Why CheckVibe?
- Made for AI-built appsTargets the mistakes vibe-coding tools make
- Supabase RLS checksFinds databases anyone can read or write
- Secrets and dependenciesCatches leaked keys and risky packages
- Fix promptsPaste-ready instructions for Lovable, Cursor or Bolt
- MCP serverRun scans from Claude or Cursor
- Agency featuresWhite-label reports and client portal on Max
Overview
CheckVibe is a different kind of tool from the builders in this category. It does not write your app; it checks it. Point it at a live URL or a GitHub repo and it runs over 100 checks, including the OWASP Top 10, secrets exposure, dependency risks and Supabase row-level security.
The company is young and does not name its team publicly. Its site says it is backed by Venture Kick.
Pricing
CheckVibe starts with a free option at $0. The first paid tier, Starter, costs £24/mo (£17 billed yearly).
| Plan | Price | What you get |
|---|---|---|
| Free | $0 | 4 scans a month, 1 project, severity overview |
| Starter | £24/mo (£17 billed yearly) | 10 scans, AI fix prompts, PDF export, API, MCP |
| Pro | £49/mo (£34 billed yearly) | 250 scans, 5 projects, daily monitoring, alerts |
| Max | £99/mo (£69 billed yearly) | Unlimited scans, 25 projects, white-label reports |
| Team Basic | £25/seat/mo (5 seats min.) | AutoFix PRs, cloud posture, container scanning |
| Team Advanced | £50/seat/mo (5 seats min.) | SSO, CI merge gate, custom rules, Jira and Linear |
Try CheckVibe for yourself
Free plan with 4 scans a month.
Key features
- Live app scan: Over 100 checks on your running site.
- Repo and PR review: Scans your GitHub code and pull requests.
- Supabase RLS: Flags tables without proper access rules.
- AutoFix PRs: Opens pull requests with fixes on team plans.
- Monitoring: Uptime, TLS, DNS and domain checks every 60 seconds on higher plans.
- MCP server: Use CheckVibe inside Claude or Cursor.
What you can build
CheckVibe works with any live URL or GitHub repository. It outputs findings, severity ratings, fix prompts, pull requests and reports.
Pros and cons
What we like
- Built for common vibe-coding security failures
- Useful free tier
- Fix prompts go straight back into your AI tool
- White-label options for agencies
What to watch
- Young company with little public information
- Scan limits on lower plans
- Automated scans do not replace a penetration test
- Prices in GBP only
Who it is for
Use CheckVibe alongside any builder on this list before you launch, and whenever you add login, payments or user data.
Ready to start with CheckVibe?
CheckVibe scans apps built with Lovable, Bolt, Cursor and other AI tools for the security holes they often ship with: exposed keys, open databases and missing access rules.
Alternatives to CheckVibe
Compare all vibe coding tools →
FAQ
Why do AI-built apps need a security scan?
AI builders often leave database access open or expose keys in the front end. A scan catches these before users or attackers do.
Is CheckVibe free?
Yes, with 4 scans a month on one project.
Does it fix problems for me?
It gives fix prompts on all paid plans and can open fix pull requests on team plans.
Is it a replacement for a pentest?
No. It is a strong first line of defense, not a full manual audit.
Disclosure: we may earn a commission if you sign up through links on this page, at no extra cost to you. Scores follow our published method and are not for sale. Prices and features change often; check the vendor's site before you buy.