Does your code have
soul?
We detect fake npm packages, exposed secrets, and bloated slop that Cursor & Claude Code leave behind. Get your copy-paste fix-prompts in seconds.
3 Simple Steps to Audit Your Codebase
Deterministic AST scans, OWASP security verification, and Cursor refactor prompts in under 10 seconds.
1. Input Repository or ZIP
Paste your public GitHub repo URL, sign in to link private repositories in 1 click, or upload a local project .zip archive.
2. Secure Checkout
Pay $10 for a single audit or subscribe to Pro Builder Pass ($39/mo) via encrypted Stripe Checkout.
3. Instant Report & Fixes
Receive evidence-backed security findings, technical debt metrics, copy-paste fix prompts, and launch your app safely.
How The Launch Readiness Audit Engine Works
Deterministic AST static analysis combined with multi-layer AI synthesis evaluates your codebase safely before customer launch.
The 4 Audit Assurance Pillars
1. SAST Security Audit
Scans for OWASP ASVS 4.0 flaws, hardcoded credentials, unsanitized SQL/command sinks, and dangerous dynamic code execution.
2. Supply Chain & CVEs
Inspects package dependencies, unpinned wildcard versions, license compliance, and known package vulnerabilities.
3. Code Quality & Debt
Measures cognitive complexity debt, swallowed exceptions, unhandled promise rejections, and strict type safety.
4. AI Code Vibe Score
Evaluates AI authoring ratio, over-commenting density, structural boilerplate, and non-existent SDK method hallucinations.
Explore an Interactive Sample Report
See how evidence-backed security findings, code quality debt metrics, and copy-paste prompts for Cursor & Windsurf look in a completed report.
Under 10-Second Scans
Fast AST analysis and findings delivered in seconds.
No Untrusted Execution
We never run customer package scripts, build commands, or binaries.
Safe Coding-Agent Prompts
Every finding includes copy-paste prompts for Cursor, Windsurf, Replit, Claude Code & Codex.
Built for the New Era of Coding
Traditional scanners are for legacy code. Vibe Code Detector is the only tool built to understand the specific patterns and pitfalls of agentic AI coding in Cursor, Windsurf, v0, and Claude Code.
Catch Fake Packages & Exposed Keys
- โCatch hallucinated npm packages before supply-chain hijacking
- โPrevent exposed Stripe & OpenAI secret keys in client bundles
- โFlag swallowed promise rejections that freeze app loading
Stop $500 LLM Token Loops
- โDetect infinite retry loops that drain $500+ in LLM tokens
- โPrune bloated try-catch boilerplate and zombie tutorial comments
- โClean up generic variable naming entropy (data / temp)
Copy-Paste Fix Prompts
- โReady-to-use refactor prompts formatted for Cursor & Claude Code
- โOrdered by fix priority for instant one-click refactoring
- โ1 Free Rescan within 14 days to verify all fix prompts pass
Frequently Asked Questions
Everything you need to know about Vibe Code Detector