Your vibe-coded app has a security hole.
Find it before someone else does.
SetScanTarget scans your live URL or GitHub repo for exposed API keys, unauthenticated admin panels, and auth vulnerabilities — in under 2 minutes. No security degree required.
"I paid $8,000 for my app. Is it safe?"
You hired a developer online. It looks great and it's ready to launch. But you have no idea what's inside the code — and your users are about to trust you with their data.
"The freelancer said it was fine. It wasn't."
API keys hardcoded in public JavaScript. Every browser that visited the site downloaded them. The developer was long gone. The damage was real.
"I launched. Three days later someone found the admin panel."
No login required. The route wasn't in the nav — but it was in the code, and it was public. AI-generated apps skip the things experienced developers catch by instinct.
How it works
Paste your URL or repo
Works on live sites and public GitHub repos. No credentials needed to get started.
We crawl with a real browser
Playwright finds what a real attacker would see: JS bundles, network calls, exposed endpoints.
Get your risk grade + report
A–F score, plain-English findings, shareable link. Ready in under 2 minutes.
What a finding looks like
Found in: /_next/static/chunks/main.abc123.js
The key was committed in a .env file and bundled into the public JavaScript. Anyone who visits this page has this key. Rotate it immediately.
DevTools → Sources → Search "ACCESS_KEY"From developers who've been there
“Ran it on a client project before handoff. Found a hardcoded Stripe secret key in the JavaScript bundle. Caught it before the client — and before their security audit.”
Dan K.
Freelance full-stack developer
“I was about to demo to investors. Scanned the staging URL the night before. Found an admin panel with no auth. Would have been a very embarrassing way to lose that deal.”
Sofia M.
Founder, Buildr.so
“I use it on every PR before merging to main. It's the only security check I've found that doesn't require a security degree to understand the output.”
Arjun P.
Solo developer
Simple pricing
Start free. Upgrade when you need more.
Free
No credit card
- Web scan
- A–F risk grade
- PR Review (3/day)
- 7-day history
- 20 pages/scan
Pro
Per seat
- Everything in Free
- Artifact / repo scan
- Unlimited PR Review
- 1-year history
- 100 pages/scan
- Export JSON
- Abuse protection
Team
Up to 10 seats
- Everything in Pro
- Active probes
- Team seats (10)
- Scheduled scans
- Slack alerts
- PDF export
- API key access
Ready to find what's hiding in your app?
Takes 2 minutes. No account needed to start.
Scan My App Free →