NPMetaSECURITY
Securing Web Apps, APIs & Vibe Coding Projects

Know how secure your website really is.

Perform safe, passive security posture audits on any public URL. Audit modern web applications, REST APIs, and projects built with AI coding & vibe coding (Claude, Cursor, GPT) before shipping to production.

Quick test:
Safe non-destructive checks•Administrative exposure audit•Role authorization analysis

Passive & Safe

Non-invasive checks only. Evaluates public security headers, certificates, cookies, and CORS policies without state-modifying payloads.

API & Admin Exposure

Audits exposed administrative consoles, config files (/.env, /.git), and checks for Broken Function Level Authorization (BFLA).

AI & Vibe Coding Audit

Audits code generated via Claude coding, Cursor, or AI agents to catch missing CSP headers, exposed OpenAPI schemas, and CORS wildcards.

Actionable Remediation

Provides impact analysis, exact telemetry evidence, and clear copy-paste configuration guidance for Apache, Nginx, and cloud providers.