SafeWeave runs several scanners over your repository. Each finding says which one found it.
Code issues
Looks for code an attacker could use: SQL injection, cross-site scripting, missing sign-in checks, unsafe redirects, weak cryptography and more, across JavaScript, TypeScript, Python, Go, Java, Ruby, PHP and other languages. Free uses a curated rule set; Cloud and Cloud Plus use the full rule registry.
Secrets
Finds API keys, tokens, passwords and private keys committed to your code. Treat any secret it finds as leaked: revoke it with the provider, create a new one, and keep it in an environment variable.
Dependencies
Checks the packages your app uses against known vulnerabilities. It reads package-lock.json, requirements.txt, go.mod and Cargo.lock. The fix is usually to upgrade the package to the version shown.
Infrastructure files
Checks Terraform, Kubernetes, CloudFormation and similar files for risky settings, such as public storage, open firewall rules or missing encryption.
Containers
Checks Dockerfiles and container images for known vulnerabilities and risky settings, such as running as root.
Live web checks
Cloud and Cloud Plus. Sends safe requests to a running app to find common misconfigurations. For your deployed app, use App URLs.
Licenses
Lists the licenses of your dependencies and flags ones that may not suit your project, such as strong copyleft licenses in closed-source software.
Security posture
Checks how your API server is set up: missing authentication middleware, rate limiting, security headers, CSRF protection, request size limits, input validation, CORS that allows every origin, and detailed errors shown to users.
Vibe-coded app checks
Cloud and Cloud Plus. Mistakes common in apps built with Lovable, Bolt, v0, Cursor and similar tools, on Supabase, Firebase, Next.js, Vite, Express and AI features. See Vibe-coded app checks.
Which plans run which checks
| Free | Cloud and Cloud Plus | |
|---|---|---|
| Code issues, secrets, dependencies, infrastructure, containers, licenses, posture | In your editor and terminal, and on your one connected repository | On every connected repository |
| Live web checks | No | Yes |
| Vibe-coded app checks | Counted in your one repository's grade | Yes, with details |