One scan · browser, agent, or CI

Finished. Safe.
Ship it.

Wardloom is a defensive pre-ship check for vibe-coded apps. One read-only scan answers the two questions that matter: is it actually done, and is it safe to launch — across twelve security families, SEO, GEO, and health. Run it here, from your AI coding agent, or as a CI gate.

CRITICAL · F-101

API key found in client bundle

src/lib/ai.js · line 12

  • Hardcoded secrets & API keys
  • CORS & origin policy
  • Security headers
  • Dependency CVEs
  • Env & config exposure
  • Auth, sessions & IDOR
  • Debug artifacts & source maps
  • LLM & agent security
  • Traffic & legal signals (advisory)
  • Verified-deployment live checks
  • SEO · GEO/AEO · Core Web Vitals

We audit everything
the AI forgot to mention.

Twelve security families mapped to the OWASP Top 10, plus deterministic SEO, GEO/AEO, and Core Web Vitals. Verify control of your domain and eight live deployment checks unlock on top. Everything stays read-only and defensive, on code and deploys you own.

Field notes

Coverage with
a craftsman's rigor.

Four notes on SEO, GEO, AEO, and launch readiness. Read them before you ship.

Built for people who build faster than they audit.

Secret-aware

Deterministic patterns plus contextual AI review catch keys the model left in the client.

Verified deployment

Prove domain control and eight live checks open up: TLS, HTTPS, dangling DNS, exposed routes.

URL, repo, or paste

Live URLs get a read-only probe. Repos add a completion audit. Pasted code is never stored.

In your agent & CI

An MCP server for Claude Code and Cursor, plus a GitHub Action that gates your build.

Fix-first reports

Roadmap, guided fixes rescanned to confirm, Dev/AI handoff prompt, PDF and HTML export.

The last gate
before launch.

Renaissance group scene of careful builders
OWASPTop 10 mapped
Read-onlyAnalysis, never executed
12Security check families
8Live checks after domain verification
4Launch Confidence pillars: security, SEO, health, GEO
Growing dailyJoin the watch

Know it's finished. Know it's safe.

Classical pastoral landscape painting, calm before a safe launch

Peace of mind, by design,
is rare & precious.

We surface what matters: leaked keys, wildcard CORS, missing headers, ownerless endpoints, prompt-injection sinks, and weak SEO or GEO signals. Ship-Readiness is earned, not assumed — and it never reads higher than your security score while a critical finding is open.

Read the field notes →

Findings, fixes &
lessons worth keeping.

Every report reads like a field guide: what broke, why it matters, the roadmap to fix it, a handoff prompt for your AI coding tool — and an honest account of what was never tested.

Explore field notes →

“The aim of the wise is not to secure pleasure, but to avoid pain, and in doing so, to attain the greatest calm.”

Epicurus, on why you should scan before deploy

Field notes

Questions careful
builders ask.

Browse the field notes →

Start your journey to a finished, safe launch.