Free security scan
Scan your vibe-coded app
Paste the URL of something you built with an AI app maker. A real server-side scan checks where it is exposed, and shows you the report.
About this scan
- Is this scan safe to run on my site?
- Yes. Every probe is read-only. It does not log in, write data, or delete anything. It looks at what your site already serves to the public, the way a visitor would. One check sends a short burst of normal page requests to see whether you rate-limit; that is lighter than a refresh-happy visitor, and it never tries passwords.
- Why does the full scan run on a server, not in my browser?
- Browsers block one site from reading another site responses, a rule called CORS. That means a page cannot inspect your headers, endpoints, or code from here. The full scan runs on our worker, which can make those requests, then saves you a report.
- What does the full scan check?
- Security headers and TLS, the open data-endpoint pattern, secrets exposed in the JavaScript bundle, permissive CORS, unauthenticated API routes that hand out data, sensitive routes that answer anonymous callers, and whether requests are rate-limited. It is powered by the same engine that pen-tests the DontCode platform every week.
- How do I just not have these problems?
- Build on infrastructure that closes them by default. On DontCode, authorization, a checked data plane, secret handling, and rate limits are part of the platform, not a checklist you maintain.