Public page & scripts
Reads one public HTML page and selected same-origin JavaScript for visible exposure signals.
Passive readVibe security lab / free public beta
Run a free passive scan of your AI-built website for public exposure signals, then close the gaps the scanner cannot verify with a practical 36-point review.
Free passive scanner
Definition
Vibe coding security is the practice of reviewing AI-assisted applications for exposed secrets, missing authorization, unsafe defaults, weak deployment controls, and other risks that fast code generation can overlook.
Check My Vibe examines limited public evidence. It does not replace source-code review, authenticated testing, or a professional security assessment.
01 / Awareness
Four deliberately bounded checks. Enough to catch costly oversights without pretending to replace an audit.
Reads one public HTML page and selected same-origin JavaScript for visible exposure signals.
Passive readReviews transport behavior and security headers returned to a normal visitor.
Public responseLooks for public source maps and credential-shaped strings, with evidence redacted.
Pattern signalsChecks a fixed set of common public paths. It does not recursively crawl, brute-force, or exploit.
Fixed scope02 / Interest
Start with observable evidence. Continue with the controls only a human can confirm.
Use a production or preview website you own or have explicit permission to assess.
See the completed tests, visible signals, limited checks, and practical remediation notes.
Verify authorization, data access, dependencies, and deployment controls the scanner cannot prove.
Example output
Representative examples show how Check My Vibe separates an observable signal from the conclusion a human still needs to verify.
These examples explain the free public signal. They are not stack-specific repair code, authenticated verification, or a professional security assessment.
03 / Desire
Work through every control. Your progress stays in this browser, and related scan signals appear beside the items that still need human confirmation.
Keep credentials out of public code, logs and version history.
Verify identity and authorization controls at every protected boundary.
Protect data access, tenant isolation and recovery paths.
Harden the public response and browser security boundary.
Keep the software supply chain deliberate, current and reproducible.
Ship production with safe defaults, observability and rollback options.
Use the right layer
Choose the method that matches the evidence you need. These approaches complement one another rather than producing interchangeable guarantees.
| Method | What it observes | Access needed | What the result can establish |
|---|---|---|---|
| Check My Vibe passive scan | One public page, selected same-origin scripts, response headers, limited source maps, and fixed public paths. | Public URL only | Externally observable signals from the completed checks; not private authorization or business logic. |
| Source-code review or SAST | Application code, configuration, data flows, and dangerous implementation patterns. | Repository access | Code-level evidence, but not every control actually deployed to production. |
| Dependency scanner | Package manifests, lockfiles, software bills of materials, and known vulnerability databases. | Manifest or repository | Known vulnerable versions; not custom authorization or deployment mistakes. |
| Authenticated assessment | Protected routes, roles, tenant boundaries, workflows, and business-logic abuse cases. | Test accounts and scoped permission | Deeper application behavior within the agreed test scope. |
04 / Trust
This is a passive review of limited public content, not a penetration test or a complete security audit.
It does not log in, attack endpoints, submit forms, or probe private resources.
It cannot see repositories, server configuration, database policies, authenticated routes, or business logic.
A clean result only means the completed checks did not find the specific signals they test.
For payments, health data, sensitive personal information, or privileged workflows, combine this checklist with threat modeling, automated tests, and an independent security assessment.
Public methodology
Transparent scope makes the result easier to interpret and prevents a limited public check from being mistaken for a complete audit.
Methodology v1.1
Reviewed
A scan starts from one authorized public URL and uses a deliberately limited request budget. It is not a recursive crawler or an endpoint brute-forcer.
Findings are based on responses available to a normal visitor. Credential-shaped evidence is redacted, and a pattern match is not presented as proof of exploitability.
The Automated Security Score covers completed machine checks only. The 36-point manual checklist records controls that a public scan cannot verify.
The scanner does not log in, submit forms, execute payloads, probe private resources, or attempt to bypass access controls.
Limited public content is processed long enough to return a redacted report. Page bodies, scripts, source maps, credentials, and scan history are not retained.
Evidence / Guidance
Primary guidance and current research inform the boundaries of this public-surface review.
Guidance for treating AI-generated code and AI-assisted development output as security-sensitive inputs that still require review and validation.
Read the sourceOWASP recommends explicit review, secure examples, and policy enforcement instead of assuming generated code is safe because it functions.
Read the sourceA 2026 empirical study reports recurring patterns such as placeholder logic, insufficient input handling, and secret exposure in vibe-coded applications.
Read the source05 / Clarity
Clear answers before you place trust in a score.
Vibe coding security is the process of reviewing AI-assisted applications for exposed secrets, missing authorization, unsafe defaults, weak deployment settings, and other risks that fast code generation can overlook.
It passively checks the public page, selected same-origin JavaScript files, security headers, HTTPS behavior, source maps, and six common sensitive file paths.
No. It does not log in, execute attacks, test private code, validate database policies, or prove that a site has no vulnerabilities. Use the manual checklist and a professional review for higher-risk applications.
No scan history is stored. The server temporarily reads limited public content, returns a redacted report, and does not retain page bodies, JavaScript, source maps, credentials, or complete results.
Ready when you are
Start with one authorized public URL. No account, no stored scan history, no exploit attempts.
Run the free passive scan