Real public scans
VibeSeal fetches your live site, checks browser-facing security controls, and blocks private networks by default.
Paste a public URL and get a live security report for exposed secrets, weak headers, risky CORS, cookie flags, source maps, and public deployment files.
This version focuses on high-signal, low-risk checks that can safely run against public websites.
VibeSeal fetches your live site, checks browser-facing security controls, and blocks private networks by default.
Client JavaScript is inspected for OpenAI, Anthropic, Stripe, GitHub, AWS, and Supabase service-role shaped secrets.
Every finding includes the observed header, path, bundle, or response signal so you know why it matters.
Findings include deterministic prompts you can paste into Claude, Cursor, Codex, or Windsurf.
The first checks target the mistakes common in Lovable, v0, Bolt, Cursor, Replit, and fast Vercel launches.
Free visitors can scan fast. Full report unlock, history, and Creem checkout are the next production layer.
Headers, CORS, cookies, public files, source maps, and bundle secrets are scored into a plain-English report.
Run a live scan