Vibe Coding Security Scanner
Scan your web app before you launch.
Check your deployed app for exposed data, leaked secrets, insecure configuration, missing browser protections, and other security mistakes commonly missed when shipping quickly with AI coding tools.
Coverage
What GuardMint checks
GuardMint analyzes the publicly observable security surface of your deployed web app: what any visitor, browser, or attacker could see without logging in.
Public API data exposure
Checks common API paths for JSON responses that return personal, payment, or admin fields without a login.
Exposed files & secrets
Looks for files like .env, .git/config, or Supabase and Firebase config that can be downloaded publicly.
Frontend JS secrets
Scans your public HTML and JavaScript bundles for private credentials, such as secret API keys or service-role tokens.
Supabase exposure
When a Supabase project and anon key are found, checks whether a few common tables return rows without authentication.
Security headers
Reviews browser protections such as Content-Security-Policy, HSTS, clickjacking, and MIME-sniffing headers.
CORS
Flags API responses that let any other website read your data cross-origin.
Cookies & sessions
Checks session cookies for missing Secure, HttpOnly, and SameSite protections.
Error & debug leakage
Looks for stack traces, framework or database errors, and debug output in public responses.
Open ports & infrastructure
Checks a short, fixed list of common ports for publicly reachable databases, caches, or dev servers.
HTTPS / TLS
Confirms your site is served over HTTPS and that plain HTTP visits redirect to it.
Route exposure
Checks common admin and API-documentation paths for interfaces that load without a login.
Source maps
Flags production source maps that make your original source code readable to anyone.
Plus launch-readiness checks: Domain & email (DNS) and Legal & trust pages. These are reported separately and don't lower your security score.
The report
Don’t just find problems. Fix them.
A GuardMint report goes beyond a generic score. Each finding shows the evidence, its severity, and what to change, so you or your AI coding tool can fix it.
- What was detected
- Why it matters
- What should change
- Where to fix it
- An AI-ready fix prompt, when available
Public API returns user or business data
/api/profiles
What was detected
/api/profiles returned JSON containing personal or business fields without authentication. If this isn't meant to be public, require a login first.
emailnameuser_idWhy it matters
What should change
Where to fix it
Paste this into Claude Code, Cursor, or your AI coding tool
Review this public API route. Confirm whether it should be accessible without authentication. If it returns user, customer, case, payment, or admin data, require authentication and authorization before returning the response. Add tests that unauthenticated requests receive 401 or 403.
Taken from the example report. Your report shows the findings from your own app.
How it works
From URL to fix list in one scan
- 1
Enter your app URL
Provide the URL of your publicly accessible deployed application.
- 2
GuardMint scans the public surface
GuardMint performs automated, non-invasive checks against externally observable security signals.
- 3
Get prioritized fixes
Review findings, evidence, severity, and remediation guidance.
GuardMint performs automated checks against your app's publicly observable security surface. See how GuardMint scans
For AI builders
Built for the way AI apps are shipped
AI coding tools can take an idea to a deployed app in an afternoon. That speed makes it easy to miss things that are visible from outside: a secret key bundled into client code, an API route without an auth check, a debug endpoint left on, or a missing header. GuardMint is designed to catch these before your users find them.
What you get
Everything you need to act on a scan
Security score and launch verdict
A 0–99 score and a clear verdict, shown as soon as the scan finishes.
Findings organized by severity
Critical to informational, so you know what to fix first.
Evidence of what was observed
The affected URL, status, and signals behind each finding. Secrets are always masked.
Why each finding matters
A plain-language explanation of the risk, without security jargon.
Remediation guidance
What should change, plus where the fix usually lives: your host, framework, API route, or Supabase.
AI-ready fix prompts
Copy-paste prompts for Cursor, Claude Code, or your AI builder, included with findings that support them.
Launch-readiness checks
Domain email records and legal and trust pages, reported separately from your security score.
A report URL to return to
Every scan gets its own report page you can come back to after you fix things.
No account needed to scan and see your score. Create a free account to see every finding, with evidence and fix guidance. Compare Free and Pro
What a GuardMint scan means
GuardMint performs automated checks against your app's publicly observable security surface.
A clean report means GuardMint found no issues in what it could observe from outside. Issues behind a login or inside your source code need other kinds of review.
FAQ
Questions about the scanner
- What is a vibe coding security scanner?
- It's a scanner for apps built quickly with AI coding tools. GuardMint checks a deployed web app from the outside for the security mistakes that fast, AI-assisted builds often ship with, such as exposed API data, leaked secrets, public config files, and missing browser protections. Then it explains what to fix.
- What does GuardMint check?
- GuardMint checks 12 security areas: HTTPS / TLS, Exposed files & secrets, Frontend JS secrets, Source maps, Supabase exposure, CORS, Cookies & sessions, Public API data exposure, Error & debug leakage, Security headers, Route exposure, and Open ports & infrastructure. It also runs launch-readiness checks for Domain & email (DNS) and Legal & trust pages, which are reported separately and don't lower your security score.
- Can GuardMint detect exposed API keys or secrets?
- Yes, when they're publicly visible. GuardMint scans your public HTML, JavaScript bundles, and source maps for private credentials like secret provider keys, Supabase service-role keys, private keys, and database URLs with credentials. It also checks whether files like .env or .git/config can be downloaded. Public keys that are meant to be in the browser, like a Supabase anon key, aren't flagged as leaks. Secrets that live only on your server or in a private repository aren't visible to a public scan.
- Does GuardMint work with Vercel apps?
- Yes. GuardMint scans any publicly reachable URL, including custom domains and .vercel.app deployments. Remediation guidance points to where fixes usually live on Vercel and Next.js, such as next.config.js headers or vercel.json. Deployment settings that are only visible in your Vercel dashboard, like environment variables or preview protection, can't be checked from outside.
- Can GuardMint scan Supabase applications?
- Yes. If your frontend exposes a Supabase project URL and anon key, GuardMint makes read-only requests to check whether a short list of common tables return rows without authentication. It also flags a service-role key shipped to the browser. A clean result doesn't prove every table has correct Row Level Security. It only means these checks found no public exposure.
- Does GuardMint need access to my source code?
- No. The public scan only needs your app's URL. It doesn't ask for passwords, API keys, database credentials, or repository access.
- Is GuardMint's scan invasive?
- No. GuardMint is intentionally non-invasive. It makes a capped number of read-only requests, doesn't log in, doesn't submit forms, and doesn't exploit vulnerabilities, brute-force anything, or run destructive tests. Only scan apps you own or are authorized to test.
- Does passing a GuardMint scan mean my app is secure?
- No. A clean report means GuardMint found no issues in what it could observe from the outside. Many vulnerabilities, like broken authorization behind a login, need authenticated testing or source-code review. Treat GuardMint as a pre-launch check, not a security guarantee.
Related guides: Vercel security checklist · Supabase RLS checklist · Launch security checklist
Ready to check your app?
Run a free GuardMint scan against your deployed application.
No account needed to scan and see your score. Only scan apps you own or are authorized to test.