Is your app ready
to launch?
Check the security & performance of your vibe-coded app in one scan, before you ship it to real users. 149+ automated checks in about 30 seconds - not a substitute for a full security review.
Apps getting checked right now.
Showing the latest 20 of 2,692 scans
| Country | Language | Findings | When |
|---|---|---|---|
| 🌐 | Website | 3 criticalNot AI Search ReadyNot Compliant | 21m ago |
| Website | 3 criticalNot AI Search ReadyNot Compliant | 26m ago | |
| Python | 135 files1 high372 medium | 47m ago | |
| Python | 19 files65 medium | 1h ago | |
| Shell | 15 files1 medium | 2h ago | |
| Python | 258 files101 medium | 4h ago | |
| 🌐 | TypeScript | 494 files29 critical10 high242 mediumNot AI Search ReadyCompliant | 4h ago |
| Python | 4 files28 medium | 5h ago | |
| TypeScript | 27 files5 critical25 high26 medium | 6h ago | |
| Python | 50 files226 medium | 7h ago | |
| 🌐 | Python | 1012 files35 medium | 8h ago |
| Python | 41 files2 critical30 high119 medium | 8h ago | |
| TypeScript | 38 files2 critical32 high47 medium | 10h ago | |
| Python | 84 files4 high210 medium | 11h ago | |
| Python | 16 files3 high45 medium | 12h ago | |
| 🌐 | TypeScript | 2072 files33 high53 mediumAI Search ReadyCompliant | 12h ago |
| Python | 50 files76 medium | 13h ago | |
| Python | 5 files2 critical43 high10 medium | 15h ago | |
| Python | 93 files55 high292 medium | 16h ago | |
| Python | 110 files9 critical75 high562 medium | 17h ago | |
| Website | 1 critical2 high3 mediumNot AI Search ReadyCompliant | 18h ago | |
| Website | 8 critical17 high7 mediumNot AI Search ReadyCompliant | 18h ago | |
| C++ | 147 files1 medium | 18h ago | |
| C# | 532 files2 critical1 high45 medium | 19h ago | |
| 🌐 | Website | 2 critical11 high1 mediumNot AI Search ReadyCompliant | 22h ago |
| 🌐 | Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 1d ago |
| 🌐 | Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 1d ago |
| Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 1d ago | |
| Website | 1 critical2 high6 mediumNot AI Search ReadyCompliant | 1d ago | |
| 🌐 | Website | 7 critical17 high5 mediumNot AI Search ReadyNot Compliant | 1d ago |
| Website | 7 critical17 high5 mediumNot AI Search ReadyNot Compliant | 1d ago | |
| Website | 5 critical9 high6 mediumNot AI Search ReadyNot Compliant | 2d ago | |
| Website | 5 critical9 high6 mediumNot AI Search ReadyNot Compliant | 2d ago | |
| Website | 2 critical6 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 2 critical6 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 1 critical1 high8 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 1 critical1 high8 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 3 critical5 mediumNot AI Search ReadyCompliant | 2d ago | |
| 🌐 | Website | 16 mediumAI Search ReadyCompliant | 3d ago |
| 🌐 | Website | 3 mediumAI Search ReadyCompliant | 3d ago |
What we found across 2,692 scans41% imported at least one package that doesn't exist · 73% had API keys or secrets committed to the repo · 1 in 3 had no rate limiting on auth endpoints
Questions.
Who is VibeDoctor actually for?
Solo devs, indie hackers, and small teams who ship with AI tools like Cursor, Copilot, Bolt, or Claude Code. If you're building fast and want a quick read on what you might be missing - security holes, performance issues, broken SEO - VibeDoctor is your second opinion.
What languages and frameworks do you scan?
JavaScript, TypeScript, Python, Go, Rust, Java, Kotlin, C#, Ruby, PHP, Swift, and more. Framework-aware checks for React, Next.js, Express, Fastify, NestJS, Vue, Svelte, and Django. Dependency scanning covers npm, pip, Go modules, and Gemfiles.
Is this safe to point at a private repo?
Yes. We clone read-only via the GitHub App (no write token, ever). Code is scanned in an isolated container, never stored on disk after the scan completes, and never used for training. You can revoke access at any time from your GitHub settings.
How is this different from SonarQube, Snyk, or CodeRabbit?
Those tools are built for enterprise CI pipelines. VibeDoctor is built for vibe coders who want a fast checkup - not a 200-page compliance report. We run AI-specific checks (hallucinated imports, god files, empty test bodies) that no enterprise tool catches, and we give you fix prompts you can paste straight into Cursor. See the full checking guide.
Does it touch my code?
Never. VibeDoctor is read-only. We clone, scan, and report. We never open PRs, commit changes, or modify anything in your repo. The fix prompts are copy-paste suggestions - you decide what to apply.
What is Vibe X-Ray?
Vibe X-Ray is a four-level visual explorer for your codebase. It shows modules, files, symbols (functions, classes, interfaces), and their dependencies. You can see what your AI actually built - which functions call what, where complexity hides, what breaks if you touch something. It updates with every scan.