Product
Two pieces. Both of them do one job.
One scan, and a connection that keeps it honest. No dashboards you'll never open, no severity table you need a degree to read.
Score
Two things to close before anyone else looks. One check had no evidence to read.
- Critical
Live payment key in git history
STRIPE_SECRET_KEY · committed 4 months ago, deleted since
- High
Admin route with no role check
/api/admin/* · anyone signed in can reach it
- Clean
Borrowed code
41 packages · checked against the OSV database
- No evidence
Who can read your database
No migration files in the repo, so the rules were never read
Reads your code the way an attacker would.
Five passes inside a locked box with the network cut: secrets in your history, doors left unlocked, borrowed code with known holes, and the parts that aren't code at all. Then it gets explained in words you already use.
Three states reported separately: found, checked and clean, could not check
Every finding says what it is, what someone could do with it, where it lives and how to close it
Version-stamped — you can always see which rules produced a given score
Keeps checking after the first scan.
Connect once, read-only. Every push gets re-scanned, so a fix stays fixed and a regression is caught early. On Pro, VibeCheck writes the fix and opens it as a branch for you to review.
Read-only by default. Write is a separate grant you can revoke at any time
Fixes land on their own branch — never on your default branch, never without review
A score history you can watch move, so the work you did is visible
What we will not do
The rules we hold ourselves to.
Three promises that decide whether the report is worth reading at all. They hold on every plan, free included.
A check that did not run is never a pass
Nothing gets a green tick because a scanner crashed or a file was missing. If a check could not run, the report says so.
The AI never invents a finding
The model reads only what the earlier checks found. It groups, ranks and explains — it cannot add a finding, and it cannot drop one.
Serious findings are never paywalled
Medium and low are capped on Free. Critical and high never are. We will not know your payment key is public and charge you to see it.
V1 is built for JavaScript and TypeScript, and Next.js in particular. Other languages get the checks that apply and a plain statement of what we could not cover — never a score that pretends the coverage was the same. See what shipped recently
Find out where you stand.
Connect a repo, read-only. Revoke it whenever you like.