2 items
Scan your vibe-coded app for exposed databases, leaked keys, and config leaks — before you get burned. VibeScan checks a web app you own or control for the security mistakes that get indie and "vibe-coded" apps hacked before someone else finds them. > With one click it scans the page you're on for: > Publicly readable databases a Supabase project with missing Row-Level Security, or an open Firebase database, that anyone could read. > Leaked API keys & secrets** — Stripe, OpenAI, AWS, Supabase service keys and more, accidentally shipped in your frontend code. > Exposed config reachable `.env`, `.git`, or source-map files. > Missing security headers clickjacking and other hardening gaps. > You get a clear A–F security grade, a plain-English explanation of each issue, and a ready-to-paste prompt you can drop into your AI coding tool (Cursor, Lovable, Claude, v0) to fix it. > > Private by design. The scan runs locally in your browser. We never store your app's data or the secret values we find only the counts and grade, and only if you choose to sign in to save your history. > Built for the people shipping fast: scan your own app, see what's exposed, fix it in minutes.
Jul 18, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.