Skip to content
← All projects

AppSafe

Live

Pre-launch security scanner for web apps, built for the vibe-coding era.

Visit appsafe.dev
AISecurityWebScanner

Overview

AppSafe is a security scanner for web apps, aimed at people who ship fast with AI coding tools. Add a site, verify you own it, and run a scan: ten modules run in parallel and cover more than 85 checks across security headers, SSL/TLS, exposed secrets, cookies, misconfigurations, attack surface, and DNS and email security.

Every finding comes with a plain-language explanation and a copy-paste prompt for your AI assistant, so fixing an issue is as simple as pasting it into Claude Code, Cursor, or ChatGPT.

Results are scored and graded A–F and can be shared as public report links. Sites can be re-scanned on a schedule, and API tokens let you run a scan from CI before every deploy.

Key features

Security headers

CSP, HSTS, X-Frame-Options, COOP and CORP, plus analysis of how strong your CSP actually is.

Exposed secrets

Scans JavaScript bundles and hidden form fields for leaked API keys — Stripe, OpenAI, Anthropic, AWS, GitHub, and more.

SSL/TLS analysis

Certificate validity, TLS version, cipher strength, chain completeness, and CAA records.

Misconfigurations

Exposed .env and .git files, source maps, debug endpoints, API docs, and open CORS.

DNS & email security

SPF, DMARC, and DKIM checks to stop others from spoofing your domain.

Cookie security

Secure, HttpOnly, and SameSite flags on session cookies.

AI fix prompts

Copy-paste prompts for AI coding tools that fix each issue.

Shareable reports

Public report URLs with an A–F security grade.

Scheduled re-scans & CI

Recurring scans per site, and API tokens to gate deploys from your pipeline.

Ownership verification

Prove you own a domain via a DNS record, meta tag, or file before scanning.

Tech stack

Next.js 15React 19TypeScriptTailwind CSSPostgreSQLDrizzle ORMBetter AuthStripeResendUpstash RedisSentryDocker

More projects

View all →