FixVibe

Build with your agent. Check what is live.

Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.

See a sample scan → repair → verify workflow

FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.

How it fits your workflow

Your agent repairs it. Recheck the deployed header.

Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.

This workflow example is currently available in English.

  1. 01

    Inspect the deployed app

    Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.

  2. 02

    Repair in your existing workflow

    Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.

  3. 03

    Deploy, then request verification

    See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.

Synthetic example · not a customer report

Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.

Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.

This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.

Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.

Scanner-Abdeckung

240+
abgedeckte Schwachstellenklassen
230+
passive Checks / Scan
130+
aktive Checks / Scan
190+
GitHub-Checks / Scan

Kompatibel mit

A security check alongside your coding agent.

Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.

  • Cursor
  • Claude Code
  • OpenAI Codex
  • GitHub Copilot
  • Lovable
  • Bolt.new
  • v0
  • Replit Agent
  • Windsurf
  • Devin
  • Google Jules
  • Gemini CLI
  • Firebase Studio
  • Amazon Q Developer
  • JetBrains Junie
  • Kiro
  • Tabnine
  • Qodo
  • Sourcegraph Amp
  • Continue
  • Cline
  • Roo Code
  • Aider
  • OpenCode
  • Base44
  • Anything
  • Builder.io Fusion
  • Tempo
  • Softgen
  • Trae

Guides

Secure your AI-built app.

FixVibe — Sicherheitsscanner fĂŒr KI-generierte Apps