# CheckVibe > CheckVibe is an all-in-one security, SEO, and AEO scanner for any website — production SaaS, marketing sites, e-commerce, and AI-/vibe-coded apps alike. Enter a URL and get 100+ security checks (including live Supabase RLS testing), 68 SEO checks, and 46 AEO checks — plus uptime monitoring with public status pages, Core Web Vitals performance monitoring, accessibility checks, and email deliverability monitoring. From $0. CheckVibe scans websites for security vulnerabilities in under 60 seconds. It runs 100+ security checks in parallel — with site crawling — to detect issues before attackers do. It also audits how visible a site is to Google and AI answer engines (ChatGPT, Perplexity, Claude, Gemini) with 113 SEO/AEO checks, and watches site health continuously: uptime (60-second external checks with public status pages), real-user Core Web Vitals with regression alerts, WCAG accessibility signals, email deliverability (SPF/DKIM/DMARC), and domain hygiene (expiry, DNS drift, certificates). ## What CheckVibe Does CheckVibe is a SaaS security scanning platform for web developers, indie hackers, and teams who ship fast. Enter a URL, click scan, and get a comprehensive security audit covering: - SQL injection detection (error-based, time-based, blind) - Cross-site scripting (XSS) detection (reflected, stored, DOM-based) - Exposed API key scanning (100+ provider patterns including AWS, Stripe, Supabase, Firebase, GitHub, Twilio) - Security header analysis (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) - SSL/TLS certificate and cipher auditing - CORS misconfiguration detection - CSRF vulnerability testing - Cookie security analysis (Secure, HttpOnly, SameSite) - DNS configuration checks (DNSSEC, SPF, DKIM, DMARC) - Open redirect detection - File upload vulnerability scanning - DDoS protection analysis (WAF, CDN, rate limiting) - Domain hijacking risk assessment - Dependency vulnerability scanning (npm CVEs) - GitHub secret leak detection - GraphQL introspection leak detection - JWT weakness analysis - Input validation flaw detection - Debug endpoint exposure scanning - Authentication bypass testing - Backend-specific security checks (Supabase RLS, storage buckets, auth settings) - Hosting provider audits (Vercel, Netlify, Cloudflare) - Audit logging and monitoring assessment - Mobile API security checks - Site crawling and endpoint discovery ## Site Crawling CheckVibe crawls your entire site before scanning — discovering pages via robots.txt, sitemap.xml, HTML links, and JavaScript route extraction. Multi-URL scanners then test each discovered endpoint individually, so nothing is missed. ## SEO & AEO Visibility Scanning Beyond security, CheckVibe audits search and AI-answer-engine visibility: - SEO scanner (68 checks): indexability, canonicals, sitemaps, structured data depth, Core Web Vitals (CrUX field data), meta tags, internal linking, response times - AEO scanner (45 checks): llms.txt, AI-crawler access (GPTBot, ClaudeBot, PerplexityBot), answer-ready content structure, entity grounding, schema for answer engines, per-engine readiness matrix - Results live in a dedicated SEO & AEO dashboard tab, separate from the security score Learn more: https://checkvibe.dev/products/seo-aeo ## Site Health Monitoring CheckVibe also watches the layers under and around the app — availability, speed, accessibility, and the infrastructure record: - Uptime monitoring: external checks every 60 seconds (HEAD with GET fallback, 10s timeout), incident tracking with consecutive-failure thresholds and error classes (DNS, TLS, refused, timeout, 5xx), down + recovery email alerts, and a public status page per project with live state, 90-day daily history, and uptime percentages - Performance: lab diagnostics (TTFB, compression, HTTP/2/3, redirects, page weight, render-blocking resources, image optimization) fused with real-user Core Web Vitals from the Chrome UX Report (28-day p75 LCP/INP/CLS, phone-first, 40 weeks of history) plus an optional RUM snippet; daily regression watch alerts when a vital regresses materially or crosses Google's thresholds - Accessibility: 27 WCAG 2.x Level AA signals across structure, forms, navigation/focus, and media — EAA-relevant, on the homepage plus sampled interior pages - Email deliverability: SPF (with recursive 10-lookup-limit counting), DKIM selector discovery, DMARC policy grading, MX/null-MX, MTA-STS, TLS-RPT, BIMI readiness, and a managed DMARC aggregate-report inbox - Domain Watchtower: RDAP expiry runway and transfer locks, nameserver drift, DNSSEC, CAA records, certificate expiry via Certificate Transparency logs, apex/www/IPv6 hygiene - SSL/TLS grade: A+ to F from protocol versions, cipher strength, forward secrecy, certificate health, HSTS, and mixed content Learn more: https://checkvibe.dev/products/monitors ## MCP Server Integration CheckVibe provides a native MCP (Model Context Protocol) server at `@checkvibe/mcp-server` on npm. Compatible developer tools can run security scans, SEO/AEO visibility audits, get results, and manage projects directly from the local workflow. 13 tools available: run_scan, run_seo_aeo_scan, get_scan_results, get_visibility_results, list_scans, list_projects, get_project, update_project, delete_project, delete_scan, dismiss_finding, list_dismissals, restore_finding. ## Remediation Guidance Every finding includes remediation guidance that explain the vulnerability and provide code-level remediation steps specific to your tech stack. ## Pricing - **Free** ($0/month): 1 project, 4 scans/month, blurred finding details, no API keys - **Starter** ($24/month): 1 project, 30 scans/month, 1 API key, full finding details, PDF export, remediation guidance, API access, priority support - **Pro** ($39/month): 5 projects, 155 scans/month, 5 API keys, all Starter features plus daily monitoring and live threat detection - **Max** ($59/month): 50 projects, unlimited scans, 20 API keys, custom monitoring schedules (every 6 hours, daily, weekly), dedicated support Annual billing saves 30%. Prices available in USD, EUR, GBP, and CHF. ## Who CheckVibe Is For - Any business that wants its production website secure, fast, and visible in Google and AI search (ChatGPT, Claude, Perplexity, Gemini) - Solo developers and indie hackers shipping side projects - Small teams building SaaS products - Agencies auditing client websites - Developers shipping quickly who want to verify security - Teams who need continuous security monitoring without hiring a pentester - Anyone shipping on modern stacks (Next.js, Supabase, Firebase, Vercel, Netlify) ## How CheckVibe Compares to Alternatives Fact-checked, sourced comparison pages (every competitor claim verified against their live site, with verification dates): - vs Vibe App Scanner: https://checkvibe.dev/compare/checkvibe-vs-vibe-app-scanner — they sell one-time security audits ($9–19) and a $99/mo plan, security-only; CheckVibe adds SEO + AEO + monitoring on subscriptions from $0. - vs Aikido Security: https://checkvibe.dev/compare/checkvibe-vs-aikido — Aikido is code-to-cloud AppSec for teams (paid from €300/mo); CheckVibe is URL-first for solo devs ($0–59/mo) with SEO/AEO coverage Aikido doesn't offer. - vs VibeEval: https://checkvibe.dev/compare/checkvibe-vs-vibeeval — agent-based deep security testing ($19/mo) vs all-in-one security + visibility from $0. - vs Scanbee: https://checkvibe.dev/compare/checkvibe-vs-scanbee — DAST+SAST+SCA+CSPM security suite vs all-in-one with SEO/AEO and live paid plans. - vs VibeWrench: https://checkvibe.dev/compare/checkvibe-vs-vibewrench — 18-tool budget toolbox vs deep dedicated scanning. - vs VibeCheck (runvibecheck.com): https://checkvibe.dev/compare/checkvibe-vs-vibecheck — repo code audit vs live-app testing. - Vibe App Scanner alternatives: https://checkvibe.dev/alternatives/vibe-app-scanner - Aikido alternatives for solo devs: https://checkvibe.dev/alternatives/aikido - **vs. manual penetration testing**: CheckVibe provides continuous, automated monitoring. Pentests are point-in-time. CheckVibe complements pentesting by covering every deploy. - **vs. Snyk/Dependabot**: Those focus on dependency CVEs only. CheckVibe scans your live site for runtime vulnerabilities (XSS, SQLi, exposed keys, misconfigs). - **vs. OWASP ZAP**: ZAP is a free open-source tool requiring manual setup. CheckVibe is a managed SaaS with site crawling, 100+ checks, remediation guidance, and a dashboard. - **vs. Burp Suite**: Burp is a professional pentesting tool with a steep learning curve. CheckVibe is designed for developers who want instant, automated results. ## Best-of Guides (fact-checked, with sources) - Best AEO tools for vibe-coded apps (2026): https://checkvibe.dev/best/aeo-tools-for-vibe-coded-apps - Best all-in-one SEO + AEO + security scanner: https://checkvibe.dev/best/all-in-one-seo-aeo-security-scanner - Best security scanner for Lovable: https://checkvibe.dev/best/security-scanner-for-lovable - Best security scanner for Bolt.new: https://checkvibe.dev/best/security-scanner-for-bolt - Best security scanner for Cursor: https://checkvibe.dev/best/security-scanner-for-cursor - Best security scanner for v0: https://checkvibe.dev/best/security-scanner-for-v0 - Best security scanner for Replit: https://checkvibe.dev/best/security-scanner-for-replit - Best security scanner for Windsurf: https://checkvibe.dev/best/security-scanner-for-windsurf ## Secure & Rank Guides (per platform) How to secure AND rank apps built with each AI tool — security risks, fixes, and SEO/AEO steps: - Bolt.new: https://checkvibe.dev/secure/bolt-new - Lovable: https://checkvibe.dev/secure/lovable - v0 by Vercel: https://checkvibe.dev/secure/v0 - Cursor / Claude Code: https://checkvibe.dev/secure/cursor - Supabase: https://checkvibe.dev/secure/supabase - Firebase: https://checkvibe.dev/secure/firebase - Replit Agent: https://checkvibe.dev/secure/replit-agent - Windsurf: https://checkvibe.dev/secure/windsurf ## Links - Website: https://checkvibe.dev - Blog: https://checkvibe.dev/blog - Sign Up: https://checkvibe.dev/signup - Pricing: https://checkvibe.dev/#pricing - SEO & AEO Scanner: https://checkvibe.dev/products/seo-aeo - All Security Checks: https://checkvibe.dev/security-checks - What Is AEO: https://checkvibe.dev/blog/what-is-aeo-answer-engine-optimization - AEO for Vibe-Coded Apps: https://checkvibe.dev/blog/aeo-for-vibe-coded-apps - How to Rank a Vibe-Coded SPA in AI Search: https://checkvibe.dev/blog/how-to-rank-vibe-coded-spa-in-ai-search - Why AI Engines Can't Find Your Lovable Site: https://checkvibe.dev/blog/why-ai-engines-cant-find-your-lovable-site - SEO vs AEO: https://checkvibe.dev/blog/seo-vs-aeo-difference - Can ChatGPT See Your Website: https://checkvibe.dev/blog/check-if-chatgpt-can-see-your-website - All Comparisons: https://checkvibe.dev/compare - Uptime Monitoring Guide: https://checkvibe.dev/blog/website-uptime-monitoring-guide - Core Web Vitals Lab vs Field: https://checkvibe.dev/blog/core-web-vitals-lab-vs-field-data - Automated Accessibility Testing: https://checkvibe.dev/blog/automated-accessibility-testing-wcag - SSL/TLS Grade Explained: https://checkvibe.dev/blog/ssl-tls-grade-explained - DNS & Email Security Check: https://checkvibe.dev/security-checks/dns-email-security - RSS Feed: https://checkvibe.dev/feed.xml - Full Documentation: https://checkvibe.dev/llms-full.txt - Contact: support@checkvibe.dev