VIBECHECK

Pricing

Free to look. $29 a month to keep watching.

The free scan is genuinely useful on its own. The paid plan is for the checks that require proving you own the app, plus monitoring that catches the leak the day it ships — not months later.

Free scan

$0 · no signup

The passive engine — reads only what any visitor can already see.

  • Scan any URL — no account needed
  • Exposed API keys & secrets (incl. Supabase service_role)
  • Exposed .env and reachable sensitive files
  • Security headers, TLS, and cookie flags
  • Leaked source maps
  • Plain-English report, sorted worst-first
Scan my app — free

Pro

$29 / month · per app

The active engine on apps you own — plus monitoring and alerts.

  • Everything in the free scan, plus:
  • Deep checks on domains you own & verify
  • Missing authorization on your endpoints
  • Supabase Row-Level-Security gaps
  • CORS-with-credentials & storage-bucket exposure
  • Dependency CVEs
  • Continuous monitoring + re-scan on every deploy
  • Alerts (email / Slack / Telegram) on new or worse findings
  • Saved history, trends, and multiple apps
Start monitoring — $29/mo

Do I need to pay to try it?

No. The free scan works on any URL with no account. You only pay when you want the deep checks, monitoring, and alerts on an app you own.

Why do the deep checks need verification?

Active checks look for things like missing authorization and open storage buckets. We run them only after you publish a DNS record proving you control the domain, so the deep scan is only ever pointed at your own app.

Can I cancel any time?

Yes — month to month, cancel whenever, and there's a 14-day money-back window on the latest charge. See the Refund & Cancellation Policy.

How is payment handled?

Securely through Paddle, our merchant of record. No card details ever touch our servers.