new: drive vas from your AI agent over MCP · Cursor, Claude Code, Windsurf
Coverage

Every check we run. All 33 of them.

Free scanners fetch one page and grade its headers. vas tests your running app: database policies, auth flows, APIs, secrets, and the rest of what actually leaks customer data. Here is the complete list.

Every plan runs every check below. Plans differ in scan quota, deep scans, and monitoring, not coverage. See pricing

Security

The core of every scan. These checks test your running app the way an attacker would: your database policies, your auth endpoints, your APIs, and the JavaScript you ship to every visitor.

Database and backend

Database Security

Tests Supabase, Firebase, Convex, MongoDB, and PostgreSQL configurations with your own public keys to find tables and collections a stranger could read or write.

API Data Exposure

Detects unauthenticated APIs exposing PII, credentials, financial data, and other sensitive information.

SQL Injection Detection

Tests API endpoints and forms for SQL injection vulnerabilities using safe detection payloads.

GraphQL Security

Finds GraphQL endpoints and tests them for introspection exposure, field-suggestion leakage, query batching, and unauthenticated access to sensitive data.

tRPC Security

Discovers and probes tRPC endpoints for authentication bypass, admin access, and information disclosure.

ORM Security

Checks for Prisma and Drizzle ORM misconfigurations, exposed schemas, and client-side usage.

Authentication and access control

Authentication Security

Checks authentication endpoints, analyzes auth patterns, and evaluates how your login flow holds up.

Authenticated Testing (Pro deep scan)

Logs into your app with a test account and tests for IDOR, broken access control, and privilege escalation: can one user reach another user's data?

Password Policy

Tests password complexity requirements on Supabase, Firebase, or generic signup endpoints.

JWT Weakness

Tests whether your session tokens can be forged using common AI-generated secrets like "supersecretjwt".

Rate Limit Detection

Detects missing or weak rate limiting on auth and API endpoints that leaves you open to brute force and abuse.

Secrets and exposed code

Secrets Scanner

Scans your HTML source, JavaScript bundles, and discovered pages for exposed API keys and secrets, with 150+ patterns for OpenAI, Anthropic, Stripe, AWS, and more.

Payment Platform Security

Detects exposed payment secrets for Stripe, Paddle, LemonSqueezy, Polar, and Dodo Payments.

Exposed Files

Checks for exposed configuration files, .env files, .git folders, and other sensitive paths reachable from the web.

Source Map Exposure

Detects publicly downloadable JavaScript source maps (.js.map) that reveal your original source code, internal logic, and secrets.

Vulnerable Dependencies

Detects known-vulnerable versions of common front-end libraries (jQuery, Lodash, Moment, Axios, Bootstrap, AngularJS, Next.js) in your served bundles and flags published CVEs.

Headers, transport, and configuration

HTTP Security Headers

Analyzes HTTP headers for security misconfigurations: HSTS, CSP, X-Frame-Options, and the rest.

SSL/TLS Security

Checks SSL certificates, TLS versions, cipher suites, and mixed content.

Security Misconfiguration

Detects CORS misconfigurations, debug mode left on, WebSocket security issues, third-party script risks, and browser storage abuse.

Client-Side Security

Analyzes client-side JavaScript for XSS sinks, postMessage vulnerabilities, prototype pollution, and template injection.

Form Security

Analyzes discovered forms for CSRF protection, autocomplete settings, and secure transmission.

Platform-aware checks

Platform Fingerprinting

Identifies your hosting platform, framework, and AI code generation tool so every other check can apply platform-specific tests and fixes.

Crawler

Discovers URLs, forms, API endpoints, and technologies via browser-based crawling, so checks run across your app rather than one page.

AI/LLM Security

Detects AI integrations, MCP servers, and LLM tool misconfigurations.

Netlify Security

Checks Netlify Functions, Edge Functions, Identity, deploy previews, and platform-specific vulnerabilities.

Bubble.io Security

Checks Bubble Data API exposure, Workflow API, privacy rules, and platform-specific misconfigurations.

Email and identity monitoring

Email Security

Checks SPF and DMARC DNS records to assess whether attackers can spoof email from your domain.

Breach Monitoring (Pro)

Checks whether your email appears in known data breaches via Have I Been Pwned, and keeps watching.

SEO

A vulnerable app is one problem. An invisible one is another. Every scan includes on-page SEO health.

SEO Health

Passive on-page SEO checks: title, meta description, canonical, H1, Open Graph, JSON-LD, noindex, plus robots.txt and sitemap presence.

AI search readiness (AEO/GEO)

More buyers ask ChatGPT and Perplexity than ever. These checks tell you whether AI answer engines can see and cite your app.

AI Visibility (AEO/GEO)

Checks AI answer-engine visibility: llms.txt presence, robots.txt rules for AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended), JSON-LD structured data, and meta description.

Accessibility

Basic accessibility failures cost you users and, in some markets, invite legal risk.

Accessibility

Checks WCAG basics: page language, zoom disabled, missing image alt text, unlabeled form inputs, icon-only buttons and links, and heading structure.

Compliance

The legal basics AI tools routinely skip when they generate your app.

Compliance

Checks legal presence: privacy policy, terms of service, cookie consent when trackers are present, and security.txt (RFC 9116).

Performance

Slow apps lose customers before security ever matters.

Performance

Lightweight performance checks: server response time (TTFB), text compression, static asset caching, render-blocking resources, large images, and oversized DOM.

The deep scan goes where quick scanners can't

On the Pro plan, a weekly deep scan logs into your app with a test account and tries to reach other users' data across up to 150 pages: IDOR, broken access control, and privilege escalation. That is the class of bug that turns into a breach headline, and no header check will ever find it.

Compare plans

See what all 33 checks find on your app

Your first scan is free. Full coverage, results in 2-3 minutes, no card required.