Roadmap
What is live, what comes next, and how we decide.
Now (live)
- Security scan of any site or app from the outside: exposed secrets in JavaScript bundles, open Supabase tables and buckets, Firebase rules, exposed files (.env, .git, backups), TLS and certificates, security headers, email DNS (SPF, DKIM, DMARC), domain expiry, blacklists, WordPress core and plugin versions.
- Monitoring and alerts: scheduled re-scans, secret and certificate monitors, alerts by email, Telegram, Slack and webhook, daily or weekly digests.
- Honest grades on hosted builders: Wix, Shopify, Squarespace, Webflow, Framer and Bubble settings the platform controls are shown separately and never lower your grade.
- Verified database backups for Supabase, PostgreSQL and MySQL: one-click Supabase connect, encrypted snapshots, every snapshot test-restored, bring-your-own storage on lifetime plans.
- Restore to a new database or back to the source, full or per table, with download links.
- Fix prompts you can paste into Cursor, Lovable, Bolt or Claude.
Next (the next 3 months)
- WordPress plugin: site heartbeat, file and database backups, one-click restore.
- Firebase backups: Firestore export and Storage files through a service account.
- PDF and JSON reports, public security badge ("Secured by Vigavo").
- Agency workspace: clients, white-label reports, team members.
- More languages for the dashboard and reports.
Later
- Supabase Storage file backups and Auth export as a separate restore option.
- Public API and webhooks for CI pipelines (fail a deploy on a new critical finding).
- Uptime and response-time monitoring.
- Scheduled restore drills with a signed report for audits.
How we decide
We build what beta users ask for most. Tell us with the feedback button on any page.