CheckVibeCodeCheckVibeCode

Documentation

Every check, one scanner.

49 scanners running 378+ individual checks — SQLi, XSS, exposed keys, BaaS misconfigs, SSL/TLS grading, plus SEO & AEO visibility, uptime, Core Web Vitals and accessibility. Every finding ships with an AI-ready fix prompt.

VulnerabilityHeuristic

SQL Injection Scanner

Detect SQL injection vulnerabilities in your web application before attackers exploit them.

6 checksLearn more
VulnerabilityHeuristic

Cross-Site Scripting (XSS) Scanner

Find XSS vulnerabilities that could let attackers inject malicious scripts into your pages.

5 checksLearn more
ConfigurationLive

Security Headers Scanner

Check if your site has the right HTTP security headers to prevent common attacks.

9 checksLearn more
VulnerabilityLive

API Key Exposure Scanner

Detect exposed API keys, tokens, and secrets in your frontend code and responses.

4 checksLearn more
ConfigurationLive

SSL/TLS Security Scanner

Verify your SSL/TLS configuration, certificate validity, and encryption strength.

6 checksLearn more
VulnerabilityLive

CORS Misconfiguration Scanner

Detect dangerous CORS policies that could allow unauthorized cross-origin access.

5 checksLearn more
VulnerabilityHeuristic

CSRF Protection Scanner

Check if your forms and API endpoints are protected against cross-site request forgery.

4 checksLearn more
ConfigurationLive

Cookie & Session Security Scanner

Audit cookie flags, session management, and token security for your application.

6 checksLearn more
VulnerabilityHeuristic

Authentication Flow Scanner

Test your login, signup, and password reset flows for common security weaknesses.

5 checksLearn more
InfrastructureLive

DNS & Email Security Scanner

Verify DNS configuration, SPF, DKIM, DMARC records, and domain security.

6 checksLearn more
VulnerabilityHeuristic

Open Redirect Scanner

Find URL redirect vulnerabilities that attackers use for phishing campaigns.

3 checksLearn more
VulnerabilityLive

GraphQL Security Scanner

Audit your GraphQL API for introspection leaks, injection, and query complexity attacks.

4 checksLearn more
VulnerabilityHeuristic

JWT Security Audit

Analyze JSON Web Tokens for weak algorithms, key exposure, and implementation flaws.

5 checksLearn more
VulnerabilityLive

Tech Stack & CVE Scanner

Identify your technology stack and check for known vulnerabilities (CVEs).

4 checksLearn more
MonitoringLive

Threat Intelligence Scanner

Check if your domain or IP appears on blocklists, malware databases, or threat feeds.

2 checksLearn more
ComplianceLive

Legal Compliance Scanner

Check for privacy policy, cookie consent, terms of service, and GDPR compliance indicators.

21 checksLearn more
InfrastructureHeuristic — passive only

DDoS Protection Scanner

Evaluate your site's resilience against distributed denial-of-service attacks.

3 checksLearn more
VulnerabilityRequires setup

File Upload Security Scanner

Test file upload endpoints for unrestricted uploads and remote code execution risks.

3 checksLearn more
MonitoringHeuristic

Audit Logging & Monitoring Scanner

Verify that security events are properly logged and monitored in your application.

2 checksLearn more
InfrastructureHeuristic — capped burst

Mobile API Rate Limiting Scanner

Check API endpoints for proper rate limiting and abuse prevention on mobile-facing APIs.

2 checksLearn more
ConfigurationLive — needs Playwright

Mobile Interface Scanner

Tap-target sizing, horizontal overflow, font legibility, and touch icons at a real mobile viewport.

4 checksLearn more
InfrastructureLive

Domain Hijacking Detection

Detect subdomain takeover vulnerabilities and domain registration security issues.

5 checksLearn more
VulnerabilityLive

Debug Endpoints Scanner

Find exposed debug routes, admin panels, and development endpoints left in production.

3 checksLearn more
VulnerabilityHeuristic

Input Validation Scanner

Test form fields and API inputs for proper validation and sanitization.

4 checksLearn more
InfrastructureLive

Vercel Hosting Security Scanner

Audit Vercel-specific security settings, headers, and deployment configuration.

3 checksLearn more
InfrastructureLive

Netlify Hosting Security Scanner

Check Netlify-specific security configuration, headers, and deployment settings.

3 checksLearn more
InfrastructureLive

Cloudflare Security Scanner

Audit Cloudflare configuration, WAF settings, and CDN security features.

3 checksLearn more
VulnerabilityEnhanced with input

Dependency Vulnerability Scanner

Scan your project dependencies for known vulnerabilities and outdated packages.

2 checksLearn more
VulnerabilityEnhanced with input

Transitive Dependency Vulnerability Scanner

Resolve every dependency your lockfiles actually install — transitive ones included, across npm, PyPI, Go, Cargo, RubyGems, Composer and Maven — and report the known CVEs against them.

7 checksLearn more
ConfigurationEnhanced with input

Container & IaC Misconfiguration Scanner

Audit the Dockerfile, Kubernetes manifests, Terraform, CloudFormation and Helm charts in your repository for insecure defaults — root containers, privileged pods, public storage, unpinned base images, secrets passed as build args.

15 checksLearn more
ConfigurationLive — auto-discovered

Supabase Security Scanner

Audit your Supabase project for RLS misconfigurations, exposed APIs, and insecure auth settings.

8 checksLearn more
ConfigurationLive — auto-discovered

Firebase Security Scanner

Check Firebase Security Rules, authentication settings, and Firestore/RTDB access controls.

5 checksLearn more
InfrastructureEnhanced with input

GitHub Repository Security Scanner

Audit your GitHub repository's security posture — branch protection, secret scanning, access, webhooks and deploy keys.

12 checksLearn more
InfrastructureEnhanced with input

GitHub Actions Supply Chain Scanner

Analyze CI workflows for script injection, untrusted-code execution, exposed self-hosted runners, and unpinned third-party actions.

5 checksLearn more
VulnerabilityLive — needs Playwright

Browser Storage & Session Token Scanner

Detect JWTs, refresh tokens, and session identifiers stored in localStorage or sessionStorage.

3 checksLearn more
VulnerabilityEnhanced with input

Source Code SAST Scanner

Scan every file in a connected GitHub repository for live credentials, committed secret files, and high-risk auth, SQL, CORS, SSRF, TLS and cookie patterns.

11 checksLearn more
VulnerabilityEnhanced with input

Git History Secret Scanner

Walk every commit for credentials that were committed and later deleted — still recoverable, still valid, and invisible to any scan of the current code.

4 checksLearn more
VulnerabilityEnhanced with input

Dependency Supply Chain Scanner

Check lockfile integrity, install-time lifecycle scripts, dependency-confusion exposure, and .gitignore credential gaps.

5 checksLearn more
VulnerabilityEnhanced with input

AI Tooling Configuration Scanner

Scan committed MCP server configs and AI coding-agent settings for inline API keys, unpinned auto-executed servers, and leaked internal endpoints.

6 checksLearn more
VulnerabilityEnhanced with input

Webhook Signature Verification Scanner

Find webhook handlers that appear to trust provider events without verifying signatures.

2 checksLearn more
VulnerabilityHeuristic

IDOR & Broken Access Control Scanner

Find exposed admin routes, unauthenticated APIs, sequential IDs, and mass data exposure.

4 checksLearn more
VulnerabilityRequires setup

Tenant Isolation Scanner

Use two authenticated test actors to verify tenant-scoped resources cannot be read across accounts.

1 checkLearn more
SEO & AEOLive

SEO Scanner

Grade your search visibility with 75 checks — indexability, metadata, structured data, content, links, and Core Web Vitals — plus a live preview of how the page renders when shared.

75 checksLearn more
SEO & AEOLive

AEO Scanner (AI Visibility)

Check whether AI answer engines — ChatGPT, Claude, Perplexity, Google AI — can crawl, parse, and cite your site. 46 checks.

46 checksLearn more
MonitoringLive — single check

Uptime Monitoring & Status Pages

External uptime checks every 60 seconds with incident tracking, down/recovery alerts, and a public status page.

3 checksLearn more
PerformanceLive

Performance & Core Web Vitals Scanner

Lab diagnostics plus real-user Core Web Vitals from CrUX and RUM — with daily regression alerts before rankings drop.

8 checksLearn more
AccessibilityLive

Accessibility Scanner (WCAG)

WCAG 2.x Level AA signals across structure, forms, navigation, and media — the EAA-relevant checks, automated.

16 checksLearn more
MonitoringLive

Domain Watchtower

Domain expiry, transfer locks, nameserver drift, DNSSEC, CAA, and certificate runway — watched daily, alerted on change.

8 checksLearn more
InfrastructureLive

Subdomain Enumeration Scanner

Discover subdomains via certificate-transparency logs and a common-name wordlist, and flag any pointing at an unclaimed third-party service.

2 checksLearn more