Security for vibe-coded apps · powered by anal-probe

Ship with vibe.
Scan before customers bad guys do.

Continuous black-box security for AI-built software. Leaked keys, exposed .env, broken headers, framework footguns — ranked for agents with fix packs & Gherkin. Prove you own the app (domain email + inbox click, or DNS TXT). Then scan on a schedule or every commit.

Free lite scan

Point it at your deploy. No signup.

Instant check for leaked secrets, exposed config, core security headers & DNS. Full suite unlocks after domain-email inbox proof or DNS TXT.

Own it first

Sign in with an email on the domain you are testing and click the inbox verify link — or place a DNS TXT record. No scanning other people’s apps.

Agent fix packs

Every finding becomes a ranked P1→Pn prompt for Claude / Cursor / Codex.

Cadence that matches how you ship

Weekly · daily · or every commit/deploy webhook.

Full test suite

Not a dozen checks. A real rule surface.

The homepage grid is 13 categories— under them sit 150+ fixed black-box probes plus a 213+ client CVE version ranges (363+ rules the full engine can evaluate). Runtime multiplies further: every cookie, script bundle, and crawl page gets re-checked. Lite samples four categories; paid fleet runs the full OSS suite.

13
Categories
150+
Black-box probes
213+
Client CVE ranges
117+
CVE refs in feed
27
Exposure paths
23/25
ASVS L1 (black-box)

lite = included in free homepage scan (4 categories, sampled). Full fleet + history needs ownership + a paid plan.

liteCritical when hit

Leaked secrets

13+ probes · secrets

HTML + every same-origin JS bundle scanned for real credentials. Public keys (pk_live, anon) ignored. Source maps flagged when downloadable.

  • Stripe sk_live / rk_live
  • AWS AKIA…
  • OpenAI / Anthropic
  • GitHub PAT
  • Slack token
  • PEM private key
  • +3 more
liteHigh

Exposed config & debug

40+ probes · exposure

27+ paths body-validated (no SPA false positives), plus stack traces, GraphQL introspection, directory listings, robots sensitive paths.

  • /.env (+.local/.production/.bak)
  • /.git/config + HEAD
  • /.aws/credentials
  • wrangler.toml / package.json
  • backup.sql / .zip / .tar.gz
  • actuator / metrics / swagger
  • +3 more
liteHigh–Medium

Headers, TLS, CORS, cookies

45+ probes · security

Deepest category: required headers, CSP weakness grading, cookie flags, TLS grade, open redirects, SRI, JWT hygiene, host-header, CSRF heuristics, DOM-XSS sinks.

  • HSTS + preload eligibility
  • CSP unsafe-inline / eval / wildcards
  • nosniff · clickjacking · Referrer-Policy
  • Permissions-Policy · COOP · CORP
  • Cookie Secure/HttpOnly/SameSite/__Host-
  • TLS protocol + cipher + expiry
  • +3 more
liteMedium

DNS & email hygiene

4+ probes · dns

SPF + DMARC policy strength, CAA (who may issue certs), dangling-CNAME subdomain takeover heuristics — all passive DNS.

  • SPF present
  • DMARC policy strength
  • CAA issuers
  • Dangling CNAME takeover
High when hit

Framework misconfigs

20+ probes · framework

Fingerprints Next.js, WordPress, Laravel, Django, Rails, Spring, ASP.NET — probes stack footguns only on confident match.

  • Next.js __NEXT_DATA__ secrets
  • WP users REST + xmlrpc
  • Laravel Telescope / Ignition
  • Django DEBUG pages
  • Rails /sidekiq · /rails/info
  • Spring Actuator env/heapdump
  • +1 more
High–Medium

Vulnerable client libraries

213+ version ranges · components

OWASP A06: fingerprint jQuery, Bootstrap, Lodash, AngularJS, Vue 2, axios… against an auto-updating feed of version ranges.

  • jQuery XSS ranges
  • Bootstrap <4.3.1
  • Lodash proto-pollution
  • AngularJS EOL + CVEs
  • axios SSRF / header gadgets
  • Vue 2 EOL
  • +2 more
Medium–Low

Reliability

5+ probes · reliability

Homepage health, broken same-origin links/images (sampled), mixed content on HTTPS pages.

  • Homepage status
  • Broken links
  • Broken images
  • Mixed content
Low

SEO basics

7+ probes · seo

Title, meta description, Open Graph, canonical, single h1, robots.txt, sitemap.xml.

  • <title>
  • meta description
  • Open Graph
  • canonical
  • single h1
  • robots.txt
  • +1 more
Low

Accessibility basics

4+ probes · a11y

html lang, viewport, images missing alt, unlabeled form inputs (WCAG starter checks).

  • html lang
  • viewport meta
  • img alt
  • form labels
Low

Performance hygiene

4+ probes · performance

Compression, oversized HTML, script count, cache headers on static assets.

  • gzip/brotli
  • HTML weight
  • script count
  • cache headers
Info–Low

Agent readiness

8+ probes · agent

Is your deploy consumable by AI crawlers? llms.txt, robots AI bots, SSR text density, structured data, MCP/ai-plugin manifests.

  • llms.txt
  • AI bot robots
  • SSR text density
  • JSON-LD
  • MCP / ai-plugin manifests
Info

Host intel (passive)

3+ probes · host

Resolved IPs, reverse DNS, CDN/hosting fingerprint — no port scanning in default mode.

  • A/AAAA resolve
  • Reverse DNS
  • CDN / hosting fingerprint
Custom

Custom plugin checks

user-defined · plugins

Drop JSON templates (status/header/body matchers) for org-specific checks with zero code.

  • GET/HEAD only
  • status / header / body matchers
  • and|or conditions
  • Nuclei-style JSON

Beyond the default pass

Opt-in modes and white-box helpers — not silent "we test everything" claims. Active exploit fuzzing (SQLi/SSRF) stays out of scope on purpose.

recon
Recon + service CVEs

Authorization-gated port/service ID; optional NVD CVE correlation (identify-only).

crawl
Deep browser crawl

Every reachable page: JS errors, broken assets, safe reflected-input probes.

browse
Headless functional smoke

Playwright browse: does the UI actually load and accept input?

separation
Tenant isolation

Two-account cross-tenant leak test for multi-tenant apps.

audit
Dependency CVEs

npm advisory audit when you point at a repo / lockfile context.

whitebox
White-box helpers

IDOR, RBAC, mass-assignment, data-isolation probes for your own test suite.

How we count (honestly): ~150+ are discrete black-box probes in the engine. ~213+ are client-library version ranges (12 libs, 117+ CVE refs) matched when those libraries appear on the page. A single full scan often emits 40–120 findings depending on the target; crawl/recon modes add more. We do notclaim "1,000 tests" as fixed checkboxes — that would be inflated. The surface is large because of rules + dynamic coverage, not fake line items.

Pricing

Hosted plans

Open-source CLI is free forever. Hosted plans add ownership verification, dashboard, cadence, and commit hooks.

Lite
$0

Public homepage lite scan — tease the full suite

  • Public homepage scanner
  • Secrets · exposure · headers · DNS
  • Rate-limited
Try lite scan
Weekly
$25/mo

1 full security scan per week for one verified app

  • 1 verified project
  • Ownership proof required
  • Manual + scheduled
  • 60d history · agent fix packs
  • MCP + API keys
Start Weekly
Daily
$100/mo

Full scan every day — catch regressions while you vibe

  • 3 verified projects
  • Ownership proof required
  • Deploy hooks
  • 90d history · agent fix packs
  • GitHub checks
  • MCP + API keys
Start Daily
Every commit
$250/mo

Scan on every push / deploy — continuous ship security

  • 10 verified projects
  • Ownership proof required
  • Every commit / deploy hook
  • 180d history · agent fix packs
  • GitHub checks
  • MCP + API keys
Start Every commit

Open source core

The scanner engine is Apache-2.0. Run it locally, in CI, or fork it. Hosted VibeTesting Agent adds auth (WorkOS), billing (Stripe), ownership gates, and always-on cadence.

npx github:newsengine/anal-probe review https://your-app.example.com

Ownership security

  1. Create a project with your production URL
  2. Domain email: sign in with an address on that domain, then click the one-time link we email to prove you control the inbox
  3. Or DNS TXT: place vibetesting-verify=… on the host (or _vta.) in your DNS control panel
  4. Only then: full scans, schedules, deploy/commit webhooks
  5. Authorization checkbox + audit log on every scan