Is your vibe-coded appleaking secrets?
45% of AI-generated apps ship with at least one critical security flaw. Find out where yours stands in 60 seconds. Free.
We scan what we build, too
Every line of production code at Robust Devs goes through the same security checks. The scanner above is the public version of what we run internally before any client repo ships.
Schedule a meeting
How it works
Three steps. Sixty seconds.
Paste your URL
Any public app URL: Lovable, Bolt, v0, Vercel, Replit, custom domain.
We scan, passively
Read-only checks against your public surface. No exploits, no intrusive probes, no auth attempts.
Get your report
Letter grade + prioritized findings + remediation steps. PDF emailed to you.
What we check
20+ automated security checks for every vibe-coded app
One scan runs 20+ checks across transport, DNS, sessions, backend rules, exposed secrets, recon and subdomain takeover, CSRF, and dependency CVEs — plus a bonus site-audit layer for performance, SEO, and accessibility. A passive, read-only audit of what attackers can already see.
Transport & headers
SSL/TLS protocol, cipher strength, and certificate expiry, plus your security headers graded by Mozilla Observatory (CSP, HSTS, and more).
DNS & email
SPF, DKIM, and DMARC records — the DNS configuration that stops attackers spoofing email from your domain.
Sessions & content
Cookie flags (Secure, HttpOnly, SameSite), mixed content, CSRF token presence, and risky client-side XSS sinks in your page code.
Clickjacking & CORS
Whether your pages can be embedded in a malicious iframe, and whether your CORS policy lets any site read your responses.
Backend rules
Firebase and Supabase probed read-only for open database rules — the #1 vibe-coded mistake that exposes every row to anonymous users.
Secrets, APIs & tokens
Exposed API keys (Stripe, OpenAI, AWS), GraphQL schema leaks via introspection, and JWTs decoded for weak algorithms and leaked claims.
Recon & takeover
Threat-intel reputation, hosting fingerprint, and dangling DNS records that leave subdomains open to takeover by an attacker.
Dependency CVEs
Front-end libraries fingerprinted by version and cross-checked against public CVE databases for known, already-published vulnerabilities.
Site audit (bonus)
A non-security layer: Core Web Vitals performance, SEO, accessibility (WCAG), and AI answer-engine readability — guidance that never affects your grade.
FAQ
Honest answers.

Don't ship vulnerable code to production