Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for Cursor
AI writes code fast and sometimes ships a secret with it. Scan the deployed app and paste our fix prompts straight into Cursor.
Free. No signup. Read-only checks from the outside.
Whatever stack Cursor helped you build, we check what reached production.
Keys and tokens in your built JavaScript, with the file and line.
.env, .git, source maps and backups served by mistake.
Fix prompts stay in English and are written to paste into Cursor's agent.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No. Only the deployed site.
Yes, with the deploy hook on paid plans.
Any public website or web app. Supabase and Firebase get extra checks.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.