VibRadar is a small independent security tool. It scans the public surface of a website, the part anyone on the internet can already reach, and flags things that should not be exposed: open databases, leaked API keys, downloadable config or source files, and outdated frameworks. Then it shows exactly where the problem is and how to fix it. Sites shipped quickly with AI and vibe-coding tools tend to leave more of these open, so that is where we look most.
We run automated external scans across the web. When we find a real exposure on a site, we send a short, one-time note to a contact address listed on that site, with a link to a free report. That is it. We are not selling fear and there is no pressure. If the issue is already handled, you can ignore the email. If you would rather not hear from us, reply and we will stop.
The scan is fully read-only. We only request pages and files that are already public. We never log in, never change anything, never run exploits, and never touch anything behind authentication. A finding simply means that data was reachable by anyone at the moment we looked. Because it is automated and external, it is best-effort: it will not catch everything, and a clean result is not a guarantee that a site is secure.
We store the domain and the finding so we can show you the report and re-scan later if you ask us to. We do not sell your data, and we do not publish or share findings. The full report is a one-time purchase; the first finding is always free so you can verify it yourself.
VibRadar is an independent project run by a small team focused on making these exposures easy to find and fix before someone less friendly does. Questions or feedback are welcome through the contact form.