Security & performance scan for your vibe-coded app

A second opinion on everything your agent ships.

149+ automated checks across your repo and your deployed site. Secrets, phantom imports, open auth routes, dead performance. One ranked report in under 2 minutes.

vibedoctor.io / scans / you-your-app Scan complete
Overall score
61 /100
Needs attention
Security48
Code quality63
Performance71
356 issues found
critical Stripe secret key committed to source lib/payments.ts:14
critical No rate limiting on /api/login app/api/login/route.ts
high Import of a package that does not exist utils/slugify.ts:2
high CORS allows every origin middleware.ts:31
medium Same fetch logic duplicated in 6 files components/*
medium 2.4 MB of unoptimised images on first load public/hero.png
low Missing page metadata app/layout.tsx
V In your agent

Fixed the Stripe key leak and added a rate limit to /api/login. Rescanning now.

Connects to
What it checks

Six things agents get wrong on almost every project.

01 21 checks

Secrets and credentials

API keys, tokens and service credentials committed into source, env files or client bundles.

02 22 checks

Auth and access

Unprotected routes, no rate limit on login or sign up, permissive CORS, sessions that never expire.

03 8 checks

Dependencies

Hallucinated imports, unpinned versions, known CVEs and packages nobody ever installed.

04 29 checks

Vibe coding health

Duplicated logic, dead files, half finished refactors and TODOs the agent promised to come back to.

05 16 checks

Performance

Payload size, render blocking assets, unoptimised images and the requests that make first load crawl.

06 34 checks

SEO and best practices

Metadata, crawlability, accessibility basics and whether an AI search engine can read your pages.

See all 149+ checks across 21 diagnostic areas.

How it works

Paste, scan, fix.

01

Paste one line into your agent

It installs the MCP server itself. Nothing to configure, no dashboard to learn, no keys to paste.

02

Ask it to scan

149+ checks run across your source and your deployed URL in under 2 minutes, public repo or private.

03

Fix it in the same chat

Findings come back ranked with file paths, so the agent that wrote the code can go straight to fixing it.

4%

imported at least one package that does not exist

35%

had API keys or secrets committed to the repo

6%

had no rate limiting on auth endpoints

Measured across
1,099

repos scanned to July 2026

Live scan results

Apps getting checked right now.

Showing the latest 20 of 5,579 scans

Country Language Findings When
INTypeScript2392 files9 critical19 high210 mediumAI Search ReadyCompliant15m ago
NOC#1990 files10 high19 medium43m ago
CNWebsite7 critical16 high6 mediumNot AI Search ReadyCompliant1h ago
CNWebsite7 critical16 high6 mediumNot AI Search ReadyCompliant1h ago
USPython1128 files3 high650 mediumAI Search ReadyCompliant7h ago
GBPython149 files6 high139 medium16h ago
GBWebsite6 critical17 high1 mediumNot AI Search ReadyCompliant19h ago
GBWebsite6 critical17 high1 mediumNot AI Search ReadyCompliant19h ago
INWebsite1 critical3 high5 mediumNot AI Search ReadyCompliant1d ago
USWebsite8 critical17 high5 mediumNot AI Search ReadyNot Compliant1d ago
GBWebsite5 critical6 mediumNot AI Search ReadyNot Compliant2d ago
GBWebsite5 critical6 mediumNot AI Search ReadyNot Compliant2d ago
ILWebsite2 highAI Search ReadyCompliant3d ago
GBWebsite2 criticalNot AI Search ReadyCompliant3d ago
GBWebsite2 criticalNot AI Search ReadyCompliant3d ago
NLWebsite3 critical11 high5 mediumNot AI Search ReadyCompliant3d ago
NLWebsite17 mediumAI Search ReadyCompliant3d ago
NLWebsite3 critical11 high5 mediumNot AI Search ReadyCompliant3d ago
USWebsite1 criticalNot AI Search ReadyCompliant3d ago
MZTypeScript425 files2 critical9 high84 medium3d ago
INTypeScript244 files21 critical51 high441 medium3d ago
INTypeScript254 files8 critical2 high87 medium4d ago
NLWebsite2 critical2 mediumNot AI Search ReadyCompliant4d ago
SAWebsite5 critical17 highNot AI Search ReadyCompliant4d ago
SATypeScript137 files10 critical11 high226 medium4d ago
SATypeScript135 files8 critical12 high225 medium4d ago
SAWebsite5 critical17 highNot AI Search ReadyCompliant4d ago
SAWebsite5 critical17 highNot AI Search ReadyCompliant4d ago
CAWebsite3 critical1 high8 mediumNot AI Search ReadyCompliant4d ago
USTypeScript77 files1 high56 medium4d ago
USSwift93 files1 medium4d ago
ATTypeScript693 files37 high480 medium4d ago
ATTypeScript693 files32 high476 medium4d ago
ATTypeScript693 files32 high476 medium4d ago
🌐Python341 files10 critical101 high506 medium4d ago
🌐TypeScript543 files23 critical6 high205 mediumNot AI Search ReadyCompliant5d ago
PYTypeScript158 files2 critical32 high89 medium6d ago
🌐TypeScript158 files2 critical29 high91 medium6d ago
PKJavaScript28 files2 critical4 high56 medium6d ago
🌐TypeScript554 files4 critical73 high244 medium10d ago
Vibe X-Ray

See what your agent actually built.

Every scan rebuilds a map of your codebase: modules, the sub-modules inside them, and the files where the findings actually sit. Follow the red down three levels and you land on the file to fix. Paste that one file into your agent instead of the whole repo.

All modules › Api › api/auth X-Ray ready
316 features detected 16 findings main 4f2c1ab 29 connections Sample project
31 18 204 96 47 Api 41 feat / 88 nodes 9 findings / health 38 App 118 feat / 214 nodes 4 findings / health 66 Components 96 feat / 181 nodes 3 findings / health 74 Lib 27 feat / 63 nodes health 91 api/auth 8 feat / 19 nodes 5 findings / health 24 api/stripe 6 feat / 14 nodes 4 findings / health 41 app/(dashboard) 34 feat / 61 nodes 4 findings / health 66 components/forms 22 feat / 38 nodes 3 findings / health 74 lib/db 11 feat / 24 nodes health 91 app/api/login/route.ts critical No rate limiting lib/session.ts high Session never expires app/api/webhook/route.ts critical Signature not verified lib/payments.ts critical Stripe key in source app/(dashboard)/page.tsx medium Missing page metadata components/UploadForm.tsx high No file type check lib/db/client.ts clean no findings
Unhealthy (<60) Fair (60-80) Healthy (>80)

Drill to the function

Module, then sub-module, then the file and the functions inside it. Findings are pinned to the symbol they came from.

Dead code and coverage

Two more tabs on the same map: what nothing calls any more, and which parts of the code no test touches.

Fewer tokens per prompt

Send the files a change actually touches instead of the repo. How Vibe X-Ray works.

On every plan, rebuilt on every scan. From $0, Watch from $15/mo. See pricing.

Questions.

Is AI-generated code safe to ship?

It usually runs, and it usually ships with the same handful of holes: keys committed to source, auth routes with no guard, missing rate limits, imports of packages that do not exist. This is a scan for people shipping apps their agent mostly wrote, and it finds those before your users do.

Does VibeDoctor modify or write to my code?

No writes. The scan reads your repo and your live site and returns findings. Any fixing happens in your editor, by you or your agent.

Can VibeDoctor scan a private GitHub repository?

Yes. Connect the GitHub App and access is scoped to read-only. Source is analysed only for the length of the scan, then dropped.

What languages and frameworks does VibeDoctor scan?

JavaScript and TypeScript, Python, Go, Ruby, Java, PHP and Rust, with framework-aware checks for React, Next.js, Express, Fastify, Django, Flask, FastAPI, Rails and Spring. Anything the site-side checks can reach over HTTP is covered as well.

How do I connect VibeDoctor to Claude Code, Cursor or Codex?

Paste one line into the agent: connect to vibedoctor using https://vibedoctor.io/mcp/start. It fetches the instructions, installs the MCP server itself, and reports back in the chat you already have open. No keys to copy, no config file to edit.

How do I find hallucinated npm packages in AI-generated code?

Every scan verifies each dependency against the registry, so an import of a package that does not exist is flagged with its file and line. It is one of the most common AI-generated defects: 4% of the repositories scanned in production had at least one.

How is VibeDoctor different from SonarQube, Snyk or CodeRabbit?

There is real overlap. VibeDoctor runs the same classes of engine they do: a SAST pass, secret detection, dependency CVE scanning, and each language's own linter and type checker (opengrep, gitleaks, trivy, ruff, biome, pyright, tsc, clippy, rubocop, phpstan). What it adds is your deployed site scanned alongside the repo (Lighthouse, security headers, SSL, SEO, exposed files, console errors), checks aimed at AI-generated code such as imports of packages that do not exist, and a graph of your codebase. It also runs from inside your agent over MCP, so findings arrive in the chat where the code was written.

What is Vibe X-Ray?

A four-level visual explorer for your codebase: modules, files, symbols and the dependencies between them. It shows what your agent actually built - which functions call what, where complexity hides, and what breaks if you touch something. It updates with every scan.

Is VibeDoctor free?

Yes. The free plan covers one project, one scan a day, and the full report, with no card required. Paid plans add more projects, a scan on every push, and PR review.

Scan it before your users do.

connect to vibedoctor using https://vibedoctor.io/mcp/start

Or paste a repo URL and skip the setup entirely.

Someone in India scanned their app
238 issues found · scored 68/100