security review for vibe-coded apps
paste a github repo. get a security score, a claude-powered code review, every issue with file and line, and ready-to-paste claude prompts that fix them — in under a minute. free · no card · public repos · secrets always redacted.
we fetch the public archive — no oauth, no installs, nothing written to disk.
one number, six subscores, and every finding ranked by severity with file + line.
each finding ships a claude-ready prompt. paste it into claude code, review the diff, re-scan.
api keys, tokens, private keys, and connection strings sitting in your code or git history.
sql built by string-mashing, eval/exec on input, shell commands assembled from variables, raw html sinks.
jwt 'none' algorithms, default signing secrets, debug mode in prod, wide-open cors.
.env files, service-account json, database dumps and private keys committed to the repo.
missing lockfiles, wildcard versions, deps installed from raw urls, curl-pipe-sh installs.
certificate verification turned off, plaintext http calls, express apps without security headers.
one free scan on claude haiku · full score, every finding, every fix + claude prompt included.
claude opus 4.8 reviews that read your whole repo, with every finding double-checked to filter false positives · weekly monitoring + email alerts · shareable report + live readme badge · 300 credits/mo · also $9/wk or $228/yr (save 34%).
no. paste a public github link and we read the same archive anyone can download. nothing is cloned to disk and nothing is stored except your report — with every secret redacted.
every scan runs the full rules engine plus an ai code review and costs credits. your first scan is free on claude haiku (one-time, no card). pro scans run on claude opus (10 credits, 300 a month).
every finding comes with a ready-to-paste prompt for claude code (or any coding agent): the issue, the file and line, why it matters, and exactly what to change. paste it, review the diff, done.
six category subscores, each starting at 100 and losing points per finding by severity, then combined with security-weighted importance — secrets count 3× more than transport.
that is exactly what it is for. ai-generated codebases ship fast and skip the security pass — securevibes is that security pass, with the fixes written for the same tools that built the app.