AppSafe
LivePre-launch security scanner for web apps, built for the vibe-coding era.
Overview
AppSafe is a security scanner for web apps, aimed at people who ship fast with AI coding tools. Add a site, verify you own it, and run a scan: ten modules run in parallel and cover more than 85 checks across security headers, SSL/TLS, exposed secrets, cookies, misconfigurations, attack surface, and DNS and email security.
Every finding comes with a plain-language explanation and a copy-paste prompt for your AI assistant, so fixing an issue is as simple as pasting it into Claude Code, Cursor, or ChatGPT.
Results are scored and graded A–F and can be shared as public report links. Sites can be re-scanned on a schedule, and API tokens let you run a scan from CI before every deploy.
Key features
Security headers
CSP, HSTS, X-Frame-Options, COOP and CORP, plus analysis of how strong your CSP actually is.
Exposed secrets
Scans JavaScript bundles and hidden form fields for leaked API keys — Stripe, OpenAI, Anthropic, AWS, GitHub, and more.
SSL/TLS analysis
Certificate validity, TLS version, cipher strength, chain completeness, and CAA records.
Misconfigurations
Exposed .env and .git files, source maps, debug endpoints, API docs, and open CORS.
DNS & email security
SPF, DMARC, and DKIM checks to stop others from spoofing your domain.
Cookie security
Secure, HttpOnly, and SameSite flags on session cookies.
AI fix prompts
Copy-paste prompts for AI coding tools that fix each issue.
Shareable reports
Public report URLs with an A–F security grade.
Scheduled re-scans & CI
Recurring scans per site, and API tokens to gate deploys from your pipeline.
Ownership verification
Prove you own a domain via a DNS record, meta tag, or file before scanning.