VibeScan
Dark Log in Join waitlist
Dark
Checks Stack Beyond Pricing FAQ
Auto-fix · one click

127 checks find it. One click fixes it.

Every finding goes to AI auto-fix agents. They write the patch, cross-check it against your code, and deliver it as a pull request on your GitHub repo. Nothing is merged without your approval.

01 · Find
127checks in every pass
  • Security63
  • SEO30
  • AI search (AEO)14
  • Performance12
  • Domain & TLS3
  • Email auth2
  • Compliance2
  • Accessibility1
02 · Fix
  • GPT-6 Astra · Opus 5.5 · GLM 5.3 · GLM 5.3 Flash
  • Podman sandbox
  • PR-ready patches

Works through the Claude Code CLI harness

03 · Ship
GitHub pull requestFixes land on a new branch as a PR you review and merge.
Fix promptsEvery finding compiles into a paste-ready prompt for your coding agent.
Human reviewNothing is merged or deployed without your approval.
Every scan covers Live site · 127 checksRepo · CodeQL deep analysisContainer images Reserve your spot →
Backed by VibeScan Labs

Security for websites
in seconds.

VibeScan runs 127 read-only checks across security, SEO, AI search, performance, domain, email, compliance and accessibility, then one click sends the findings to AI auto-fix agents that open a pull request on your repo.

Reserve your spot

Join The WaitList - Launching in Four Days

Free during launch week. One email at launch — no spam.

Use as an API-first engine

Claude Code Cursor Windsurf VS Code Codex Replit Copilot Antigravity

Site, code and backend. One scan.

Scan for issues
https:// your-app.dev
Connected scans
Website GitHub
REST API
$ curl -X POST /api/v1/scans → 202 Accepted
One-click auto-fix
8 issues
Beyond the scan
Live threats AEO scan Uptime
All 127 checks
Security SEO AEO Performance Domain Email A11y Compliance

Beyond the scan.

The same engine keeps watching long after the URL is submitted.

AEO scanner

Be the answer, not just a result.

ChatGPT, Claude and Perplexity are the new top of the funnel. VibeScan audits whether they can parse your site, trust your claims and cite you, then ships the rewrites that flip the answer.

User what's the best static-site scanner?
AI VibeScan runs 127 read-only checks across security, SEO, AEO and performance in about 40 seconds and ranks fixes by blast radius.
User is it free?
AI The first scan is. Paid tiers add fix-prompt exports, monitoring and connected scans.

Live threat feed

Know exactly when someone's trying to hack you.

Auth-bypass probes, credential-stuffing bursts, OWASP top-10 hits against your routes. We log the IP, the rule and the timestamp; you get a single Slack message.

Uptime

Know exactly when your site goes down.

Sixty-second probes from 12 regions, with a one-minute minimum downtime floor so flapping doesn't blow up your inbox.

The full website health stack. One scan.

  • Securityheaders · CSP · secrets · RLS · CORS
  • SEOsitemap · canonical · meta · crawl
  • AEOllms.txt · schema · answer eligibility
  • PerformanceLCP · CLS · bundle · fonts
  • Monitoringuptime · cert · drift alerts
  • Complianceconsent · WCAG · regional disclosure

Built for builders who ship fast.

Shipped a weekend project

Paste the URL, get the 4 criticals, paste the fix prompt into your agent. Done before the coffee's cold.

Verified before demo

One scan, one green badge. Investors don't have to take your word for it anymore.

Compared two stacks

Same check list, both branches, side-by-side score diff. Pick the winner with evidence.

Re-scanned after deploy

Hooks into CI. A bad CSP header fails the build before the prod URL is even live.

Why builders stay.

Built for developers.

$ claude mcp add vibescan ✓ connected · 26 tools exposed > scan your-app.dev --fix running 127 checks ··· 38.4s ✗ 4 critical · 12 warning > apply patching 3 files ··· done

Repo scanning

yourapp/web Secrets SAST Dependencies

Daily monitoring

  • scan-9a2c passed · 4m ago
  • cert renewed · 2h ago
  • drift +1 critical · yesterday

Exports

report.pdf 142 kb
report.md 8 kb

Domain health

  • TLS certificate
  • DNSSEC
  • Domain expires

Score over time

Questions, answered honestly.

Is it safe to scan a production site?
Yes. Every check is a read-only probe of something already publicly reachable. Nothing is written, submitted, mutated or stored on your side. The scan looks like ordinary traffic.
What is AEO, and why does it have its own pillar?
Answer Engine Optimisation. People increasingly ask ChatGPT, Claude or Perplexity what tool to use rather than typing into a search box. AEO checks whether those systems can reach your content, parse a clear claim out of it, and cite you.
Do I need to install anything or change my code?
No. Paste a URL and the scan runs against the live surface. Connecting your repository or database is optional and only widens what we can see.
What does a "fix prompt" contain?
The finding, the affected file paths or routes, the relevant framework context, and the change to make — written to be pasted directly into a coding agent. Paid plans can open an auto-fix pull request on GitHub instead of handing you text.
Will a bad score be shown publicly?
Never by default. Reports are private to your account. An opt-in public leaderboard is available for builders who want to show a clean score.
How does one-click auto-fix work?
Pick the findings you want fixed, or all of them, and click Auto-fix. AI auto-fix agents write and cross-check the patch, then deliver it as a pull request on your GitHub repo. Nothing is merged without your approval.
Do you offer team plans?
Yes. Team Basic ($19 per seat per month) and Team Advanced ($39 per seat per month), both with a 5-seat minimum sold in blocks of 5, add pooled scans, shared team projects and member invites — Team Advanced also includes SIEM log export. See Pricing for the full comparison.

The scan is free. The fixes aren't.

Your first scans are free (3 a day) with your score and critical count. Paid plans open every finding, one-click auto-fix and continuous monitoring.

Recon

See where you stand. No card, no expiry.

$0
FOREVER
  • 3 scans a day on 1 site
  • All eight pillar scores
  • Critical count and severity split
  • Top 4 findings in full
Reserve my spot
most chosen

Operator

The full report, plus a fix for every line of it.

$29/mo
PER MONTH · CANCEL ANYTIME
  • Every finding, fully detailed
  • GitHub auto-fix pull requests, 20 a month
  • Up to 5 sites, scheduled re-scans
  • Daily monitoring with drift alerts
  • PDF and Markdown exports
Unlock the report

Command

For agencies shipping other people's sites.

$59/mo
PER MONTH · CANCEL ANYTIME
  • Everything in Operator
  • 25 sites, custom schedules, API access
  • Governance policies across every project
  • Priority support and onboarding
  • Client-ready PDF reports
Talk to us

Every plan, one ladder

Annual billing saves 20%. Need more than 25 seats, a DPA or invoicing? Enterprise is a conversation, not a form.

  • New: team plans with seats and invites
  • New: SIEM-ready findings export (NDJSON)
  • New: scan any site from your CI with the REST API
  • New: plan-based project, scan and API-key limits you can see

Find it. Fix it.
In one click.

Launching in four days. Reserve your spot and your first scan runs the moment we open.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.