Apps built with Cursor, Lovable or Claude forget the same things: passwords left in the open, doors with no lock. Would you bet your users that yours got lucky? Paste it and know in minutes.
What the scan looks for
It happens on almost every app we scan. Not because the tool is bad. Because nobody taught it to think like a burglar. We do. Every scan asks what a hacker would ask:
paste a GitHub repo
paste your URL
After the scan
Today's scan ends today. Next week's vibe-coding session can open a brand-new hole, and it won't email you about it. We will.
Fair questions
We only accept public repos and public URLs, and the form requires you to confirm you own the target. Scanning public code for defensive purposes is standard practice; exploiting anything would not be, and we never do.
No. Reports are unlisted pages only you and we can link to. We never publish client findings without written permission. Your repo name appears nowhere public.
Then you get a clean bill worth having: proof that today's version of your app passes every check. That's the free product working exactly as intended.
Because every finding ships with redacted evidence from your actual files, and every prompt tells you how to verify the fix yourself. You are always the last gate.