VulX Watch - Vibe-code freely. We watch your back

by
The AI that built your app can't verify its own work. VulX Watch can, connect a GitHub repo and it independently reviews what your AI actually shipped, shows you what's vulnerable, and backs every finding with the evidence and the exact line. Read-only, never touches your code, free to try. Keep building fast, and let something independent certify what you made.

Add a comment

Replies

Best
Maker
📌
Hey PH 👋 AI writes most of your app now but the same AI can't tell you if what it shipped is safe. It's marking its own homework. VulX Watch is the independent check. It started as an enterprise product; we're bringing it to the builders who need it just as much, so Watch is free while we build it out. Would love feedback, especially if you build with AI tools: what would make you trust something like this with your repo? — Tomek, Founder of VulX

If you have any questions or feedback I would love to hear it and will try to answer as quickly as possible thank you again for being here

 Super clean landing page! How do notifications work once a vulnerability is found? Can we route alerts to Slack or Email...

 Right now it's email only. When a new CVE lands on a package your app depends on you get a digest from , we check twice a day and dedupe, so no repeat pings. Findings from the code scan itself live in the dashboard. And I completely forgot about Slack if it would be included would you prefer it to be rollups daily or every finding. Open to any suggestions you might have regarding how it should look like.

 sounds great, I think daily rollups would work best for most users, with an option to switch to instant alerts for critical vulnerabilities. all the best for your launch🙌

 Ok sounds good will add this to next rollout list should. This should be live by next week

Sounds very interesting, worth trying as i do vibe coding a lot!

 Thanks a lot. That's exactly what we're going for, letting people build as much as they want, free for now, with the guarantee that whatever you vibe-code gets an independent verification. So you don't have to worry as much about what your AI is producing. Thank you again for this comment and if you have any suggestions on improvements please let us know

This solves a very real problem, especially for small teams shipping AI-generated code without a dedicated security function. Continuous re-checking as new vulnerabilities emerge is far more valuable than a one-time scan. The positioning around "your model can’t audit itself" is sharp and easy to understand.

Great product.

 Thanks means a lot, and you named the exact reason we built it. The "small team shipping AI code with no security function" is precisely who gets left out. Real security tooling is priced for companies with a security budget and those are the people who need it just as much. Appreciate you taking the time 🙏

With the increase of vibe coders and recent surge of vulnerabilities in many packages and libraries, tools like VulX are much needed, excited to try it out

 Thanks 🙏 That surge is what we are going after, more people shipping faster with less ability to verify it. It's free, so give it a run and let me know what you think

Congrats on the launch of VulX Watch! This is a thoughtful idea and I’m excited to see where it goes. 🙌

 Thank you, appreciate the words of support. Any suggestions for improvement?

Great launch, congrats!

 Thank you

Quick update: based off all the feedback we received, we are rolling some massive/exciting changes in the next coming days with a potential relaunch on ProductHunt. Please stay tuned, release notes will be out in the next couple days!