Scan before you ship

Is your app ready
to launch?

Check the security & performance of your vibe-coded app in one scan, before you ship it to real users. 149+ automated checks in about 30 seconds - not a substitute for a full security review.

149+ checks · 30-second scan · Public or private repos
Live scan results

Apps getting checked right now.

Showing the latest 20 of 2,781 scans

Country Language Findings When
🌐Python1025 files70 medium13m ago
GBTypeScript64 files4 critical44 high68 medium1h ago
USTypeScript41 files2 critical23 high49 medium2h ago
GBTypeScript709 files13 critical14 high4934 medium3h ago
FRPython42 files4 high93 medium5h ago
FRCode1 medium6h ago
INPython61 files1 critical16 high96 medium7h ago
PEJava64 files27 high7 medium8h ago
INTypeScript123 files17 critical10 high179 medium8h ago
DETypeScript33 files8 high50 medium10h ago
CAWebsite1 high1 mediumAI Search ReadyCompliant10h ago
DERust78 files3 high13 medium11h ago
DEJavaScript106 files1 critical1 high17 medium12h ago
LTWebsite2 critical6 mediumNot AI Search ReadyCompliant12h ago
LTWebsite2 critical6 mediumNot AI Search ReadyCompliant12h ago
LTWebsite2 critical6 mediumNot AI Search ReadyCompliant12h ago
INTypeScript9 files4 high3 medium13h ago
INRust16 files41 medium15h ago
GBPython66 files4 high100 medium16h ago
DETypeScript206 files5 critical52 high71 medium17h ago
USSvelte159 files2 critical4 high15 medium18h ago
DZWebsite2 mediumAI Search ReadyCompliant19h ago
INTypeScript5 files1 critical19 high26 medium19h ago
DEPython340 files16 high1642 medium20h ago
USTypeScript33 files1 critical13 high33 medium21h ago
🌐Website2 critical1 high16 mediumAI Search ReadyCompliant1d ago
USWebsite2 high15 mediumAI Search ReadyCompliant1d ago
USWebsite7 critical18 high5 mediumNot AI Search ReadyCompliant1d ago
🌐Website3 criticalNot AI Search ReadyNot Compliant1d ago
USWebsite3 criticalNot AI Search ReadyNot Compliant1d ago
AUWebsite1 critical2 high3 mediumNot AI Search ReadyCompliant2d ago
USWebsite8 critical17 high7 mediumNot AI Search ReadyCompliant2d ago
🌐Website2 critical11 high1 mediumNot AI Search ReadyCompliant2d ago
🌐Website4 critical5 mediumNot AI Search ReadyNot Compliant3d ago
🌐Website4 critical5 mediumNot AI Search ReadyNot Compliant3d ago
TWWebsite4 critical5 mediumNot AI Search ReadyNot Compliant3d ago
KRWebsite1 critical2 high6 mediumNot AI Search ReadyCompliant3d ago
🌐Website7 critical17 high5 mediumNot AI Search ReadyNot Compliant3d ago
CAWebsite7 critical17 high5 mediumNot AI Search ReadyNot Compliant3d ago
NLWebsite5 critical9 high6 mediumNot AI Search ReadyNot Compliant3d ago
What we found across 2,781 scans

41% imported at least one package that doesn't exist · 73% had API keys or secrets committed to the repo · 1 in 3 had no rate limiting on auth endpoints

Give your AI agent a live map of your codebase. Connect the VibeDoctor MCP so Cursor, Claude Code, Copilot, or Windsurf can pull your codebase structure and findings while it writes - no copy-pasting files.
Connect VibeDoctor MCP →
FAQ

Questions.

Who is VibeDoctor actually for?

Solo devs, indie hackers, and small teams who ship with AI tools like Cursor, Copilot, Bolt, or Claude Code. If you're building fast and want a quick read on what you might be missing - security holes, performance issues, broken SEO - VibeDoctor is your second opinion.

What languages and frameworks do you scan?

JavaScript, TypeScript, Python, Go, Rust, Java, Kotlin, C#, Ruby, PHP, Swift, and more. Framework-aware checks for React, Next.js, Express, Fastify, NestJS, Vue, Svelte, and Django. Dependency scanning covers npm, pip, Go modules, and Gemfiles.

Is this safe to point at a private repo?

Yes. We clone read-only via the GitHub App (no write token, ever). Code is scanned in an isolated container, never stored on disk after the scan completes, and never used for training. You can revoke access at any time from your GitHub settings.

How is this different from SonarQube, Snyk, or CodeRabbit?

Those tools are built for enterprise CI pipelines. VibeDoctor is built for vibe coders who want a fast checkup - not a 200-page compliance report. We run AI-specific checks (hallucinated imports, god files, empty test bodies) that no enterprise tool catches, and we give you fix prompts you can paste straight into Cursor. See the full checking guide.

Does it touch my code?

Never. VibeDoctor is read-only. We clone, scan, and report. We never open PRs, commit changes, or modify anything in your repo. The fix prompts are copy-paste suggestions - you decide what to apply.

What is Vibe X-Ray?

Vibe X-Ray is a four-level visual explorer for your codebase. It shows modules, files, symbols (functions, classes, interfaces), and their dependencies. You can see what your AI actually built - which functions call what, where complexity hides, what breaks if you touch something. It updates with every scan.