Scan before you ship

Is your app ready
to launch?

Check the security & performance of your vibe-coded app in one scan, before you ship it to real users. 149+ automated checks in about 30 seconds - not a substitute for a full security review.

149+ checks · 30-second scan · Public or private repos
Live scan results

Apps getting checked right now.

Showing the latest 20 of 2,692 scans

Country Language Findings When
🌐Website3 criticalNot AI Search ReadyNot Compliant21m ago
USWebsite3 criticalNot AI Search ReadyNot Compliant26m ago
USPython135 files1 high372 medium47m ago
DEPython19 files65 medium1h ago
FRShell15 files1 medium2h ago
USPython258 files101 medium4h ago
🌐TypeScript494 files29 critical10 high242 mediumNot AI Search ReadyCompliant4h ago
GBPython4 files28 medium5h ago
INTypeScript27 files5 critical25 high26 medium6h ago
USPython50 files226 medium7h ago
🌐Python1012 files35 medium8h ago
INPython41 files2 critical30 high119 medium8h ago
INTypeScript38 files2 critical32 high47 medium10h ago
FRPython84 files4 high210 medium11h ago
FRPython16 files3 high45 medium12h ago
🌐TypeScript2072 files33 high53 mediumAI Search ReadyCompliant12h ago
USPython50 files76 medium13h ago
DEPython5 files2 critical43 high10 medium15h ago
FRPython93 files55 high292 medium16h ago
INPython110 files9 critical75 high562 medium17h ago
AUWebsite1 critical2 high3 mediumNot AI Search ReadyCompliant18h ago
USWebsite8 critical17 high7 mediumNot AI Search ReadyCompliant18h ago
GBC++147 files1 medium18h ago
FRC#532 files2 critical1 high45 medium19h ago
🌐Website2 critical11 high1 mediumNot AI Search ReadyCompliant22h ago
🌐Website4 critical5 mediumNot AI Search ReadyNot Compliant1d ago
🌐Website4 critical5 mediumNot AI Search ReadyNot Compliant1d ago
TWWebsite4 critical5 mediumNot AI Search ReadyNot Compliant1d ago
KRWebsite1 critical2 high6 mediumNot AI Search ReadyCompliant1d ago
🌐Website7 critical17 high5 mediumNot AI Search ReadyNot Compliant1d ago
CAWebsite7 critical17 high5 mediumNot AI Search ReadyNot Compliant1d ago
NLWebsite5 critical9 high6 mediumNot AI Search ReadyNot Compliant2d ago
NLWebsite5 critical9 high6 mediumNot AI Search ReadyNot Compliant2d ago
GRWebsite2 critical6 mediumNot AI Search ReadyCompliant2d ago
USWebsite2 critical6 mediumNot AI Search ReadyCompliant2d ago
USWebsite1 critical1 high8 mediumNot AI Search ReadyCompliant2d ago
USWebsite1 critical1 high8 mediumNot AI Search ReadyCompliant2d ago
TWWebsite3 critical5 mediumNot AI Search ReadyCompliant2d ago
🌐Website16 mediumAI Search ReadyCompliant3d ago
🌐Website3 mediumAI Search ReadyCompliant3d ago
What we found across 2,692 scans

41% imported at least one package that doesn't exist · 73% had API keys or secrets committed to the repo · 1 in 3 had no rate limiting on auth endpoints

Give your AI agent a live map of your codebase. Connect the VibeDoctor MCP so Cursor, Claude Code, Copilot, or Windsurf can pull your codebase structure and findings while it writes - no copy-pasting files.
Connect VibeDoctor MCP →
FAQ

Questions.

Who is VibeDoctor actually for?

Solo devs, indie hackers, and small teams who ship with AI tools like Cursor, Copilot, Bolt, or Claude Code. If you're building fast and want a quick read on what you might be missing - security holes, performance issues, broken SEO - VibeDoctor is your second opinion.

What languages and frameworks do you scan?

JavaScript, TypeScript, Python, Go, Rust, Java, Kotlin, C#, Ruby, PHP, Swift, and more. Framework-aware checks for React, Next.js, Express, Fastify, NestJS, Vue, Svelte, and Django. Dependency scanning covers npm, pip, Go modules, and Gemfiles.

Is this safe to point at a private repo?

Yes. We clone read-only via the GitHub App (no write token, ever). Code is scanned in an isolated container, never stored on disk after the scan completes, and never used for training. You can revoke access at any time from your GitHub settings.

How is this different from SonarQube, Snyk, or CodeRabbit?

Those tools are built for enterprise CI pipelines. VibeDoctor is built for vibe coders who want a fast checkup - not a 200-page compliance report. We run AI-specific checks (hallucinated imports, god files, empty test bodies) that no enterprise tool catches, and we give you fix prompts you can paste straight into Cursor. See the full checking guide.

Does it touch my code?

Never. VibeDoctor is read-only. We clone, scan, and report. We never open PRs, commit changes, or modify anything in your repo. The fix prompts are copy-paste suggestions - you decide what to apply.

What is Vibe X-Ray?

Vibe X-Ray is a four-level visual explorer for your codebase. It shows modules, files, symbols (functions, classes, interfaces), and their dependencies. You can see what your AI actually built - which functions call what, where complexity hides, what breaks if you touch something. It updates with every scan.