Skip to content
SiteList

Fixvibe

fixvibe.app

Domain-verified owner

What it does

Security scanner for AI-generated web apps, including DAST, BaaS misconfiguration checks, leaked-secret detection, and AI-ready remediation prompts.

Two ratings

SiteList review score

Developer-centric positioning provides exceptional technical SEO parity. Entry-point friction and limited middle-of-funnel content hinder adoption.

Reviewed on Jul 20, 2026

Why this score? →

Screenshots

Captured during our latest review on Aug 24, 2026

Home · fixvibe.app
Checks · www.fixvibe.app
Pricing · www.fixvibe.app
Research · www.fixvibe.app

Pricing details

Monthly and annual billing available. Annual plans offer a 30% discount. Billed monthly. free plan · New accounts start on Free with 3 passive scans per month, 1 project, and 7-day retention.

PlanPriceDetails
Hobby$19 monthly per project

For individual developers and small projects. 1 project · 50 scans / month · 1 API key · 270+ passive checks · 120+ active checks

View source
Pro$49 monthly per 5 projects

Most popular plan for shipping fast and staying secure. 5 projects · 200 scans / month · 5 API keys · 160+ GitHub repo checks · Scheduled re-scans (≥3h cadence)

View source
Unlimited$149 monthly per 20 projects

Security at scale with live threat detection. 20 projects · Unlimited scans · 20 API keys · Live threat detection · Scheduled re-scans (≥6h cadence)

View source
View source

Key features

  • Passive Scanning

    Scanning

    Performs 270+ passive checks per scan without active probing.

  • Active Probing

    Scanning

    Performs 120+ active security checks on verified domains.

  • AI Remediation Guidance

    Remediation

    Provides AI-ready prompts and guidance to fix discovered security holes.

  • Scheduled Re-scans

    Automation

    Automated recurring security audits at set intervals.

  • Outbound Webhooks

    Integrations

    Signed events for completed scans, failures, and high-severity findings.

View source

Who it’s for

  • AI-Generated App Security

    Finding security gaps and leaked secrets in web apps built with AI coding tools.

  • Continuous DAST

    Ongoing dynamic application security testing for production web applications.

View source

Integrations

  • Supabase

    BaaS

    Finds exposed service keys and missing RLS.

  • Firebase

    BaaS

    Checks for open Firebase security rules.

  • GitHub

    developer tools

    Repository security checks via FixVibe GitHub App.

  • Cursor

    developer tools

    Security scanning for apps deployed from Cursor.

  • Claude Code

    developer tools

    Security scanning for apps built with Claude Code.

  • MCP

    developer tools

    Model Context Protocol access for starting scans.

View source

Buyer questions

Questions buyers actually ask

Is there a Free plan?

Yes. New accounts start on Free with 3 passive scans per month, 1 project, 7-day retention, and preview-level findings. Upgrade when you need active probes, full evidence, API/MCP access, repo scans, webhooks, or longer retention.

View source

Are outbound webhooks live?

Yes. Paid plans can send signed outbound events for completed scans, failed scans, high-severity findings, monitor alerts, and queued scheduled runs.

View source

Can API or MCP start active scans?

Yes, for verified domains you explicitly authorize from Dashboard → Domains.

View source

Product FAQ information · View source

The expert review

Fixvibe earns a 83/100 for its developer-centric positioning and exceptional technical SEO parity. However, the platform is currently hindered by significant entry-point friction and a lack of middle-of-funnel content.

83/100: Sophisticated technical core meeting significant structural friction.

Read the full review

Verified user reviews

0 verified

No reviews yet. The evidence locker is empty.

Fixvibe has a live access offer — claim a seat and review it honestly.

Reviews are from the SiteList community. Some reviewers received incentives — disclosed in the review, always. The verdict is never for sale.

Scores across 13 dimensions

Domain
fixvibe.app
Category
Security monitoring
Platforms
web, api
Founded
2026
Last checked
Jul 20, 2026
Public dimensions
13

qsa.sh — External security scan of your own IP, in your terminal

Score 86 out of 100 — Strong

qsa.sh

A terminal-based service that performs an external port and vulnerability scan of the user's own public IP address using open-source tools (naabu, nmap, nuclei), offering a free live-streaming tier and paid async/deep scan tiers.

VulnWatch Agency — Branded website security reports for digital agencies

Score 77 out of 100 — Strong

vulnwatch.tech

VulnWatch is an automated website vulnerability scanner that uses a proprietary AI Analyst module to transform raw scanner data into prioritized security reports. It provides executive summaries, ranked risks, and actionable remediation plans for web applications, WordPress sites, and network services.