Connected. 10 tools available.
> run_scan yourapp.com
security 92 seo 88 aeo 76 · 12 findings
$ ▍
MCP Server
10 tools. Run scans and pull findings from Claude, Cursor, or any MCP client.
Repo scanning
Connect GitHub and scan the code behind the site: SAST, secrets, dependencies.
Daily monitoring
CheckVibeCode re-checks your site on a schedule and emails you the moment your score gets worse.
Exports
Every report as PDF and Markdown, built for handoffs and paper trails.
Domain health
Registration runway, registrar locks, DNS resilience, and certificate expiry — caught before they bite.
Scan history & diffs
Every scan is kept. Watch the score recover as things break and get fixed.
7 new scanners
in the last month.
The threat surface for vibe-coded apps moves fast. So do we — new checks, deeper crawls, and more answer engines, every week.
- New scanner
Git History Secret Scanner — finds credentials that were committed then deleted, still live in your history
- New scanner
AI Tooling Configuration Scanner — API keys in committed MCP configs, and servers auto-run from unpinned packages
- New scanner
Dependency Supply Chain Scanner — lockfile integrity, install-time scripts, dependency-confusion exposure
- New scanner
GitHub Actions Supply Chain Scanner — workflow script injection, untrusted-code execution, exposed self-hosted runners
- Improved
Leaked keys are now verified against the issuer, so a report says "this key still works" instead of "this looks like a key"

Hey, I'm Aadarsh!
I shipped my first real app in a weekend — a prompt, a Supabase project, a deploy, done. Two days later someone DM'd me a screenshot of my service key sitting in the client bundle.
So I went looking for something that would just tell me what was broken. Everything was either an enterprise security suite with a sales call attached, or an SEO dashboard with forty tabs. I didn't want to learn a product. I wanted a list.
That's the whole idea behind CheckVibeCode. Paste a URL, wait under a minute, get 378+ checks across 49 scanners — leaked keys, missing RLS, dead meta tags, pages ChatGPT can't read — sorted by what will actually bite you, with the fix sitting right next to it.
Security, SEO, AEO, performance and uptime all live in one scan because to me they were never separate questions. They were one question: is my app okay right now?
I'm one person shipping this every week, and I read every reply. If you build fast with AI and want something double-checking behind you, this was built for you.
Free, no card. Or say hi on X.
Simple pricing, real limits.
Start free with one full audit. Upgrade to unlock every fix, daily re-scans, and room for more projects and clients.
Free
One full audit, no card
Free forever · no card
See every score. Fix one on us.
- 1 full audit · 378+ checks
- All 7 levels scored
- 1 finding unlocked + fix
- 1 project · 1 repo
- Apex uptime + status page
Starter
For solo makers shipping fast
billed monthly · save 30% annually
The full report, re-run every day.
- 1 project · 1 repo
- 10 scans / mo + daily auto-scan
- Every finding + paste-ready fix
- GitHub + Supabase code scans
- Dependency & supply-chain scan
- SEO & AEO scans
- Regression alert emails
- PDF + Markdown exports
- 1 API key + MCP server
- 3 uptime monitors + status page
Pro
For growing products & multi-repo projects
billed monthly · save 30% annually
Deep Scan + live attack alerts.
- 5 projects · 5 repos each
- 250 scans / mo + daily auto-scan
- Deep Scan — crawl + semgrep SAST
- Live threat detection + attacker IPs
- Every finding + paste-ready fix
- GitHub + Supabase code scans
- Dependency & supply-chain scan
- SEO & AEO scans
- PDF + Markdown exports
- 5 API keys + MCP server
- 5 uptime monitors + status page
Max
For agencies delivering audits to clients
billed monthly · save 30% annually
Unlimited scans. White-label. Resale.
- 25 projects · 25 repos each
- Unlimited scans + daily auto-scan
- Deep Scan + live threat detection
- White-label reports — your brand
- Commercial resale & client delivery
- Every finding + paste-ready fix
- GitHub + Supabase code scans
- Dependency & supply-chain scan
- SEO & AEO scans
- PDF + Markdown exports
- 25 API keys + MCP server
- 10 uptime monitors + priority support
Full breakdown of every limit on the pricing page.
Is it safe to scan a live site?
Yes. Every check is a read-only probe of what your site already serves publicly — the same requests a browser or a search crawler makes. Nothing is written, submitted or changed, and the traffic is no heavier than a handful of page views.
What does a scan check?
One pass runs 378+ checks across seven levels — Security (exposed secrets and .env files, open storage buckets, missing headers, CORS and CSP, auth and injection surface), plus SEO, AEO, Performance, Domain, Compliance and Accessibility. You get one overall score, a per-level breakdown and every finding with the evidence behind it.
What is AEO, and why does it matter?
Answer Engine Optimization — whether ChatGPT, Claude, Perplexity and Google's AI answers can crawl, understand and cite your site when someone asks about your space. The AEO scanner reads your site the way an answer engine does and shows exactly what is keeping you out of the answer.
Do I need to install anything?
No. Paste a URL and the scan runs against your live site in about a minute. Connecting GitHub for source-level scanning — SAST, dependency and webhook-signature checks — is optional and read-only.
What do threat detection and monitoring watch for?
On paid plans CheckVibeCode keeps watching after the scan: it flags credential stuffing, scraping and injection probes hitting your live site — each with the attacker's IP and an instant alert — and runs 60-second uptime probes with down-and-recovery alerts and a public status page.
What do paid plans add?
The free scan shows your scores and one taster finding. Paid plans unlock every finding with paste-ready fixes, continuous threat detection, uptime monitoring, scheduled daily re-scans and API access. Plans scale with how many projects and scans you run.
How often can I scan?
Free includes one full scan. Paid plans re-scan automatically every day plus a monthly pool of manual scans (10 on Starter, 250 on Pro, unlimited on Max), so regressions get caught the day they ship.
Shipping doesn't stop.
Neither does the watching.
A clean scan is a snapshot. The next deploy can undo it. CheckVibeCode keeps checking your live site so a regression reaches you before it reaches your users.
Daily re-scans
Emailed the moment your score drops
Attack alerts
Credential stuffing, scraping, injection probes
60s uptime probes
Down-and-recovery alerts + a status page
First scan is free. Monitoring is on every paid plan.
