Is your app ready
to launch?
Check the security & performance of your vibe-coded app in one scan, before you ship it to real users. 149+ automated checks in about 30 seconds - not a substitute for a full security review.
Apps getting checked right now.
Showing the latest 20 of 2,781 scans
| Country | Language | Findings | When |
|---|---|---|---|
| 🌐 | Python | 1025 files70 medium | 13m ago |
| TypeScript | 64 files4 critical44 high68 medium | 1h ago | |
| TypeScript | 41 files2 critical23 high49 medium | 2h ago | |
| TypeScript | 709 files13 critical14 high4934 medium | 3h ago | |
| Python | 42 files4 high93 medium | 5h ago | |
| Code | 1 medium | 6h ago | |
| Python | 61 files1 critical16 high96 medium | 7h ago | |
| Java | 64 files27 high7 medium | 8h ago | |
| TypeScript | 123 files17 critical10 high179 medium | 8h ago | |
| TypeScript | 33 files8 high50 medium | 10h ago | |
| Website | 1 high1 mediumAI Search ReadyCompliant | 10h ago | |
| Rust | 78 files3 high13 medium | 11h ago | |
| JavaScript | 106 files1 critical1 high17 medium | 12h ago | |
| Website | 2 critical6 mediumNot AI Search ReadyCompliant | 12h ago | |
| Website | 2 critical6 mediumNot AI Search ReadyCompliant | 12h ago | |
| Website | 2 critical6 mediumNot AI Search ReadyCompliant | 12h ago | |
| TypeScript | 9 files4 high3 medium | 13h ago | |
| Rust | 16 files41 medium | 15h ago | |
| Python | 66 files4 high100 medium | 16h ago | |
| TypeScript | 206 files5 critical52 high71 medium | 17h ago | |
| Svelte | 159 files2 critical4 high15 medium | 18h ago | |
| Website | 2 mediumAI Search ReadyCompliant | 19h ago | |
| TypeScript | 5 files1 critical19 high26 medium | 19h ago | |
| Python | 340 files16 high1642 medium | 20h ago | |
| TypeScript | 33 files1 critical13 high33 medium | 21h ago | |
| 🌐 | Website | 2 critical1 high16 mediumAI Search ReadyCompliant | 1d ago |
| Website | 2 high15 mediumAI Search ReadyCompliant | 1d ago | |
| Website | 7 critical18 high5 mediumNot AI Search ReadyCompliant | 1d ago | |
| 🌐 | Website | 3 criticalNot AI Search ReadyNot Compliant | 1d ago |
| Website | 3 criticalNot AI Search ReadyNot Compliant | 1d ago | |
| Website | 1 critical2 high3 mediumNot AI Search ReadyCompliant | 2d ago | |
| Website | 8 critical17 high7 mediumNot AI Search ReadyCompliant | 2d ago | |
| 🌐 | Website | 2 critical11 high1 mediumNot AI Search ReadyCompliant | 2d ago |
| 🌐 | Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 3d ago |
| 🌐 | Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 3d ago |
| Website | 4 critical5 mediumNot AI Search ReadyNot Compliant | 3d ago | |
| Website | 1 critical2 high6 mediumNot AI Search ReadyCompliant | 3d ago | |
| 🌐 | Website | 7 critical17 high5 mediumNot AI Search ReadyNot Compliant | 3d ago |
| Website | 7 critical17 high5 mediumNot AI Search ReadyNot Compliant | 3d ago | |
| Website | 5 critical9 high6 mediumNot AI Search ReadyNot Compliant | 3d ago |
What we found across 2,781 scans41% imported at least one package that doesn't exist · 73% had API keys or secrets committed to the repo · 1 in 3 had no rate limiting on auth endpoints
Questions.
Who is VibeDoctor actually for?
Solo devs, indie hackers, and small teams who ship with AI tools like Cursor, Copilot, Bolt, or Claude Code. If you're building fast and want a quick read on what you might be missing - security holes, performance issues, broken SEO - VibeDoctor is your second opinion.
What languages and frameworks do you scan?
JavaScript, TypeScript, Python, Go, Rust, Java, Kotlin, C#, Ruby, PHP, Swift, and more. Framework-aware checks for React, Next.js, Express, Fastify, NestJS, Vue, Svelte, and Django. Dependency scanning covers npm, pip, Go modules, and Gemfiles.
Is this safe to point at a private repo?
Yes. We clone read-only via the GitHub App (no write token, ever). Code is scanned in an isolated container, never stored on disk after the scan completes, and never used for training. You can revoke access at any time from your GitHub settings.
How is this different from SonarQube, Snyk, or CodeRabbit?
Those tools are built for enterprise CI pipelines. VibeDoctor is built for vibe coders who want a fast checkup - not a 200-page compliance report. We run AI-specific checks (hallucinated imports, god files, empty test bodies) that no enterprise tool catches, and we give you fix prompts you can paste straight into Cursor. See the full checking guide.
Does it touch my code?
Never. VibeDoctor is read-only. We clone, scan, and report. We never open PRs, commit changes, or modify anything in your repo. The fix prompts are copy-paste suggestions - you decide what to apply.
What is Vibe X-Ray?
Vibe X-Ray is a four-level visual explorer for your codebase. It shows modules, files, symbols (functions, classes, interfaces), and their dependencies. You can see what your AI actually built - which functions call what, where complexity hides, what breaks if you touch something. It updates with every scan.