Skip to content

Find what your AI coder left exposed

Free vibe code security scanner

Paste your public app URL. We check what a visitor can see, then show what needs review and what the scan could not confirm. If you want to know whether a website was vibe coded rather than scan your own app, use the free Vibe Check instead.

The scan is read only, does not log in and usually finishes in under a minute. We ask for your name and work email before it starts.

Interactive scan

Start the scan

Public app security scanWaiting for URL

The scan is read only, does not log in and usually finishes in under a minute.

https://
Enter a URL and confirm permission
What the scan checks

Vibe Scan makes automated, read only requests to the submitted public page and up to eight scripts from the same origin. It then inspects response headers, HTTPS handling and one TLS connection. It does not execute the page, log in, submit forms, change data or exploit a finding. A server allowlist is required for separately authorised additional checks. This checkbox alone never enables them.

We ask for your name and work email before the scan starts.

The report is automated and limited to public evidence. It does not inspect source repositories, logged in workflows or private infrastructure.
Certification
CyberCert SMB1001 SilverHeld by VibeZero.
Result basis
Coverage labelledCompleted, limited and blocked collection steps stay distinct.
Scan boundary
No loginOne submitted page and selected assets from the same origin. No source repository access.

Public evidence

What the scan can observe

The scanner reads material available without an account. Bot protection, dynamic loading and unavailable assets can limit the result. The security Field Note explains the sources behind the broader review method.

Page and scripts

Material sent to a public visitor

Reads the submitted public HTML and metadata, then analyses up to eight JavaScript assets declared by the page and served from the same origin. It looks for known secret patterns and static client side risks without entering a private repository or logged in workflow.

Submitted HTMLUp to eight scripts from the same originKnown secret patternsStatic client side patterns

Browser controls

Response headers and static code signals

Reviews response headers and static client code patterns that affect framing, script loading, cross origin requests, redirects and message handling. It does not execute the page in a browser.

HSTSCSP and framingCookie and CORS headersRedirect and message patterns

Transport and dependencies

Public certificate and library signals

Checks whether plain HTTP reaches HTTPS, reads the certificate presented on one TLS connection and inventories selected libraries and version signals found in public scripts. It is not a full TLS or dependency audit.

HTTP to HTTPSTLS certificateLibrary inventoryVersion signals

Reading the report

Findings and scan limits

The report shows findings from the public material it could read, then states whether document, asset and transport collection was complete, limited or blocked.

Direct evidence

Evidence in a public response

The report shows the material it read and why it matters. Urgency still depends on whether the value or control remains effective in context.

Pattern match

A pattern that needs review

Client code can suggest a risky path without proving it is exploitable. These findings are prompts for a developer, not a confirmed incident.

Blocked or incomplete

No automatic pass

When the scanner cannot collect enough evidence, it says so. A blocked check is not presented as proof that the control is safe.

Before you scan

Authority, scope and next steps

What the scanner reads, which sites it is intended for, how the report is delivered and what to do with a critical result.

The scan is read only. It looks at the submitted public page, its response headers and selected scripts from the same origin. It does not log in, submit forms or send attack payloads.

Manual review

When the public result needs a deeper answer

Source code, access rules, business logic and private infrastructure need a manual review. We scope that work before implementation starts.
Automated public review. A manual audit is available once the scope is agreed.