Vibe Coding Security Scanner

Scan your web app before you launch.

Check your deployed app for exposed data, leaked secrets, insecure configuration, missing browser protections, and other security mistakes commonly missed when shipping quickly with AI coding tools.

Paste your live app's address — that's all we need to start. We'll add https:// if you leave it off.

By scanning, you confirm you own or are authorized to test this app.

  • Free public scan
  • No account needed for your score
  • No credentials required
  • 12 security areas checked
  • Actionable fixes

Improve my scan results (optional)

Tell GuardMint about your stack and app features to get more relevant findings and recommendations.

Add details

Optional — add it to identify or claim this scan later. We don't email the report; it opens as soon as the scan finishes.

What's in your stack?

Check everything your app uses or includes.

A few quick questions

These help us flag risks we can't always see from the outside.

Does your app store user data?
Does your app have login / accounts?
Does your app have an admin dashboard?
Does your app accept payments?
Does your app allow file uploads?
Does your app use AI prompts with user-submitted data?
Does your app use Supabase or Firebase?
Are you confident your database rules / RLS are configured?
Do users have private records that should not be visible to other users?
Is the app already live with real users?

Ready to scan?

Coverage

What GuardMint checks

GuardMint analyzes the publicly observable security surface of your deployed web app: what any visitor, browser, or attacker could see without logging in.

  • Public API data exposure

    Checks common API paths for JSON responses that return personal, payment, or admin fields without a login.

  • Exposed files & secrets

    Looks for files like .env, .git/config, or Supabase and Firebase config that can be downloaded publicly.

  • Frontend JS secrets

    Scans your public HTML and JavaScript bundles for private credentials, such as secret API keys or service-role tokens.

  • Supabase exposure

    When a Supabase project and anon key are found, checks whether a few common tables return rows without authentication.

  • Security headers

    Reviews browser protections such as Content-Security-Policy, HSTS, clickjacking, and MIME-sniffing headers.

  • CORS

    Flags API responses that let any other website read your data cross-origin.

  • Cookies & sessions

    Checks session cookies for missing Secure, HttpOnly, and SameSite protections.

  • Error & debug leakage

    Looks for stack traces, framework or database errors, and debug output in public responses.

  • Open ports & infrastructure

    Checks a short, fixed list of common ports for publicly reachable databases, caches, or dev servers.

  • HTTPS / TLS

    Confirms your site is served over HTTPS and that plain HTTP visits redirect to it.

  • Route exposure

    Checks common admin and API-documentation paths for interfaces that load without a login.

  • Source maps

    Flags production source maps that make your original source code readable to anyone.

Plus launch-readiness checks: Domain & email (DNS) and Legal & trust pages. These are reported separately and don't lower your security score.

The report

Don’t just find problems. Fix them.

A GuardMint report goes beyond a generic score. Each finding shows the evidence, its severity, and what to change, so you or your AI coding tool can fix it.

  • What was detected
  • Why it matters
  • What should change
  • Where to fix it
  • An AI-ready fix prompt, when available
Example report — yourapp.vercel.app
HighAPI exposure

Public API returns user or business data

/api/profiles

What was detected

/api/profiles returned JSON containing personal or business fields without authentication. If this isn't meant to be public, require a login first.

Sensitive fields detected:emailnameuser_id

Why it matters

Public API routes that return user, customer, or admin data without a login let anyone read information meant to be private.

What should change

Require authentication and authorization before returning this data, and confirm anonymous requests receive 401 or 403.

Where to fix it

Add an authentication and authorization check inside the API route handler (Next.js route handler or server action) before it returns any data.

Paste this into Claude Code, Cursor, or your AI coding tool

Review this public API route. Confirm whether it should be accessible without authentication. If it returns user, customer, case, payment, or admin data, require authentication and authorization before returning the response. Add tests that unauthenticated requests receive 401 or 403.

Taken from the example report. Your report shows the findings from your own app.

How it works

From URL to fix list in one scan

  1. 1

    Enter your app URL

    Provide the URL of your publicly accessible deployed application.

  2. 2

    GuardMint scans the public surface

    GuardMint performs automated, non-invasive checks against externally observable security signals.

  3. 3

    Get prioritized fixes

    Review findings, evidence, severity, and remediation guidance.

GuardMint performs automated checks against your app's publicly observable security surface. See how GuardMint scans

For AI builders

Built for the way AI apps are shipped

AI coding tools can take an idea to a deployed app in an afternoon. That speed makes it easy to miss things that are visible from outside: a secret key bundled into client code, an API route without an auth check, a debug endpoint left on, or a missing header. GuardMint is designed to catch these before your users find them.

GuardMint scans the deployed result, whatever you built it with, including apps made with:

GuardMint is independent and isn't affiliated with these tools. Linked names open our security guide for that builder.

What you get

Everything you need to act on a scan

  • Security score and launch verdict

    A 0–99 score and a clear verdict, shown as soon as the scan finishes.

  • Findings organized by severity

    Critical to informational, so you know what to fix first.

  • Evidence of what was observed

    The affected URL, status, and signals behind each finding. Secrets are always masked.

  • Why each finding matters

    A plain-language explanation of the risk, without security jargon.

  • Remediation guidance

    What should change, plus where the fix usually lives: your host, framework, API route, or Supabase.

  • AI-ready fix prompts

    Copy-paste prompts for Cursor, Claude Code, or your AI builder, included with findings that support them.

  • Launch-readiness checks

    Domain email records and legal and trust pages, reported separately from your security score.

  • A report URL to return to

    Every scan gets its own report page you can come back to after you fix things.

No account needed to scan and see your score. Create a free account to see every finding, with evidence and fix guidance. Compare Free and Pro

What a GuardMint scan means

GuardMint performs automated checks against your app's publicly observable security surface.

A clean report means GuardMint found no issues in what it could observe from outside. Issues behind a login or inside your source code need other kinds of review.

Read our methodology and limitations Scan disclaimer

FAQ

Questions about the scanner

What is a vibe coding security scanner?
It's a scanner for apps built quickly with AI coding tools. GuardMint checks a deployed web app from the outside for the security mistakes that fast, AI-assisted builds often ship with, such as exposed API data, leaked secrets, public config files, and missing browser protections. Then it explains what to fix.
What does GuardMint check?
GuardMint checks 12 security areas: HTTPS / TLS, Exposed files & secrets, Frontend JS secrets, Source maps, Supabase exposure, CORS, Cookies & sessions, Public API data exposure, Error & debug leakage, Security headers, Route exposure, and Open ports & infrastructure. It also runs launch-readiness checks for Domain & email (DNS) and Legal & trust pages, which are reported separately and don't lower your security score.
Can GuardMint detect exposed API keys or secrets?
Yes, when they're publicly visible. GuardMint scans your public HTML, JavaScript bundles, and source maps for private credentials like secret provider keys, Supabase service-role keys, private keys, and database URLs with credentials. It also checks whether files like .env or .git/config can be downloaded. Public keys that are meant to be in the browser, like a Supabase anon key, aren't flagged as leaks. Secrets that live only on your server or in a private repository aren't visible to a public scan.
Does GuardMint work with Vercel apps?
Yes. GuardMint scans any publicly reachable URL, including custom domains and .vercel.app deployments. Remediation guidance points to where fixes usually live on Vercel and Next.js, such as next.config.js headers or vercel.json. Deployment settings that are only visible in your Vercel dashboard, like environment variables or preview protection, can't be checked from outside.
Can GuardMint scan Supabase applications?
Yes. If your frontend exposes a Supabase project URL and anon key, GuardMint makes read-only requests to check whether a short list of common tables return rows without authentication. It also flags a service-role key shipped to the browser. A clean result doesn't prove every table has correct Row Level Security. It only means these checks found no public exposure.
Does GuardMint need access to my source code?
No. The public scan only needs your app's URL. It doesn't ask for passwords, API keys, database credentials, or repository access.
Is GuardMint's scan invasive?
No. GuardMint is intentionally non-invasive. It makes a capped number of read-only requests, doesn't log in, doesn't submit forms, and doesn't exploit vulnerabilities, brute-force anything, or run destructive tests. Only scan apps you own or are authorized to test.
Does passing a GuardMint scan mean my app is secure?
No. A clean report means GuardMint found no issues in what it could observe from the outside. Many vulnerabilities, like broken authorization behind a login, need authenticated testing or source-code review. Treat GuardMint as a pre-launch check, not a security guarantee.

Related guides: Vercel security checklist · Supabase RLS checklist · Launch security checklist

Ready to check your app?

Run a free GuardMint scan against your deployed application.

No account needed to scan and see your score. Only scan apps you own or are authorized to test.

Vibe Coding Security Scanner — Scan Your Web App | GuardMint