Headers, TLS and DNS
Security headers checked against a prioritised checklist, plus HTTPS, certificates, SPF and DMARC.
Find out whether strangers can read or change your customers' data. In plain language, with the evidence and a fix you can paste into your AI builder.
Free passive scan, no signup. Active scans only run after you confirm you own the site.
profiles is readable without logging inExpected: owner only · a stranger read 214 rows · evidence attachedorders could not be testedPolicy needs a signed-in user · define an access modelEnable row level security on profiles and add a policy so users can only select their own row…
Built for apps made with
Plain-text names, no endorsement implied. The one-prompt connector is verified on Lovable; support on other builders varies.
Paste a live URL. No account. The passive scan reads what your site shows the world: headers, TLS, DNS, files, the JavaScript bundle and your Supabase setup. You get a plain-language report, a PDF and fix prompts.
Start a free scanPassive scan, plain-language report, PDF export, "Fix it with AI" prompts.
Thorough active scans (nuclei, nmap, ZAP) run only on sites you confirm you own.
Dashboard with connected builders, checks about every 30 minutes and alerts.
Paid plans aren't set yet. The URL scan is free.
Security headers checked against a prioritised checklist, plus HTTPS, certificates, SPF and DMARC.
/assets/index-4f2a.js const supabase = createClient( "https://xyzcompany.supabase.co", "eyJhbGciOiJIUzI1…" // anon key ) /.env → 200 OK, file is public
Finds secrets in your client bundle and publicly reachable files (a public Supabase anon key is normal; your access policies decide what it can read), plus known-vulnerable JavaScript libraries, trackers and AI-crawler access.
Every finding says what it means for your users. Copy a prompt into your builder; you stay in control of the change.
Not a guess from a checklist. SafetyVibe tests access against the rules you define and reports one of three verdicts, each with the evidence.
The tested reads and writes matched your rules. The verdict covers the tested scope, nothing more.
A test demonstrated access a stranger shouldn't have. You get the request that proved it, and the fix.
Something blocked the test. The report says what, so a missing result never looks like a pass.
{
"mcpServers": {
"safetyvibe": {
"url": "https://mcp.safetyvibe.eu/mcp"
}
}
}
Point Claude Code, Cursor or another MCP client at our server. Your agent can define access rules, run the tests and scan sites.
$ bun add safetyvibe-connect $ bunx safetyvibe-connect setup --claim-token •••••• ✓ 678 packages reported · Supabase project linked ✓ Connected. Checks re-run after every install.
Your builder's AI installs the safetyvibe-connect npm package. It sends the dependency list and, if used, your public Supabase URL and anon key, never source code or secrets. Dependencies are checked against OSV.dev.
Connect builders from a catalog of 30, get checks about every 30 minutes and an alert when something changes. Currently in testing.
See your findings in plain language, and what to fix next.
Scan your site free