Back to Seatbelt

AI-built app security scanner compare: repo, live URL, and ship-flow

Most free scanners probe your live URL after you are already public. Seatbelt runs a Ship Read on the repo, folder, or ZIP you hand it, and on a deployed URL when that is all you have, with seven plain-English surfaces, a shareable proof link, and an optional push gate. Same surfaces; honest framing per lane.

Reviewed July 2026

One line

Snyk finds CVEs in dependencies. CheckVibe and ScanVibe grade headers on a deployed URL. ship-safe and REA cover local agent scans and fleet gates. Seatbelt Ship Read covers repo, folder, ZIP, and live URL for AI-built apps before you share the link: keys, database rules, server auth, payments wiring, customer data cues, and leftover admin routes, with outside-view honesty when you only paste a URL. New here? Audit my AI-built app walks the lanes in plain English.

Three lanes, not one tool

Repo / SAST lane

Snyk, Semgrep, gitleaks, vibe-check-cli, ship-safe. Great for CVEs, OWASP patterns, and secrets in git history. They do not read RLS-off migrations, unsigned webhooks, or client-priced checkout by default.

Live URL lane

CheckVibe, ScanVibe, ScanMyVibe, Mosai, VibeAppScanner, ShipSecure.io. Probe TLS, headers, passive posture, and what responds on a public URL, often with dozens of checks or runtime crawl. Useful after deploy. They do not gate your git push or park a flagged PR.

Ship-flow lane (Seatbelt)

Repo / folder / ZIP: static read of the artifact you are about to ship, plain English on seven surfaces, shareable report, optional pre-push gate. Live URL: outside-view read at /app when you only have a deploy, observation framing, honest limits on auth/IDOR/runtime, funnel to clone the repo for the full read. Not a pentest. Repo sample · URL sample.

Two sample reports

Seatbelt ships both lanes. The repo read is the full seven-surface check with push gate. The URL read is the outside view when that is all you have. Same report shape, different honesty framing. Try either at /app.

Repo / folder sample

Pinned dogfood on this landing repo: files walked, seven-surface grid, cleared ship permission, Verified by Seatbelt badge embed pattern.

Open repo sample report

Outside-view URL sample

Live URL scan of an app built on Lovable: what any visitor's browser is served, with clear limits on what a URL scan can see, and a path to run /seatbelt on the code for the full read.

Open outside-view sample report

Compare at a glance

QuestionSeatbeltURL scannersSnyk / Semgrep
Reads repo before launchYesNoYes
Probes live deployed URLYes (outside view)Yes (passive / runtime)No
Plain English for non-security foundersYesMixedMixed
Seven ship-killers in one passYesPartialPartial
Parks flagged push on a PRYes (with gate)NoNo
Shareable proof-of-check reportYesOften paywalledDashboard-first
Cross-platform (Lovable, Bolt, Cursor, Replit)YesURL-agnosticRepo-agnostic
Full findings on tryoutYesFreemiumFreemium tiers

Honest scope: Seatbelt is a safety slice at the handoff moment, not a $3k audit replacement. Paste a live URL at /app for the outside-view read; clone or export the repo for the full read and push gate. Runtime DAST and deep passive probes (Mosai, Perfai) are still a different job.

Named tools (honest scope)

Most scanners in this table grade a deploy-context outside view or scan inside one platform's lane. That is not the same moment as a seven-surface artifact read at the git push boundary with shareable proof anyone can verify when you hand off. URL clears and in-platform greens are real layers; neither gates cross-platform export or replaces the push-boundary read. For why each built-in scanner over-indexes on its home stack, see the platform-skew FAQ below.

External citations from July 2026 research. Each does real work in its lane. Seatbelt is not a replacement; it is repo + outside-view URL Ship Read at the handoff moment, with optional push gate.

ToolLaneWhat it readsSeatbelt difference
REA 0.11.0Fleet push gateCodex review on every push via rea hook push-gate. Probabilistic LLM verdict, policy YAML, audit log.Enterprise fleet governance. Seatbelt is a deterministic seven-surface static read with a shareable report URL.
CodeRabbitPR review layerAI pull-request review on GitHub/GitLab. Free OSS: PR summarization + IDE/CLI reviews only. Pro $24/dev/mo annual: 5 PR reviews/hour rolling; fair-usage throttle at 95th percentile degrades Pro to 4→3→2→1 reviews/hour at 30/40/50/60+ reviews in the last 7 days (Jul 2026). When rate-limited, posts a comment and a Review rate limited check that passes by design (never blocks merge on protected branches, per official Fair Usage Limits Policy).Real probabilistic diff review lane. npm audit catches dependency CVEs, not RLS-off migrations, client Stripe keys, or unsigned webhooks. Agent fleets opening many PRs/hour hit the throttle; merge stays ungated even when throttled. Seatbelt is a deterministic seven-surface artifact read at ship moment with shareable proof at handoff.
vibe-check-cliPre-push hookvibe-check init installs pre-push hook + PR comment bot. Broad SAST, secrets, prompt-injection rules.Rule-count breadth, not seven-surface triage. No founder-readable handoff report at freelancer delivery.
ScanVibeLive URL / runtimeURL-first analyzers: SSL, headers, secrets, libs, exposed files, Supabase RLS, Firebase rules, API auth. Free unlimited, no signup. Pro $9/mo adds monitoring, badges, and history. Business $29/mo: multi-page crawl, API tokens, CI/CD score-threshold deploy block, Slack/Discord webhooks (Jul 2026).ScanVibe runs deeper passive URL checks, including a cheap CI/CD gate on Business. Seatbelt also accepts a live URL at /app. Repo handoff unlocks seven-surface read, shareable proof, optional push gate.
vibeappscanner (vas)Live URL / runtimeURL scanner that retired per-scan $5/$19 for subscriptions: Free $0 (full check suite, one finding unlocked in detail) · Go $19/mo (20 scans, every finding unlocked) · Pro $39/mo (150 scans, weekly deep/authenticated, monitoring). Suite also covers SEO, AEO/GEO, performance, accessibility (Jul 2026).Real post-deploy URL grade with a partial-free first scan. Subscription motion, not pay-per-depth. No seven-surface plain-English map on the repo you export, no git push gate, no shareable Ship Read proof at handoff. Seatbelt reads the artifact before you share the link.
CheckVibeLive URL / runtimePassive/runtime URL letter grade. Free $0 (1 project · 4 scans/mo). Starter $29/mo · Pro $59/mo · Max $129/mo (Jul 2026 raise; FAQPage dated 2026-07-27). Every scan can include a visibility audit: 68 SEO + 46 AEO checks at no extra charge.Real URL posture plus a bundled SEO/AEO visibility lane. Letter grade in their UI ≠ shareable Ship Read proof at git push. Seatbelt also grades live URLs at /app; repo export unlocks seven-surface read and optional push gate.
ScanMyVibeLive URL / runtimePassive/runtime URL probe. Free $0 (4 scans/mo, 3 modules, no signup per schema.org offers) · Pro $29/mo (100 scans · 16 modules · AI fix prompts · PDF) · Enterprise $79/mo (Jul 2026).Honest free-cap URL lane (four scans/mo, not unlimited). Outside view after deploy ≠ seven-surface artifact read + shareable proof at handoff. Seatbelt also accepts a live URL at /app; repo export unlocks the full read and push gate.
ShipSecure.ioLive URL / runtimeRuntime URL scanner after deploy. Free $0: headers-only (1 of 6 checks), 5 scans/mo, no shareable reports. Pro $7.99/mo (or $79.99/yr): all 6 scanners, up to 1000 scans/mo, AI fix prompts, shareable reports (Jul 2026). Distinct from npm ship-safe.Cheapest full-runtime URL tier in this cluster, with an honest Pro scan cap (not unlimited). Runtime crawl after deploy and artifact read before you share the link are different layers. Seatbelt also accepts a live URL at /app; wedge is seven surfaces on the repo you export.
VibeEvalLive URL / runtime DASTAutonomous-agent DAST motion with 310+ security checks. ~$19/mo unlimited retired. Pro $49/mo · Team $149/mo · Lifetime $499 once · 14-day free trial, no card (Jul 2026). Pentest engagements still from $2,900. Vendor schema.org offer can still list $19 (stale).Respect the agentic DAST layer: live probes find real access-control breaks. Seatbelt reads the static ship artifact in git before the link goes out: no attack traffic, human keeps structural judgment, shareable proof link. Different layer from Perfai-class black-box DAST and from passive URL grades.
getvibescanPaste-code / fixture demo/scan is live: paste code, get a security report, no account required. Homepage ships an interactive canned demo. Paid tiers (Pro $29 · Shield $99) still route to a private-beta email waitlist; chip "Pre-launch · Q3 2026" (Jul 2026). Distinct from tryvibescan.dev and vibescan.co.Motion split: self-serve paste-code demo works; paid checkout does not. Fixture-first demo ≠ seven-surface read of your repo at git push with shareable proof. Seatbelt scans the folder, ZIP, or URL you hand it.
VibeCheckRepo + URL hybridDual lane on notelon.ai: Source Code Scanner (GitHub API; optional token for private repos) + Live Site Scanner (headers, exposed files, CORS, cookies, SSL). Free letter grade with no signup; publishes "State of Vibe Coding Security 2026" (5,600 apps cited); $19 Security Playbook upsell (Jul 2026).Real dual lane: repo via GitHub API and live URL checks. Assigns a letter grade in their UI. Seatbelt opens a shareable proof report at the push boundary (cleared link anyone can verify), optional push gate, seven surfaces in plain English. Grade in-browser vs proof at handoff.
Vibe Check (didyouvibecheck.com)Repo SASTPublic GitHub-repo scanner (distinct from notelon.ai VibeCheck). Five review layers; 2-of-3 model agreement before a finding ships; OWASP Top 10 (2021) and CWE mapping. Badge-ready shareable reports at score 90+. Free $0 (1 job, public repos under 100 files) · Single $5/job · Solo $49/10 jobs · Team $99/25 jobs (Jul 2026). Public repos only on self-serve tiers.Real badge lane on public clones: the agreement gate is more serious than a single-model grade. They score a GitHub repo anyone can clone. Seatbelt reads your local artifact at the push boundary, gates the handoff, seven surfaces in plain English, optional push gate. Badge on a public scan vs proof on what you are about to ship.
Ship Safe (shipsafecli.com)Repo SAST · hooks · CI gatenpm ship-safe v9.5.2 (MIT, Jul 2026; distinct from ShipSecure.io URL scanner · shipcheck-cli launch-readiness · Shippingszn scoreboard). 29 parallel agents (InjectionTester, AuthBypass, SSRF, SupplyChain, MCP/LLM red-team, SlopSquat, InstallGuard, Supabase RLS, CICD, …). npx ship-safe REPL · audit · ci --threshold + SARIF · red-team --gpt-red · agent fix loop; init hooks. Vendor /share scan URL (7-day TTL). Free MIT local core (no signup for core scans) · hosted Pro $9/mo (scan history, cloud dashboard, PDF) · Team $19/seat/mo (shared workspace, PR Guardian, collaboration) per shipsafecli.com. ~1.05K npm dl/wk (API Jul 2026).Real broad local agent/MCP/LLM coverage lane: vendor self-assigned score + optional vendor /share URL (7-day TTL) ≠ seven-surface plain-English artifact read + shareable Ship Read proof anyone can verify at git push/handoff. Fourth ship* homophone (name the tool when you answer). Pairs Self-scored launch gates + DIY deny-hooks Overlap rows · shipcheck-cli launch-readiness FAQ on this page.
VibeDoctorRepo + URL hybrid · PR reviewGitHub-repo + live-site scanner for vibe-coded apps: read-only GitHub App clone (isolated container, code not stored) + URL lane. 149+ checks in ~30s; AI-specific (hallucinated imports, god files, empty test bodies); framework-aware. MCP for Cursor, Claude Code, Copilot, Windsurf. Launch Audit $9 one-time ends in a plain-language launch verdict. Subs: Watch $15/mo · Guard $39/mo (+ AI PR review on GitHub) · Shield $79/mo (Jul 2026).Real repo+runtime breadth and optional PR review on Guard tier. Vendor assigns its own launch verdict in their UI. Seatbelt reads your local artifact at the push boundary, optional push gate, shareable proof anyone can verify at handoff. Guard PR gate ≠ seven-surface ship-read on what you export.
SafeVibesLive URL / runtimeURL-first database-exposure scanner (Safe Vibe Codes; safevibe.codes alias). Paste URL → API endpoint + JS bundle analysis; maps exposed tables, record counts, write access (insert/update); security grade + fix instructions + verification rescan. Bolt, Lovable, Base44, v0; Replit coming soon. Free $0 scan (Jul 2026; no paid tiers visible). Base44's own application-security guide prescribes SafeVibes as step 1 before the in-platform Security tab.Real anonymous-access probe after deploy; vendor-endorsed external lane for Base44 builders. Vendor grade on a live URL ≠ cross-platform git push gate or shareable proof anyone can verify at export handoff. Seatbelt also accepts a live URL at /app; repo export unlocks seven-surface read and push gate.
VibeProofLive URL / runtimeURL paste → bundled Trust Score (security + SEO + mobile UX + performance; demo 64→86 on homepage). 50+ checks; AI fix prompts for Cursor, Bolt, Lovable, v0, and Replit; continuous monitoring digests. Solo Launch $19.99→$4.99/mo with moltbot75 75% promo (Jul 2026; Growth/Scale tiers same discount). Marketing positions as replacing a $396/mo stack (Snyk + Semrush + Ahrefs + GTmetrix). No repo or static read lane.Real outside-view overlap on exposed keys and endpoints after deploy. Trust Score mixes SEO and UX into a post-deploy security grade. No seven-surface plain-English map, no git push gate, no shareable Ship Read proof at handoff. Distinct from SafeVibes (DB-exposure focus) and CheckVibe (letter grade). Seatbelt reads the artifact before you share the link.
Perfai Security (Autonomous DAST)Live URL / runtime DAST3-agent black-box URL scan (Vision, Security, Fix). Vendor claim: over 20,000 contextual exploit mutations at BOLA/IDOR and broken access control. No source access. Free $0 (900 credits/mo), Pro $99/mo, Growth $499/mo (Jul 2026; pricing shifted once in 10 days).Live-attack DAST after deploy finds real access-control breaks; respect it. Seatbelt reads the static ship artifact in git before the link goes out: no attack traffic, no auto-merged patches, human keeps structural judgment, shareable proof link.
v0 deploy blocks (Vercel)Platform-nativeDefault gate, no setup: security checks run during generation and before deploy. Vercel reports over 100k insecure deployments blocked, 17k in 30 days on exposed secrets alone; top blocked class is NEXT_PUBLIC_ variable misuse (Vercel blog, Aug 2025, and Vercel KB).The strongest default platform gate; respect it. Scope is the v0 to Vercel deploy lane, secrets and config focused, with no shareable report or badge. Export the repo or build anywhere else and nothing gates the push.
Lovable Security (Basic/Deep + Wiz/Aikido)Platform-nativeBasic scan auto on publish; Deep scan optional; opt-in "Block publishing with critical findings" (all plans, off by default) plus Enterprise-only "Block publishing with PII" when Sensitive data scanning is on. Jul 2026: opt-in auto-fix during agent chat (eligible Basic-scan error-level findings; consumes credits; not Deep scan) plus security memory (dismiss/accept/context edits persist; scanner + agent reference). Security view Try to fix all on deep-scan filter is free; chat auto-fix consumes credits (security-view docs). Greyed Try to fix all usually means stale Deep scan, not clearance. Official disclaimer: No issues found means the latest scan found nothing, not zero security risk. HackSafe self-reported audits (Feb 2026): 63% of 62 Lovable apps had critical or high findings; average 10 per app. Wiz connector + Aikido pentest on all plans → shareable SOC 2/ISO-structured report. April 2026: platform API regression (Feb 3 through Apr 20; fixed Apr 20); HackerOne reports from Feb 22 closed on stale triage docs until public disclosure Apr 20 (Lovable incident response).Strongest opt-in publish gate in the category; respect it. Auto-fix and security memory are in-platform remediation, not ship-moment gating. The April 2026 episode was broken access control on shared infrastructure, not ship-moment gating. Wiz/Aikido/deep scan in-platform ≠ cross-platform git push gate. Export the synced GitHub repo, rotate if exposure is plausible, and run a ship-moment read before you share.
Replit Security (publish checks)Platform-nativeAlways runs a security scan before publishing. Opt-in Block publishing of critical vulnerabilities in Deploy → Advanced (off by default; renamed from Beta "Security scan before publishing", July 2026): On blocks until resolved or dismissed; Off publishes with findings surfaced. Critical tier includes leaked credentials, SQL injection on exposed endpoints, and RCE. Security Agent + dependency scans in-editor.Same opt-in critical block pattern as Lovable: always pre-publish scan, optional critical block when enabled. In-platform only, critical severity when toggle on, dismiss unblocks publish, no shareable plain-English proof link. Private GitHub export → path scan still ungated.
Bolt.new Security AuditPlatform-nativeSettings → Database → Security tab: missing RLS, leaked-password protection, mutable search paths. Auto on publish. Ask Bolt to fix. When clean, Publish menu shows No security issues (support.bolt.new publish, July 2026).Green No security issues line is confidence copy, not v0's deploy block. Alerts with Review security if issues remain; publish never stops. Does not follow export to GitHub or a Cursor push path. Ship-moment gate still needed at handoff.
Base44 SecurityPlatform-nativeManual Run Security Scan (Dashboard → Security), not automatic on deploy. Security tab on all plans, including free: data permission gaps, exposed creds, login gaps, package vulns, code vulns (Builder+), security headers. One-click Fix. Ignore moves issues to Ignored; they do not reappear on the next scan. Base44's own application-security guide prescribes SafeVibes as step 1 of an external URL loop before the in-platform check.Weakest in-platform gate among major builders: no block, manual scan, Ignore can false-green a rescan. SafeVibes is their endorsed external lane; Seatbelt is cross-platform ship read + shareable proof link anyone can verify at git handoff. Export or clone to Cursor still ungated.
OX Security VibeSecEnterprise generation-timeEmbeds org security context into AI editors at generation time. Enterprise product (September 2025). Prevent-at-source inside org-managed editors, not a solo builder push gate.Real enterprise AppSec lane for fleet editors. Does not gate cross-platform git pushes on exported repos or produce plain-English shareable proof at handoff. Seatbelt reads the artifact at the push boundary.

Competitor rows reflect public docs and pricing pages reviewed July 2026. Pricing and features change; verify on each vendor site.

FAQ

Which AI-built app security scanner should I run first?

Before you share the link, run a Ship Read on the repo, folder, or ZIP you are about to ship. If you only have a deployed URL, paste it at /app for the outside-view read, then clone the repo for the full read and push gate. Dedicated URL scanners add passive posture checks Seatbelt does not claim. If you handle payments or customer data, do not treat a clean URL scan as permission to skip the repo read.

Does Seatbelt replace CheckVibe?

No. CheckVibe and peers run passive or runtime URL probes. Seatbelt also grades live URLs via outside-view static read (observation framing, honest limits), but the wedge is seven-surface plain English at repo handoff plus optional push gate. Use both if you want deep URL posture and ship-moment proof.

I already run npx ship-safe / Ship Safe before I ship. Why Seatbelt?

Respect it. Four different products collide on ship* as of July 2026. Name the one you mean before you compare:

  • Ship Safe (npm ship-safe v9.5.2, shipsafecli.com): local-first CLI with 29 parallel agents (InjectionTester, AuthBypass, SSRF, SupplyChain, MCP/LLM red-team, SlopSquat, InstallGuard, Supabase RLS, CICD, …). npx ship-safe REPL · audit · ci --threshold + SARIF · red-team --gpt-red · agent fix loop; init hooks. Free MIT core · hosted Pro $9/mo · Team $19/seat/mo. Findings include a vendor self-assigned score and optional vendor /share URL (7-day TTL). ~1.05K npm dl/wk (Jul 2026). That broad local agent/MCP coverage lane is real.
  • ShipSecure.io: runtime URL scanner after deploy (headers-only on free tier; Pro $7.99/mo capped at 1000 scans/mo). Not the npm ship-safe CLI. See the ShipSecure row in the named-tools table above.
  • shipcheck-cli: launch-readiness + MCP metadata scanner. Not Ship Safe. See the shipcheck-cli on this page.
  • Shippingszn: paywall scoreboard motion (pairs bench FP-burden compare ammo). Not a local 29-agent CLI.

Seatbelt is a different moment on the Ship Safe lane: seven surfaces in plain English on your local artifact at the git push boundary, optional deny hooks on --no-verify bypass paths, and a shareable Ship Read link anyone can verify at handoff. Vendor self-assigned score + optional /share URL you mint is not push-boundary proof anyone can open without trusting your terminal. Many teams want both. See a repo sample report for ship-moment proof.

vibe-check-cli init gives me pre-push hooks. Why Seatbelt?

vibe-check-cli covers broad SAST and secret rules with a PR comment bot. Seatbelt prioritizes seven ship-killers in founder English and produces a shareable report URL at handoff. Breadth and triage are different jobs; you can run both.

Why not just ask your agent to audit the code?

Respect the instinct. Anthropic's Claude Code Security (Feb 20 2026, limited research preview for Enterprise and Team) reads and reasons about your code the way a human security researcher would, with multi-stage self-verification and nothing applied without human approval. Founders also shop claude code security audit skill and prompt recipes for the same job. Detection is not the wedge: a naive founder audit prompt on a frontier model already finds most planted flaws. Precision is. On our July 2026 agent-audit bench, that prompt wrongly blocked 27 to 33% of known-safe apps as ship-blocking. The Seatbelt engine blocked none of those same cases. Same thirty clean apps: the agent blocked ten, the engine blocked none. Limits on that number: one model (Gemini 3.6 Flash), Fable 5 not in the bench yet, our corpus, single-shot prompt. What still holds without leaning on catch-rate: Seatbelt is deterministic on the same artifact, independent of the model that wrote the code, automatic at git push via hooks, enforcing when you wire deny hooks, and provable with a shareable Ship Read link anyone can verify. Distinct from OpenAI's Codex Security CLI recipe in the FAQ below. Many teams want both.

I already run OpenAI's Codex Security CLI (@openai/codex-security). Why Seatbelt?

Respect it. OpenAI's Codex Security CLI (npx @openai/codex-security, Jul 2026 research preview) is a real repo AppSec client: scan a folder or diff, CI and SARIF export, and install-hook can sit on pre-commit and block high findings. That packaging competes for the commit slot. Two limits stay load-bearing: the analysis still calls OpenAI (sign-in or API key; access grant, often Trusted Access), and the input is still a repository path or diff. No domain, no served-bytes read, no estate discovery, and no stranger-forwardable Proof of Read. Seatbelt is a different moment: a seven-surface plain-English read of what you export at git push, optional deny hooks, and a shareable Ship Read link anyone can verify at handoff. Distinct from REA's fleet Codex-review gate in the FAQ below. Many teams want both.

REA already gates my fleet pushes. Do I still need Seatbelt?

REA runs a probabilistic Codex review as its fleet-policy mechanism. That is REA's review lane, not OpenAI's Codex Security CLI (see the FAQ above). Seatbelt is a deterministic static read of seven surfaces with exit codes and a shareable report. Fleet stacks often use both: LLM review for governance, artifact read for launch-day ship-killers.

npm audit or CodeRabbit already reviews my PRs. Why Seatbelt?

Respect it. npm audit catches dependency CVEs, not RLS-off migrations, client Stripe keys, or unsigned webhooks. Under agent-heavy PR volume, AI PR reviewers throttle in five different modes (Jul 2026), and none blocks merge on seven-surface artifact read at git push:

  • CodeRabbit pass-check: CodeRabbit Pro fair-usage throttle degrades from 5 to as low as 1 review/hour at 60+ reviews in seven days. When rate-limited, it posts a Review rate limited check that passes by design (never blocks merge on protected branches).
  • Greptile flex-skip: Greptile Starter Free includes 50 credits/mo. When projected flex spend hits the Flex Usage Limit, Greptile skips reviews that would incur flex usage until the next billing period (silent skip, merge ungated).
  • Qodo credit exhaustion: Qodo Pro Team pools credits at $0.012/credit with headline "No rate limits", but reviews stop at zero credits.
  • Macroscope spend-cap silence: Macroscope Code Review is $0.05/KB unified diff (10 KB minimum = $0.50/review; large refactor ~$35). Prepaid balance + auto-refill with monthly hard ceiling (cannot override), per-review cap, and per-PR cap. When a cap hits, reviews halt; commits/PRs during the pause are skipped, not retroactively processed. 1000 free Agent credits/mo (Jul 2026).
  • Bugbot neutral-on-findings: Cursor Bugbot posts a neutral check by default when findings land (~$1-1.50/run); merge stays ungated unless you wire a custom block.

Probabilistic diff review on merged PRs is not a deterministic seven-surface artifact read at ship moment. Seatbelt reads keys, database rules, auth, payments, customer data cues, and risky shortcuts in founder English, with optional push gate and shareable proof anyone can verify at handoff. Pairs Git AutoReview, Qodo, and Macroscope PR-review rows on this page. Many teams want both.

Git AutoReview already reviews my PRs for ~$15/mo. Why Seatbelt?

Respect it. Git AutoReview Team is a real flat-price PR-review lane: $12.49/mo annual ($149.90/yr) or $14.99/mo monthly for up to 10 members (not per-seat like CodeRabbit), with Free tier 10 AI reviews/day, BYOK, and a human-approval workflow where every AI comment stays a draft until you approve, edit, or reject before it posts to GitHub/GitLab/Bitbucket (Jul 2026). That flat team price and approval-before-publish motion is genuine value for eng teams. Seatbelt is a different moment: a deterministic seven-surface plain-English read of your local artifact at the git push boundary, with optional push gate and a shareable Ship Read link anyone can verify at handoff. Probabilistic diff review on merged PRs is not the same layer as ship-moment proof on what you export. Pairs CodeRabbit and Greptile PR-review rows on this page. Many teams want both.

Platform scanning (v0, Lovable, Bolt, Netlify) already covers me?

Platform checks are real but platform-scoped. Platforms differ, no one default covers every builder. v0 has the strongest default gate: Vercel blocks insecure v0 deploys automatically, no setting to turn on. Lovable and Replit share the opt-in critical block band: Lovable workspace admins can enable "Block publishing with critical findings" on all plans (off by default), and Enterprise workspaces can enable a second opt-in "Block publishing with PII" when Sensitive data scanning is on. Replit always runs a security scan before publishing and offers opt-in Block publishing of critical vulnerabilities under Deploy → Advanced (off by default; Replit Project Security Center, July 2026): when On, publish blocks on critical severity until you fix or dismiss; dismissed findings unblock. Both Lovable gates and Replit's toggle are in-platform only and off by default; the shareable proof there is an Aikido connector report shaped for SOC 2 questionnaires, not a plain-English ship read. Lovable also documents in-platform remediation as of July 2026: opt-in auto-fix during agent chat injects eligible Basic-scan error-level findings into chat context and consumes credits (not Deep scan). Security memory persists dismiss, accept, and context edits so the scanner and coding agent reference prior decisions. In Security view, Try to fix all on your current deep-scan filter is free; chat auto-fix consumes credits (Lovable security-view). That is platform remediation inside the builder, not ship-moment gating and not shareable proof at git push. In April 2026 a platform API regression let any authenticated Lovable user read chat history and source on legacy public projects (Feb 3 through Apr 20; fixed Apr 20, per Lovable's incident response). That post also documents that researchers filed valid HackerOne reports starting Feb 22 that were closed without escalation because stale triage documentation still described public chat visibility as intended until a public disclosure Apr 20. That episode was broken access control on shared infrastructure and a disclosure-process miss, not ship-moment gating and not something either opt-in publish block would catch on a cross-platform export. Bolt is the opposite false-green: when it finds nothing or you fixed issues, the Publish menu shows No security issues (Bolt support publish, July 2026). That green line is confidence copy, not v0's deploy block. If issues remain, Bolt alerts with Review security; the publish flow never stops. Base44 sits at the bottom: manual Run Security Scan (not on deploy), no publish block, and Ignore hides findings from the next scan so a green rescan can read false-clean. Base44's own application-security guide prescribes SafeVibes as step 1 of an external URL loop before the in-platform check. Wiz and Aikido deep scans in-platform still do not gate a git push from Cursor or any other host. Either way the gate lives inside one platform's deploy lane. Push from Cursor or any other host and nothing checks the artifact you hand off. Export the synced GitHub repo, rotate if exposure is plausible, and run a ship-moment read before you share. Seatbelt gates your push wherever you build and returns the shareable report at freelancer handoff. For why a green in-platform scan still misses cross-platform handoff, see the platform-skew FAQ below.

My platform's built-in scanner already cleared me. Do I still need Seatbelt?

Respect it. Every vibe platform ships a real in-platform scanner tuned to what breaks most often on that stack. They are not interchangeable. July 2026 research pins a platform-skew pattern: each native scanner over-indexes on its home failure mode and under-checks the rest.

PlatformWhat the built-in scanner emphasizes
Claude Code / Cursor agentsMissing auth rate limits (~80% of vibe-coded apps per vibe-eval pattern #10, Jul 2026; onout primary shows clean bcrypt/JWT login POST with zero throttling)
LovableRow-level security gaps, publish versus editor-private confusion, opt-in publish blocks (off by default, in-platform only), in-chat auto-fix (opt-in, credit-priced) and security memory
BoltExposed keys in bundle and export paths; publish menu can read No security issues when clean (confidence copy, not a deploy block)
v0 / VercelServer actions and NEXT_PUBLIC_ misuse (default deploy block on the v0 lane; Vercel blog, August 2025)

Each native scanner optimizes in-platform. None reads all seven surfaces at git handoff, gates cross-platform export from Cursor or GitHub sync, or returns shareable proof anyone can verify at handoff. For publish-gate ladder detail (v0 default block, Lovable opt-in, Bolt false-green, Base44 Ignore), see the platform scanning FAQ above. Seatbelt gates your push wherever you build and returns the shareable Ship Read at freelancer handoff. See a repo sample report for ship-moment proof.

Lovable already auto-fixes security findings in chat. Do I still need Seatbelt?

Respect it. Lovable documents opt-in auto-fix during agent chat as of July 2026: eligible Basic-scan error-level findings flow into chat context and the agent can patch in-platform. That motion consumes credits and does not apply to Deep scan. Lovable also ships security memory: dismiss, accept, and context edits persist so the scanner and coding agent stop re-flagging what you already judged. In Security view, Try to fix all on your current deep-scan filter is free; chat auto-fix consumes credits (Lovable security-view, July 2026). If Try to fix all is greyed out, Lovable usually means your Deep scan results are stale or out of date, not that you are cleared or that Lovable will not help. Security view requires Deep scan results to be up to date before remediation runs; when your project changes, earlier results are marked outdated. Builders often search for lovable try to fix greyed out when they hit that state. Lovable's own docs also say that No issues found means the latest scan did not surface findings, but it does not guarantee the project has no security risk. That is the same false-green shape as Bolt's No security issues publish menu label. As of July 2026, Deep scan does not run on every edit. You run it on demand from Security view, your workspace Security center, or the publish dialog after Basic scan passes. That on-demand scan does not replace cross-platform Ship Read proof anyone can verify at git push or handoff. A Basic-only green state can still miss code-level issues Deep scan covers. A Jul 2026 audit of 50 deployed Lovable repos found 89% missing Row Level Security on app tables and 34% with service_role keys in client code (DEV tgoldi, Jul 2026). Lovable creates Supabase tables but often does not turn RLS on. That complements HackSafe's 63% critical/high rate on 62 self-reported Lovable app audits (Feb 2026). Real in-platform remediation. It still lives inside Lovable: no cross-platform git push gate, no seven-surface artifact read at handoff, no shareable Ship Read link anyone can verify when you export to Cursor or clone GitHub. Seatbelt reads the synced repo at the push boundary with proof you can forward.

v0 already blocks insecure deploys by default. Do I still need Seatbelt?

v0's gate is real and on by default. Vercel reports over 100k insecure deployments blocked, including 17k in 30 days on exposed secrets alone, with NEXT_PUBLIC_ variable misuse the top blocked class (Vercel blog, August 2025). Respect it. It covers the v0 to Vercel deploy lane, focuses on secrets and config, and produces a block, not a shareable report or badge. Export the repo or build anywhere else and nothing gates the push. Seatbelt reads the artifact on any platform and returns proof you can hand off.

Bolt's Security Audit already checks my app. Do I still need Seatbelt?

Bolt's Security Audit tab scans database rules and secrets inside Bolt, runs automatically on publish, and offers one-click fixes. When Bolt finds nothing or you fixed issues, the Publish menu shows No security issues (Bolt support publish, July 2026): a green confidence line, not a deploy block like v0's automatic Vercel stop. If issues remain, Bolt alerts with a Review security link to Settings; the publish steps never block. Export to GitHub or push from Cursor and nothing gates the artifact. You still need a ship-moment read with shareable proof at handoff.

Replit's publish scan cleared me. Do I still need Seatbelt?

Replit always runs a security scan before you publish. Respect it. Opt-in Block publishing of critical vulnerabilities (Deploy → Advanced, off by default) blocks on critical severity until you resolve or dismiss; dismissed findings unblock publish (Replit docs, July 2026). Security Agent grades in-platform only. No shareable plain-English cleared-report link at handoff. Sync to private GitHub, clone, and path-scan the checkout (never a Repl URL). That export path is still ungated. Seatbelt reads the artifact at the push boundary with proof you can forward.

Base44's Security tab already scans my app. Do I still need Seatbelt?

Base44's Security tab runs on all plans, including free: data permission gaps, exposed credentials, login gaps, package vulns, and security headers, with one-click Fix. The scan is manual (Run Security Scan in Dashboard → Security), not automatic on deploy, and it does not block publish. Ignore moves an issue to Ignored and it will not reappear on the next scan, so a green rescan can read false-clean after you dismissed a real gap. Base44's own application-security guide prescribes SafeVibes as step 1 of an external URL loop before the in-platform check. SafeVibes is their endorsed outside view; Seatbelt is cross-platform ship read plus shareable proof link anyone can verify when you export or clone and push from Cursor.

ScanVibe is unlimited free. Why use Seatbelt?

ScanVibe offers unlimited free URL scans with no signup, Pro at $9/mo for monitoring and badges, and Business at $29/mo for multi-page crawl plus CI/CD score-threshold deploy block (Jul 2026). URL-first passive checks. Seatbelt also grades live URLs at /app. Repo export unlocks the full read and push gate; outside view alone uses observation framing.

ScanMyVibe is free. Why use Seatbelt?

ScanMyVibe offers four free URL scans per month with no signup (schema.org offers, Jul 2026), passive/runtime URL probe, plus Pro $29/mo and Enterprise $79/mo. Seatbelt also accepts a live URL at /app (outside view). The full seven-surface read, shareable proof, and optional push gate need the repo, folder, or ZIP export.

ShipSecure Pro is only $7.99/mo. Why Seatbelt?

Respect it. ShipSecure Pro at $7.99/mo is the cheapest full runtime URL scan tier in this cluster: six checks in about 30 seconds with shareable reports, capped at 1000 scans/mo (not unlimited; Jul 2026). Their free tier is headers-only: one of six checks, five scans per month, no shareable reports. That is an honest freemium wedge. Seatbelt also accepts a live URL at /app (outside view) but the ship-moment wedge is seven surfaces on the repo you export, shareable proof, optional push gate. Runtime crawl after deploy and artifact read before you share the link are different layers.

Don't I need URL, repo, and runtime scanners (three-layer model)?

Most tools cover one or two layers. Seatbelt runs repo, folder, ZIP, and live URL outside-view Ship Reads, seven surfaces in plain English, shareable proof, optional push gate. Dedicated URL scanners add passive posture depth and runtime crawl. DAST (Perfai) is a different job again. Match the tool to the moment; do not treat a URL-only read as permission to skip the repo export. See a repo sample report and an outside-view sample report. The full method is public: how Seatbelt scans.

vibe-check-cli says it is 95% deterministic. Isn't that enough?

Deterministic rule hits are real value. They are not the same as ship-killer prioritization in founder English. vibe-check-cli covers broad SAST breadth with a PR comment bot. Seatbelt triages seven surfaces, parks flagged pushes, and returns a shareable report URL at handoff. You can run both.

How does Seatbelt fit with Shiplight's pre-launch testing workflow?

Shiplight owns the parent "how to test a vibe-coded app before launch" query with a 10-step workflow where security is step 10. Seatbelt automates that security step: a plain-English seven-surface read before you share the link. Adjacent, not competitive.

An AI pentester already attacks my app for $0-$99/mo. Why Seatbelt?

Respect it. Perfai's live-attack DAST lane finds real access-control breaks on a deployed URL. That is a different layer than a static read of the ship artifact before the link goes out. Perfai's own launch reviews concede the black-box motion's costs: browser automation loops bottleneck on rate-limiting firewalls and MFA gateways; the Fix Agent "addresses symptoms rather than underlying software designs," and merging auto-generated patches without senior structural oversight risks convoluted dependency layers (Product Hunt reviews, Daniyal Khamzin, Jul 2026). Seatbelt reads what you are about to ship, in git, before you share the link: no attack traffic, no auto-merged patches, human keeps structural judgment, shareable proof link.

There is already a dozen free or cheap URL scanners. Why Seatbelt?

The URL scanner cluster is crowded, and pricing has moved up-market: vas retired per-scan $5/$19 for Free / Go $19/mo / Pro $39/mo (partial-free first scan); CheckVibe Free plus Starter $29 / Pro $59 / Max $129 (Jul 2026 raise); ScanVibe Free unlimited plus Pro $9/mo and Business $29/mo CI/CD; VibeEval Pro $49 / Team $149 / Lifetime $499 with a 14-day no-card trial; Mosai's pay-per-report unlock at R$47; free DB-exposure scans like SafeVibes ($0; Jul 2026); trust-score bundles like VibeProof (Solo Launch $4.99/mo with moltbot75 promo); live self-serve monitoring like VibeScan (tryvibescan.dev) (Free $0 · Pro $19/mo); paste-code demos like getvibescan (/scan live, paid still waitlist); and headers-only free tiers like ShipSecure (1 of 6 checks on $0, 5 scans/mo). Full runtime on ShipSecure Pro is $7.99/mo with up to 1000 scans/mo, not unlimited. Respect what they do: passive checks, TLS, sometimes runtime crawl, vendor scan grades, and AI fix prompts. Mosai's own FAQ says they do not authenticate or test IDOR, tenant isolation, or internal access controls (scan.mosai.com.br). Seatbelt also accepts a live URL at /app (outside-view read, observation framing) but does not claim Mosai-class passive breadth. The wedge is seven-surface plain English on the repo you export, shareable proof anyone can verify at handoff, optional push gate. Vendor scan grade + fix prompts are not push-boundary shareable proof. Not a cheaper URL scanner.

A URL scanner already gives me a trust/security score. Why Seatbelt?

Respect it. VibeProof and peers run a real outside view after deploy: exposed keys in client bundles, unprotected endpoints, TLS, and more. VibeProof bundles security with SEO, mobile UX, and performance into one Trust Score (50+ checks, AI fix prompts, Solo Launch $4.99/mo with moltbot75 promo, Jul 2026). That post-deploy grade is genuine value for live-site hygiene. Seatbelt is a different moment: a seven-surface plain-English read of the artifact in git before you share the link, with optional push gate and a shareable proof report anyone can verify at handoff. A runtime SEO+UX mixed into a security score after deploy is not the same layer as ship-moment read on what you export. Many builders want both. See repo and URL samples.

Base44's blog tells me to run SafeVibes first. Isn't that enough?

Respect it. SafeVibes is a real free URL scan focused on database exposure: exposed tables, record counts, and write access from an anonymous outside view (Jul 2026). Base44's own application-security guide prescribes SafeVibes as step 1 of a security hardening loop before the in-platform Security tab. That external validation lane is genuine. Seatbelt is a different moment: a cross-platform ship read on the artifact in git at the push boundary, with optional push gate and a shareable proof link anyone can verify when you export or clone. External anonymous-access grade after deploy and artifact read before you share the link are different layers. Many Base44 builders want both.

VibeDoctor already gave me a launch verdict. Why Seatbelt?

Respect it. VibeDoctor runs 149+ checks on a GitHub repo and live site in ~30s, with a Launch Audit $9 one-time that ends in a plain-language is-this-safe-to-launch verdict and MCP in Cursor, Claude Code, Copilot, and Windsurf (Jul 2026). That launch-verdict lane is real. Seatbelt is a different moment: a static read of your local artifact at the push boundary with optional push gate and a shareable proof link anyone can verify at handoff. Their Guard tier adds AI PR review on GitHub; that is not the same as seven ship-killers in founder English on what you export. Many teams want the launch audit and the push-boundary read.

A free scanner already grades my app. Why Seatbelt?

Respect it. VibeCheck on notelon.ai runs a real dual lane: Source Code Scanner via GitHub API and Live Site Scanner on headers, exposed files, CORS, cookies, and SSL. Free letter grade, no signup. Seatbelt also grades live URLs at /app and runs the full read on repo/folder/ZIP, shareable proof anyone can verify, optional push gate, seven surfaces in plain English. Grade in-browser vs proof at handoff. See repo and URL samples.

What about slopsquatting or malicious npm packages?

Real risk, and the names matter. Four separate supply-chain shapes show up in builder conversations (July 2026):

  • Typosquatting: you typo a real package name and install the wrong one.
  • Slopsquatting: the model invents a package at codegen and you copy-paste the install. The Jan 2026 react-codeshift hallucination spread to 237 repos via agent skill files (Aikido).
  • HalluSquatting: the agent hallucinates a repo, skill, or MCP name at fetch with no human paste. Jul 2026 research reports hallucination rates up to 85% on repos and 100% on skills for trending names; tested agents include Cursor, Copilot, Cline, and Gemini CLI (arXiv, SecurityWeek).
  • Dual-namespace collision: two legitimate packages share an unscoped name. @yagyeshvyas/vibeguard and @indicated/vibeguard are different products (see the VibeGuard disambiguation above). Confusion, not malware.

Run Socket or Snyk on your dependencies for registry lookup, malware signals, and install-time skill gates. Seatbelt reads your src/ artifact on the seven surfaces that hurt launches before you share. It is complementary, not a replacement: Seatbelt does not registry-lookup package names. Many teams run both.

My org already embeds security in the AI editor at generation time (OX VibeSec). Do I still need Seatbelt?

Respect it. OX Security VibeSec embeds org security context into AI editors at generation time inside org-managed editors (September 2025). That is real prevent-at-source AppSec for teams on a fleet editor stack. Seatbelt is a different moment: a cross-platform ship read on the artifact in git at the push boundary, with optional push gate and a shareable proof link at freelancer handoff. OX does not gate git pushes from Cursor on exported repos, and does not produce plain-English proof anyone can verify. Many enterprise stacks use both: generation-time guardrails in the editor, ship-moment read on what leaves git.

I already have PreToolUse hooks or an agent-control IDE. Why Ship Read?

Respect it. PreToolUse hooks, Cursor beforeShellExecution denylists, and agent-control stacks like Aura (git-native IDE with proof-ledger commits via hooks, July 2026) are real for in-session catastrophic mistakes. Anthropic permissions docs say rules are enforced by the harness, not the model. Session hooks block commands at the harness layer. They do not read the seven-surface build you export. A documented gap: PreToolUse hooks silently skip Bash from subagents spawned via the Agent tool (anthropics/claude-code#43612, closed not_planned May 2026). Terminal commits, other agents, and human pushes can bypass session-only hooks. Seatbelt is a different moment: a cross-platform Ship Read on the artifact in git at the push boundary, with optional push gate and shareable proof anyone can verify at handoff. Many fleet stacks use both: session hooks for blast radius, artifact read for what leaves git. See a repo sample report for ship-moment proof.

Verified by Seatbelt badge

Cleared Ship Reads earn a shareable report and an embed badge. After you clear hard gates, paste this HTML on your site. Visitors who want their own check land on the app with ?ref=badge tracked.

Verified by Seatbelt
Copy embed HTML
<a href="https://app.withseatbelt.com/app?ref=badge" target="_blank" rel="nofollow noopener noreferrer" title="Verified by Seatbelt: independent scan report"><img src="https://www.withseatbelt.com/badge.svg" width="200" height="51" alt="Verified by Seatbelt" loading="lazy" decoding="async" /></a>

Earned badges on cleared reports link to your live proof URL with ?ref=badge, not a static sticker. See the repo sample report or outside-view sample report for lane-matched proof patterns.

For agent fleets

Seatbelt is an enforced human-in-the-loop layer between agents: one agent's output is evidence, not authorization. The next agent builds only after a deterministic seven-surface read. You still approve blocks and accept risks. Wire it once with /seatbelt init on Get started.