SiteList review score
Developer-centric positioning provides exceptional technical SEO parity. Entry-point friction and limited middle-of-funnel content hinder adoption.
Reviewed on Jul 20, 2026
fixvibe.app
Domain-verified ownerWhat it does
Security scanner for AI-generated web apps, including DAST, BaaS misconfiguration checks, leaked-secret detection, and AI-ready remediation prompts.
SiteList review score
Developer-centric positioning provides exceptional technical SEO parity. Entry-point friction and limited middle-of-funnel content hinder adoption.
Reviewed on Jul 20, 2026
Verified user rating
—
No verified reviews yet — the evidence locker is empty.
Captured during our latest review on Aug 24, 2026
Monthly and annual billing available. Annual plans offer a 30% discount. Billed monthly. free plan · New accounts start on Free with 3 passive scans per month, 1 project, and 7-day retention.
| Plan | Price | Details |
|---|---|---|
| Hobby | $19 monthly per project | For individual developers and small projects. 1 project · 50 scans / month · 1 API key · 270+ passive checks · 120+ active checks View source |
| Pro | $49 monthly per 5 projects | Most popular plan for shipping fast and staying secure. 5 projects · 200 scans / month · 5 API keys · 160+ GitHub repo checks · Scheduled re-scans (≥3h cadence) View source |
| Unlimited | $149 monthly per 20 projects | Security at scale with live threat detection. 20 projects · Unlimited scans · 20 API keys · Live threat detection · Scheduled re-scans (≥6h cadence) View source |
Passive Scanning
Scanning
Performs 270+ passive checks per scan without active probing.
Active Probing
Scanning
Performs 120+ active security checks on verified domains.
AI Remediation Guidance
Remediation
Provides AI-ready prompts and guidance to fix discovered security holes.
Scheduled Re-scans
Automation
Automated recurring security audits at set intervals.
Outbound Webhooks
Integrations
Signed events for completed scans, failures, and high-severity findings.
AI-Generated App Security
Finding security gaps and leaked secrets in web apps built with AI coding tools.
Continuous DAST
Ongoing dynamic application security testing for production web applications.
Supabase
BaaS
Finds exposed service keys and missing RLS.
Firebase
BaaS
Checks for open Firebase security rules.
GitHub
developer tools
Repository security checks via FixVibe GitHub App.
Cursor
developer tools
Security scanning for apps deployed from Cursor.
Claude Code
developer tools
Security scanning for apps built with Claude Code.
MCP
developer tools
Model Context Protocol access for starting scans.
Yes. New accounts start on Free with 3 passive scans per month, 1 project, 7-day retention, and preview-level findings. Upgrade when you need active probes, full evidence, API/MCP access, repo scans, webhooks, or longer retention.
Yes. Paid plans can send signed outbound events for completed scans, failed scans, high-severity findings, monitor alerts, and queued scheduled runs.
Yes, for verified domains you explicitly authorize from Dashboard → Domains.
Product FAQ information · View source
Fixvibe earns a 83/100 for its developer-centric positioning and exceptional technical SEO parity. However, the platform is currently hindered by significant entry-point friction and a lack of middle-of-funnel content.
83/100: Sophisticated technical core meeting significant structural friction.
No reviews yet. The evidence locker is empty.
Fixvibe has a live access offer — claim a seat and review it honestly.
Reviews are from the SiteList community. Some reviewers received incentives — disclosed in the review, always. The verdict is never for sale.
qsa.sh
A terminal-based service that performs an external port and vulnerability scan of the user's own public IP address using open-source tools (naabu, nmap, nuclei), offering a free live-streaming tier and paid async/deep scan tiers.
vulnwatch.tech
VulnWatch is an automated website vulnerability scanner that uses a proprietary AI Analyst module to transform raw scanner data into prioritized security reports. It provides executive summaries, ranked risks, and actionable remediation plans for web applications, WordPress sites, and network services.
codecanary.org
Client-side browser fingerprinting diagnostic tool that runs live measurements in the browser and displays collected signals for identifiability assessment.
dropstone.io
Self-hosted AI assistant and coding agent that runs on user infrastructure, featuring long-term memory, proactive monitoring, smart home control, phone calls, and code generation across CLI, chat, and SDK surfaces.