FREE REPO SCANSECURITY FOR VIBE CODERS

Ship fast.
Don’t ship exposed.

Your idea is ready for the world. Make sure your app is, too. Find the security oversights. Get the fix. Keep shipping.

Connect GitHub for one free scan. No card.

A LOOK INSIDE YOUR REPORT
clod / security-reportSAMPLE

SECURITY / OVERVIEW

Your next steps, clearly.

REPOyou/your-appEXAMPLE DATA
CRIT

Privileged key in client code

A secret credential belongs on the server.

MED

Content security policy missing

Set boundaries for what the browser can load.

A CLEAR NEXT STEP01

Move privileged credentials to server-only code. Rotate any key that was exposed.

Run it on your repository

Real context. Specific fixes. No mystery score.

MADE FOR THE STACK
YOU ALREADY SHIP WITH

SupabaseVercel

01 / THE BLIND SPOTS

It works.
But what did you miss?

AI can help you build fast. Security details can still slip through. Here’s what Clod checks in your repository — once for free when you connect GitHub, and on every push with the PR bot.

{ }01

Secrets in plain sight

Catch privileged credentials bundled into the JavaScript your app sends to browsers, or published through NEXT_PUBLIC_ variables.

CLIENT-SIDE CREDENTIALS
</>02

Missing guardrails

Review security headers that help protect your app against common browser-based attacks.

SECURITY HEADERS
$03

Webhooks anyone can call

Find Stripe webhook routes that act on a payload without verifying its signature first.

STRIPE WEBHOOKS
[ ]04

Database blind spots

Find Supabase tables your migrations create without ever turning on row-level security.

SUPABASE RLS
alt=05

Doors nobody can open

Find the controls, links and images that a screen reader cannot name, so the people using one aren’t locked out.

ACCESSIBILITY MARKUP
Set-Cookie06

Cookies scripts can read

Find session cookies your server code sets without httpOnly or secure, so a script on the page can’t walk off with them.

COOKIE FLAGS

02 / FROM REPO TO FIX

A shorter path
to a safer ship.

Start free on your repo.
Stay covered on every push.

  1. 01

    Connect GitHub

    Install the Clod app on the repository you want checked. No card.

  2. 02

    Get one free scan

    Clod scans that repository right away and reports findings by severity, with evidence.

  3. 03

    Add the PR bot

    Subscribe to scan every push and get a pull request with the fix.

03 / SIMPLE BY DESIGN

Your next launch.
Fewer loose ends.

Connect GitHub and scan your repository once for free. When you want every push checked and the fix written for you, add the PR bot.

FREE SCANNO CARD
Freeone scan, one repository
  • Runs as soon as you connect GitHub
  • Every check the PR bot runs
  • Evidence behind every finding
  • Reports only — opens no pull requests
Scan your repo free
PR BOT · INDIEEVERY PUSH
$19per month, one repository
  • Scans your repository on every push
  • Opens a pull request with the fix
  • Secrets, Supabase RLS, Stripe webhooks, headers, cookies
  • Starts with the free scan when you install
Get the PR bot

Connecting GitHub is the only setup.

04 / STAY IN THE LOOP

Get notified about new checks.

An email when Clod adds new checks. No charge, no commitment.

Free. We’ll only email you about product updates.

A FEW THINGS TO KNOW

Before you ship.

Can I run a real scan today?

Yes. Connect GitHub and Clod scans your repository straight away, once, for free.

What does the free scan cost me?

Nothing. Installing the Clod app on GitHub gives you one free scan of one repository. It reports findings and opens no pull requests. Scanning every push, with fixes, is the PR bot.

Does a clean report mean my app is secure?

A report covers the checks that ran, not every possible vulnerability. Clod is designed to catch common oversights and explain fixes; it does not replace a full security review.