Scanned by VibeSafe on 2026-04-19 — SAST, secret detection, and WCAG 2.1 accessibility audit.
No critical or high severity issues — this repo passes VibeSafe's safety gate.
Stack: css, javascript, python · Detected frameworks: fastapi, flask. 24 secrets flagged (path/entropy-adjusted — docs, test fixtures, and non-code artifacts downgraded).
rules.vibesafe.jwt-no-expiry — 4 occurrencesrules.vibesafe.a11y-html-missing-lang — 1 occurrenceThis scan runs Semgrep OSS rules plus custom rules tuned for AI-generated code patterns. It flags hardcoded secrets (AWS, OpenAI, GitHub tokens, JWTs), SQL injection, eval/exec, path traversal, missing security headers, and WCAG 2.1 Level A accessibility gaps.
Paste your GitHub URL → Free. 30 seconds. No signup. Results include findings with file:line and a copy-pasteable fix prompt for Cursor / Claude.
Paste your GitHub repo URL. Find out in 30 seconds.
Free. No signup. No install.
Public GitHub repos only. Your code stays on our server only during the scan.