VibeCheck-AI
Product · overview

Product

Two pieces. Both of them do one job.

One scan, and a connection that keeps it honest. No dashboards you'll never open, no severity table you need a degree to read.

vibecheck-ai.com / scans / acme-storefront

Score

41/100

Two things to close before anyone else looks. One check had no evidence to read.

  • Live payment key in git history

    STRIPE_SECRET_KEY · committed 4 months ago, deleted since

    Critical
  • Admin route with no role check

    /api/admin/* · anyone signed in can reach it

    High
  • Borrowed code

    41 packages · checked against the OSV database

    Clean
  • Who can read your database

    No migration files in the repo, so the rules were never read

    No evidence
Security scanner

Reads your code the way an attacker would.

Five passes inside a locked box with the network cut: secrets in your history, doors left unlocked, borrowed code with known holes, and the parts that aren't code at all. Then it gets explained in words you already use.

  • Three states reported separately: found, checked and clean, could not check

  • Every finding says what it is, what someone could do with it, where it lives and how to close it

  • Version-stamped — you can always see which rules produced a given score

GitHub automation

Keeps checking after the first scan.

Connect once, read-only. Every push gets re-scanned, so a fix stays fixed and a regression is caught early. On Pro, VibeCheck writes the fix and opens it as a branch for you to review.

  • Read-only by default. Write is a separate grant you can revoke at any time

  • Fixes land on their own branch — never on your default branch, never without review

  • A score history you can watch move, so the work you did is visible

What we will not do

The rules we hold ourselves to.

Three promises that decide whether the report is worth reading at all. They hold on every plan, free included.

A check that did not run is never a pass

Nothing gets a green tick because a scanner crashed or a file was missing. If a check could not run, the report says so.

The AI never invents a finding

The model reads only what the earlier checks found. It groups, ranks and explains — it cannot add a finding, and it cannot drop one.

Serious findings are never paywalled

Medium and low are capped on Free. Critical and high never are. We will not know your payment key is public and charge you to see it.

V1 is built for JavaScript and TypeScript, and Next.js in particular. Other languages get the checks that apply and a plain statement of what we could not cover — never a score that pretends the coverage was the same. See what shipped recently

Find out where you stand.

Connect a repo, read-only. Revoke it whenever you like.