Security scans for vibe-coded apps

YoushippeditwithAI.Now see what it leaked.

Paste your URL. In minutes you get every missing header, open path, and leaked key name ranked from low to critical, each with a fix prompt your AI can run.

  • No account to start
  • Passive, read-only crawl
  • Results in minutes
See a real sample report
Passive checks on every scan
40+
Free scan, no card
1
Lowest price per full scan
$1.99
Expiry on credits. Ever.
0

How it works

AI wrote the code. Nobody read the headers.

FixPrompt does the boring security pass your agent skipped, in about the time it takes to refill your coffee.

  1. Paste your URL

    Any public http(s) app. Localhost, private IPs, and cloud metadata endpoints are blocked.

  2. We look, we don't touch

    A real browser loads your pages and JavaScript bundles, reads headers, cookies, and public paths. One normal request each. No payloads.

  3. Hand the fix to your AI

    Copy one prompt into Claude Code, Codex, Cursor, or any LLM. It fixes every issue in priority order and tells you how to verify.

The report

The scary stuff is behind the lock.

Your free scan shows how many medium, high, and critical issues exist and what they're called. Unlock to get the evidence and the exact fix.

  • Low findings open free after signup
  • Medium → critical unlock for $9 per report, or use a credit for a full scan
  • One prompt fixes everything — paste it into any AI coding agent
LOW · OPEN

Missing X-Content-Type-Options

Add X-Content-Type-Options: nosniff at the edge or in middleware to stop MIME sniffing.

› Fix prompt: add nosniff to every response in middleware.ts…
CRITICAL · LOCKED

Client bundle references a privileged key name

HIGH · LOCKED

Content-Security-Policy not set

Compare

Cheaper than a pentest. Faster than a checklist.

Where FixPrompt fits next to the other ways to answer “is my app leaking?”

FixPrompt
Manual pentest
Generic scanners
Ship & hope

Price

Free first scan, then from $1.99
Thousands per engagement
Often a monthly plan
$0 until it isn't

Time to a report

Minutes
Weeks
Minutes
—

Knows AI-built stacks

Supabase / Firebase hosts, key names in client bundles

Fix prompt per finding

One prompt for Claude Code, Codex, Cursor, or any LLM

Ranked low → critical

Passive, no exploit payloads

No subscription

Deep manual logic testing

We're honest: for that, hire a human

Pricing

Pay per scan. Keep the credits forever.

Your first scan is free. After that, packs make each full, unlocked scan cheaper than a coffee.

Tip: scan once, fix, then scan again to prove it's gone.

10 scans

Best fit · Builder

$3.27per full scan

64% less than a $9 report unlock

Starter

$20

5 full scans · $4.00/scan

One app, scan before and after fixing

  • Every severity unlocked, low → critical
  • AI fix prompt per finding + one fix-everything prompt
  • Re-scan after fixing to verify
  • Credits never expire
Get 5 scans
Recommended

Builder

Save 18%

$49

15 full scans · $3.27/scan

Scan every deploy of a couple of apps

  • Every severity unlocked, low → critical
  • AI fix prompt per finding + one fix-everything prompt
  • Re-scan after fixing to verify
  • Credits never expire
Get 15 scans

Studio

Save 38%

$99

40 full scans · $2.48/scan

Agencies and side-project collectors

  • Every severity unlocked, low → critical
  • AI fix prompt per finding + one fix-everything prompt
  • Re-scan after fixing to verify
  • Credits never expire
Get 40 scans

Fleet

Save 50%

$199

100 full scans · $1.99/scan

Teams shipping many apps every week

  • Every severity unlocked, low → critical
  • AI fix prompt per finding + one fix-everything prompt
  • Re-scan after fixing to verify
  • Credits never expire
Get 100 scans

Only need one report? Unlock the scan you already ran for $9, straight from the report page.

One-time payments · no subscription · secure checkout

FAQ

Straight answers

Scope, the free scan, and exactly what you're paying for.

What does the free scan include?

One free scan per account. Low-severity findings are unlocked, with the explanation and a fix prompt. Medium and above stay locked until you buy credits or unlock that report for $9.

Is this a penetration test?

No. FixPrompt passively reads what any visitor's browser receives — pages, JavaScript bundles, headers, cookies, common public paths — plus public DNS records. It does not send exploit payloads or try credentials, and secret values it spots are never stored.

Which URLs can I scan?

Public http(s) URLs for apps you are authorized to assess. Localhost, private networks, and cloud metadata endpoints are blocked.

Do credits expire?

No. Packs are one-time purchases and credits never expire. You can also unlock a single report without buying a pack.

Which AI can use the fix prompt?

Any of them. The report gives you one fix-everything prompt (plus one per finding) written for any coding agent with access to your repo: Claude Code, Codex, Cursor, GitHub Copilot, Windsurf, Gemini CLI, Cline, Aider — or a chat model via OpenRouter, DeepSeek, or GLM. It knows your stack, says where to change what, and how to verify each fix.

$9 unlock or a credit pack — which should I buy?

The $9 unlock opens every finding on a report you already ran. A pack gives you full scans with everything unlocked from the start — ideal for scanning, fixing, and scanning again to confirm the fix. From 3 scans up, a pack is cheaper per report.

What happens right after I pay?

Checkout is secure and one-time. A $9 unlock opens the report as soon as your payment is confirmed. Pack credits land in your balance on the same confirmation and are spent one per new scan.

Find it before someone else does.

Paste a public URL. No account needed to start. Your first report is free.

Scan my app now