SetScanTargetFree
25% of AI-generated code ships with a security flaw

Your vibe-coded app has a security hole. Find it before someone else does.

SetScanTarget scans your live URL or GitHub repo for exposed API keys, unauthenticated admin panels, and auth vulnerabilities — in under 2 minutes. No security degree required.

Scan My App Free →No account needed · 3 free scans to start

"I paid $8,000 for my app. Is it safe?"

You hired a developer online. It looks great and it's ready to launch. But you have no idea what's inside the code — and your users are about to trust you with their data.

"The freelancer said it was fine. It wasn't."

API keys hardcoded in public JavaScript. Every browser that visited the site downloaded them. The developer was long gone. The damage was real.

"I launched. Three days later someone found the admin panel."

No login required. The route wasn't in the nav — but it was in the code, and it was public. AI-generated apps skip the things experienced developers catch by instinct.

How it works

01

Paste your URL or repo

Works on live sites and public GitHub repos. No credentials needed to get started.

02

We crawl with a real browser

Playwright finds what a real attacker would see: JS bundles, network calls, exposed endpoints.

03

Get your risk grade + report

A–F score, plain-English findings, shareable link. Ready in under 2 minutes.

What a finding looks like

HighExposed API Key in JavaScript Bundle
AWS_SECRET_ACCESS_KEY=AKIAIOSFODNN7EXAMPLE…
Found in: /_next/static/chunks/main.abc123.js

The key was committed in a .env file and bundled into the public JavaScript. Anyone who visits this page has this key. Rotate it immediately.

Attack path:DevTools → Sources → Search "ACCESS_KEY"

From developers who've been there

Ran it on a client project before handoff. Found a hardcoded Stripe secret key in the JavaScript bundle. Caught it before the client — and before their security audit.

Dan K.

Freelance full-stack developer

I was about to demo to investors. Scanned the staging URL the night before. Found an admin panel with no auth. Would have been a very embarrassing way to lose that deal.

Sofia M.

Founder, Buildr.so

I use it on every PR before merging to main. It's the only security check I've found that doesn't require a security degree to understand the output.

Arjun P.

Solo developer

Simple pricing

Start free. Upgrade when you need more.

Free

$0

No credit card

  • Web scan
  • A–F risk grade
  • PR Review (3/day)
  • 7-day history
  • 20 pages/scan
Start scanning →
Most popular

Pro

$19/mo

Per seat

  • Everything in Free
  • Artifact / repo scan
  • Unlimited PR Review
  • 1-year history
  • 100 pages/scan
  • Export JSON
  • Abuse protection
See Pro plan →

Team

$49/mo

Up to 10 seats

  • Everything in Pro
  • Active probes
  • Team seats (10)
  • Scheduled scans
  • Slack alerts
  • PDF export
  • API key access
See Team plan →

Ready to find what's hiding in your app?

Takes 2 minutes. No account needed to start.

Scan My App Free →