VibeScan — App Exposure Scanner
Scan your vibe-coded app for exposed databases, leaked keys, and config leaks — before you get burned.
Upgrade to view the full paid extension report
Public basics remain visible. Paid access adds payment clues, related extensions, and more review detail.
7-day user preview
Free accounts only see a short preview for paid extensions.
User Growth Over Time
7-day rating trend preview
Preview mode shows collected rating snapshots from the latest 7-day window.
Daily, weekly, and monthly growth
Compare 1-day, 7-day, and 30-day net growth and growth rate.
Version, languages, and crawl freshness
Review publication date, version, supported languages, and crawl timestamps.
Product summary
Review the store description, core capabilities, and common use cases.
VibeScan checks a web app you own or control for the security mistakes that get indie and "vibe-coded" apps hacked before someone else finds them.
> With one click it scans the page you're on for:
> Publicly readable databases a Supabase project with missing Row-Level Security, or an open Firebase database, that anyone could read.
> Leaked API keys & secrets** — Stripe, OpenAI, AWS, Supabase service keys and more, accidentally shipped in your frontend code.
> Exposed config reachable `.env`, `.git`, or source-map files.
> Missing security headers clickjacking and other hardening gaps.
Recent review snapshot
Inspect the latest comments and rating distribution.
Store average score: --. Synced review text can be locked or unavailable even when the store shows a public score.
More reviews require paid access
The rating summary remains visible. Paid access includes more synced review text.
Similar and related extensions
Review related products from the Chrome Web Store detail page.
Related paid products require paid access
Upgrade to compare similar products and adjacent extensions.