← All free tools

Free tool

Static pre-scan

Paste a file and get the deterministic pre-scan the installed audit runs FIRST — the danger patterns (eval, HTML sinks, injection shapes, disabled TLS, embedded keys) and the structural ones (a mutating route with no auth check, a test that asserts source text instead of behavior, a guard that is never called).

No account. No AI call. Nothing is uploaded: this runs in your own browser, so what you paste never reaches us to be kept.

What it reads

These are lines to LOOK AT, not verdicts. A pattern match is a question; deciding whether it is real is the part a scan cannot do.

What it does not look at

A starting point, not a clean bill of health

This scan looks for known risky patterns in the code you paste. Finding nothing does not mean the code has no problems: it means none of these patterns showed up. It is the first step the full vibe code audit runs before it reads your app as a whole.

Checking by hand too? The security checklist for AI-generated code walks through what to look at.