Code checks

What SafeWeave looks for in your code, in plain words, and which plans include each check.

SafeWeave runs several scanners over your repository. Each finding says which one found it.

Code issues

Looks for code an attacker could use: SQL injection, cross-site scripting, missing sign-in checks, unsafe redirects, weak cryptography and more, across JavaScript, TypeScript, Python, Go, Java, Ruby, PHP and other languages. Free uses a curated rule set; Cloud and Cloud Plus use the full rule registry.

Secrets

Finds API keys, tokens, passwords and private keys committed to your code. Treat any secret it finds as leaked: revoke it with the provider, create a new one, and keep it in an environment variable.

Dependencies

Checks the packages your app uses against known vulnerabilities. It reads package-lock.json, requirements.txt, go.mod and Cargo.lock. The fix is usually to upgrade the package to the version shown.

Infrastructure files

Checks Terraform, Kubernetes, CloudFormation and similar files for risky settings, such as public storage, open firewall rules or missing encryption.

Containers

Checks Dockerfiles and container images for known vulnerabilities and risky settings, such as running as root.

Live web checks

Cloud and Cloud Plus. Sends safe requests to a running app to find common misconfigurations. For your deployed app, use App URLs.

Licenses

Lists the licenses of your dependencies and flags ones that may not suit your project, such as strong copyleft licenses in closed-source software.

Security posture

Checks how your API server is set up: missing authentication middleware, rate limiting, security headers, CSRF protection, request size limits, input validation, CORS that allows every origin, and detailed errors shown to users.

Vibe-coded app checks

Cloud and Cloud Plus. Mistakes common in apps built with Lovable, Bolt, v0, Cursor and similar tools, on Supabase, Firebase, Next.js, Vite, Express and AI features. See Vibe-coded app checks.

Which plans run which checks

Free Cloud and Cloud Plus
Code issues, secrets, dependencies, infrastructure, containers, licenses, posture In your editor and terminal, and on your one connected repository On every connected repository
Live web checks No Yes
Vibe-coded app checks Counted in your one repository's grade Yes, with details