Security, performance & SEO
all in one place. Built for vibecoders.
Passive security scans in under five seconds, Core Web Vitals, SEO & AEO, accessibility audits, stack profiling, and uptime monitoring — one dashboard, with MCP support for your AI coding tools.
Project: api.vergate.dev
Last scan: 2 minutes ago
Everything your site needs.
One platform.
Security scanning, performance monitoring, SEO optimization, accessibility audits, and more — built for the vibecoder workflow.
Passive Scanning
50+ checks — headers, CORS, cookies, exposed files, server disclosures — with results in under 5 seconds.
Active Scanning
SQL injection, XSS, open redirects — active scans run in isolated ephemeral containers, destroyed after every scan.
OpenAPI Discovery
Auto-discovers your spec, parses endpoints, and injects them into the active scanner. Zero manual config.
Technology Profiling
50 detectors plus WhatWeb's 1,800+ plugins identify your stack, hosting, CDN, and analytics.
10 Integrations
GitHub, Vercel, Netlify, Supabase, Cloudflare, Firebase, Railway, Stripe, Fly.io, Render — each with provider-specific security analysis.
Performance Analysis
Core Web Vitals — LCP, TBT, CLS, FCP, SI — plus 11 resource quality checks, with AI fix suggestions for every failing metric.
SEO & AEO Analysis
20+ SEO checks with real browser rendering for JS-heavy SPAs, plus 26 AEO checks for GPTBot, ClaudeBot, and PerplexityBot.
Accessibility Audits
WCAG 2.1 AA via axe-core — contrast, ARIA, semantics, keyboard navigation — grouped by impact.
Email Deliverability
9 weighted DNS checks — SPF, DKIM, DMARC, MX, MTA-STS, DNSSEC, BIMI, DANE — each with a pass/fail/warn verdict.
Integration Security
Scans connected providers for misconfigurations — branch protection, SSL modes, env var exposure, API key hygiene, WAF rules.
MCP Integration
17 tools for Claude Code, Cursor, and Windsurf — scan, profile, verify, and audit directly from your editor. stdio + HTTP transports.
Uptime Monitoring
60-second health checks with downtime alerts, plus passive re-scans that catch regressions before they reach users.
Built for the modern API terminal.
Run scans from your shell, wire them into CI/CD, or connect via MCP — 17 tools for AI coding assistants.
curl -X POST https://api.vergate.dev/api/v1/scan \
-H "Authorization: Bearer pk_live_..." \
-H "Content-Type: application/json" \
-d '{"url": "https://yourtarget.com", "max_depth": 2}'
From shipped to verified in minutes.
No agents, no setup. Point Vergate at a URL or repository and let it work.
Point it at your project
Add a URL or repository. The passive scan starts within seconds — no agent, no config, no credit card.
Get the full picture
Security, Core Web Vitals, SEO & AEO, accessibility, and stack profiling run against your live site in isolated containers.
Stay green
Fix what matters, verify it stays green, and show it off with a Vergate Verified badge.