passive recon · zero intrusion

Two scores for every site:
security posture & AI authorship

VibeGuard runs a deterministic, passive audit DNS, TLS, redirects, headers, CSP, privacy notice, exposures and CVE mapping then reports a security score and an AI-authorship likelihood index side by side.

try

free · unlimited · no sign-in required

Educational security research only scan only what you are permitted to test.

pipeline

Four passes, two scores

Same input, same evidence, same output every run is fingerprinted.

01 Normalize

Resolve the host, follow redirects, canonicalize the target.

02 Inspect

TLS, DNS records, security headers and CSP directives.

03 Correlate

Reputation, exposed paths and CVE lookups via the NVD.

04 Report

Severity-tagged findings, remediation and PDF export.

deterministicpassive onlyevidence fingerprintedcvss + cve mapped
01 · Security

Security score (0–100)

Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.

0100
02 · Authorship

AI-authorship score (0–100)

Builder fingerprints, generic copy patterns, framework defaults, bundle traces and structural repetition weighed against signals of human craft. Higher means more AI.

0100
coverage

Scan apps built with the tools you already use

VibeGuard fingerprints AI builders, hosting platforms and payment stacks — so vibe-coded apps get the same scrutiny as hand-written ones.

  • LLovable
  • Replit logoReplit
  • EEmergent
  • CCursor
  • AAntigravity
  • Windsurf logoWindsurf
  • Stripe logoStripe
  • Copilot logoCopilot
  • Render logoRender
  • Cloudflare logoCloudflare
  • Netlify logoNetlify
toolbox

Recon tools included in every scan

Passive OSINT plus light, non-intrusive probing no exploitation, no authentication bypass.

Subdomain finder

Certificate transparency logs plus a fixed wordlist, with live checks on admin/staging hosts.

Email & DNS hygiene

SPF, DMARC policy strength, DKIM selectors, DNSSEC, CAA and NS records.

TLS & certificate audit

Issuer, expiry, HTTPS upgrade path and HSTS coverage.

Security headers & CSP

Per-directive CSP parsing plus header drift between pages.

Cookie inspector

Secure, HttpOnly and SameSite flags on every cookie the site sets.

Exposure sweep

Dot-files, backups, source maps, debug routes, HTTP methods and leaked keys.

Pro tools · coming soon
Bulk domain scanScheduled monitoringScanner API accessWhite-label PDFCompliance mapping (OWASP / CWE)Shareable score cards
daily security brief

Today’s software security news, in plain English

Newly published CVEs are technical security notices. We translate the most important ones into who may be affected and what to do next.

Not every alert affects you. Check whether you use the named product before taking action. Source: U.S. National Vulnerability Database.