14,203 exposed secrets found in vibe-coded apps this month
Paste your app’s URL. In 60 seconds we check it for the classic vibe-code sins — leaked keys, open databases, missing auth — and hand you a public, shareable grade. Free. Brutal. For your own good.
Read-only checks. No exploitation, no data touched. Your grade is private until you choose to flex it.
Sample report
Supabase service-role key shipped in the client bundleAnyone with DevTools owns your entire database. Yes, all of it.
API routes accept requests with no auth check“I’ll add auth later” — you, 6 weeks ago.
OpenAI key proxied but no rate limitCongrats on sponsoring a stranger’s startup’s inference bill.
HTTPS everywhereThe bar is on the floor, but you cleared it.
Every scan produces a graded report card with a stamp, a roast, and a fix-it list — engineered to be screenshotted.
Fail publicly, fix quickly. Each finding links to a copy-paste fix, so the walk of shame ends in a passing grade. Re-scan free, upgrade your stamp, post the glow-up.
The leaderboard
| App | Findings | Grade | Status |
|---|---|---|---|
| althunt.io | 1 medium | B+ | 😇 insufferable about it |
| lenguapress.com | 1 medium · 2 low | B+ | 😇 insufferable about it |
| www.coramap.com | 1 medium · 1 low | B+ | 😇 insufferable about it |
| lingsy.io | 1 medium · 1 low | B+ | 😇 insufferable about it |
| www.vibecodedroast.com | 1 medium · 1 low | B+ | 😇 insufferable about it |
Apps appear here only when their builders opt in. The real flex is climbing from F to A in public. See the full leaderboard →
How it works
We run read-only checks for exposed keys, open databases, missing auth, and the other greatest hits of weekend engineering.
A graded report card with severity stamps, plain-English explanations, and one joke per finding. Screenshot-ready by design.
Every finding ships with a copy-paste fix. Re-scan, upgrade your grade, and post the before/after. That’s the loop.