Vigavo for Cursor

Coded with Cursor?We stay awake.

AI writes code fast and sometimes ships a secret with it. Scan the deployed app and paste our fix prompts straight into Cursor.

Free. No signup. Read-only checks from the outside.

What we check on Cursor

Whatever stack Cursor helped you build, we check what reached production.

  1. Secrets that slipped out

    Keys and tokens in your built JavaScript, with the file and line.

  2. Files left online

    .env, .git, source maps and backups served by mistake.

  3. Prompts for Cursor

    Fix prompts stay in English and are written to paste into Cursor's agent.

Everything a small team forgets to check

Findings ranked by what an attacker would try first, with the fix right next to each one.

Scan like an attacker, safely

Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.

Watch for changes

Scheduled scans compare against the last result, so you hear about a new leak once, not every day.

Backups that restore

Encrypted database snapshots, verified by an actual restore and row counts.

Fix prompts

Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.

Alerts without noise

Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.

Questions

Do you read my repository?

No. Only the deployed site.

Can I run a scan after every deploy?

Yes, with the deploy hook on paid plans.

Which stacks are supported?

Any public website or web app. Supabase and Firebase get extra checks.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

What do you store?

The scan result. Free scans are deleted after 30 days.

Feedback
Type