Did your AI-built site ship a secret?
A passive security check for vibe-coded and AI-built websites. We read what your site already serves: shipped JavaScript, headers, exposed files and libraries, and show you what is leaking, with the evidence. No login, no exploit.
What we check
Secrets in JavaScript
Scans shipped bundles for live secret keys and private-key blocks. Any match is shown masked, never in full.
Source maps
Public .map files hand your original source to anyone. We flag bundles that reference one.
Exposed files
.env, .git config and backups, checked for existence only, never downloaded or read.
Security headers
CSP, HSTS, clickjacking and MIME-sniffing protection, plus cookie flags and CORS.
Mixed content
Subresources loaded over plain HTTP on an HTTPS page, which browsers block or downgrade.
Vulnerable libraries
Front-end libraries with public CVEs, matched against a dated local dataset.
Shipped fast, now make it safe
We take AI-built prototypes to production: the security, the polish and the code quality that a launch actually needs.
Hire a vibe coderTalk to us