paste a github repo. a rules engine runs first, then claude reads the code, then a second pass argues against every finding and deletes the ones it can disprove. you get a score, every issue that survived with file and line, and a paste-ready prompt for each. about a minute.
two scans free · no card · public repos (paid scans read private ones) · secrets always redacted · see a real report · log in
we fetch the public archive. no oauth, no installs, nothing written to disk.
one number, six subscores, and every finding ranked by severity with file + line.
each finding ships a claude-ready prompt. paste it into claude code, review the diff, re-scan.
api keys, tokens, private keys, and connection strings sitting in your code or git history.
sql built by string-mashing, eval/exec on input, shell commands assembled from variables, raw html sinks.
jwt 'none' algorithms, default signing secrets, debug mode in prod, wide-open cors.
.env files, service-account json, database dumps and private keys committed to the repo.
missing lockfiles, wildcard versions, deps installed from raw urls, curl-pipe-sh installs.
certificate verification turned off, plaintext http calls, express apps without security headers.
two scans on claude haiku, no card. full score, every finding, every fix prompt. two because the point is to scan, fix, and scan again.
no subscription, no expiry. claude opus 5 reads your whole repo, a second skeptical pass throws out what it can disprove, and you get two scores: security and code quality · private repos · findings exported as github issues · weekly monitoring · shareable report + live readme badge · buy 1, 3 or 10.
no. paste a public github link and we read the same archive anyone can download. nothing is cloned to disk and nothing is stored except your report, with every secret redacted.
two scans free on claude haiku, no card. after that it's $5 a scan, bought one at a time or in packs of 3 or 10. there's no subscription and nothing expires. a scan that fails costs you nothing. it goes straight back on your balance.
every finding comes with a ready-to-paste prompt for claude code (or any coding agent): the issue, the file and line, why it matters, and exactly what to change. paste it, review the diff, done.
six category subscores, each starting at 100 and losing points per finding by severity, then combined with security-weighted importance: secrets count 3× more than transport.
that is exactly what it is for. ai-generated codebases ship fast and skip the security pass. securevibes is that security pass, with the fixes written for the same tools that built the app.