Security score (0–100)
Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.
VibeGuard runs a deterministic, passive audit DNS, TLS, redirects, headers, CSP, privacy notice, exposures and CVE mapping then reports a security score and an AI-authorship likelihood index side by side.
Same input, same evidence, same output every run is fingerprinted.
Resolve the host, follow redirects, canonicalize the target.
TLS, DNS records, security headers and CSP directives.
Reputation, exposed paths and CVE lookups via the NVD.
Severity-tagged findings, remediation and PDF export.
Weighted, auditable sub-scores across domain trust, TLS, redirects, headers, CSP, reputation, exposures, privacy notice, frontend hygiene and attack surface. Higher is safer.
Builder fingerprints, generic copy patterns, framework defaults, bundle traces and structural repetition weighed against signals of human craft. Higher means more AI.
VibeGuard fingerprints AI builders, hosting platforms and payment stacks — so vibe-coded apps get the same scrutiny as hand-written ones.
Passive OSINT plus light, non-intrusive probing no exploitation, no authentication bypass.
Certificate transparency logs plus a fixed wordlist, with live checks on admin/staging hosts.
SPF, DMARC policy strength, DKIM selectors, DNSSEC, CAA and NS records.
Issuer, expiry, HTTPS upgrade path and HSTS coverage.
Per-directive CSP parsing plus header drift between pages.
Secure, HttpOnly and SameSite flags on every cookie the site sets.
Dot-files, backups, source maps, debug routes, HTTP methods and leaked keys.
Newly published CVEs are technical security notices. We translate the most important ones into who may be affected and what to do next.
Not every alert affects you. Check whether you use the named product before taking action. Source: U.S. National Vulnerability Database.