VICE icon

VICE

VICE is a web security auditing tool for indie builders that combines public light scans, verified full audits, and Supabase RLS checks. It helps teams catch exposed headers, TLS issues, leaked secrets, and database policy gaps, with evidence and fixes attached to each finding.

VICE

What VICE does

VICE is a web security auditing tool for indie builders and small product teams. It scans a site the way an attacker would look at it, starting with public checks such as headers, TLS, exposed files, and leaked secrets, then moving into deeper verification for domains you own.

For Supabase projects, VICE adds a dedicated RLS-focused scan that checks what public credentials can actually reach. The product pairs each finding with evidence, a plain-language explanation, and an exact fix, and it can also run in GitHub Actions or on a weekly or monthly schedule.

Core capabilities

Fast light scans

Run public, non-intrusive checks on a site and get a score quickly. The homepage says first results arrive in about a minute.

Domain verification

Verify a domain and then run deeper checks that stay attached to that domain. The site says VICE uses DNS TXT verification and keeps audits, modules, schedules, and findings per workspace.

Supabase Deep Scan

Inspect Supabase-specific risks that generic scanners may miss, including RLS gaps, permissive policies, exposed storage buckets, and edge functions.

AI fixes

Pair each finding with a plain-language explanation and an exact patch that can be pasted into Cursor or a migration.

Security score tracking

Track a score out of 100 over time and show it through an embeddable badge. The homepage describes this as a single number that can be tracked across audits.

CI and scheduled audits

Run audits in GitHub Actions and on a schedule, with the option to fail builds when new critical issues appear and update the score badge automatically.

Where VICE fits

  • Pre-launch sanity check

    Use the free public scan to check headers, TLS, exposed files, and leaked secrets before asking a user to sign up or share data.

  • Supabase security review

    Use the Supabase Deep Scan to look for RLS gaps, permissive policies, exposed buckets, and other issues in a Supabase-backed app.

  • Continuous security checks in CI

    Run VICE in GitHub Actions so each push can surface a new critical issue and update your score badge automatically.

  • Ongoing monitoring

    Schedule weekly or monthly audits to catch regressions and keep a score current without running scans manually.

  • Single-project audit

    Buy a one-off audit credit when you only need a single verified report for one project and do not want a subscription.

Pros and Cons

Pros

  • Offers a free public light scan with no signup needed.
  • Provides evidence next to findings, which helps verify issues before making changes.
  • Includes Supabase RLS-specific checks rather than only generic web security signals.
  • Supports CI and scheduled audits for ongoing monitoring.
  • Includes one-off audit credits for teams that only need a single pre-launch check.

Cons

  • Deeper checks only unlock after domain verification, so the product is not a fully anonymous deep scanner.
  • The source pages do not list every integration or workflow detail, so some deployment options and outputs are not fully documented here.

FAQ

Do I need an account to run a scan?

VICE offers public light scans without an account, and verified full audits after domain verification. The pricing page also says the free tier keeps working if you cancel.

What does the light scan check?

The site says the light scan checks public signals only, including security headers, TLS, robots.txt, security.txt, exposed files, and secrets leaked in public JavaScript. It does not authenticate, intrude, flood, or mutate anything.

Can VICE be used in CI?

Yes. The pricing page says VICE can run in GitHub Actions, audit on every push, fail the build when a new critical appears, and update the score badge automatically.

How does the Supabase Deep Scan work?

For Supabase projects, VICE saves the project URL and anon key once per domain, then checks what those public credentials can reach, including tables without RLS, permissive policies, exposed storage buckets, and edge functions.

What pricing options are available?

The pricing page offers a free public light scan, monthly Solo and Pro plans, and one-off audit credits. It states that Solo and Pro are monthly with no lock-in, and credits stay valid for 12 months.

Quick Facts

Category
Web security auditing
Primary users
Indie builders and solo makers
Public scan
Available without signup
Paid options
Monthly plans and one-off audit credits
Notable workflow
GitHub Actions and scheduled audits
Source domain
vice-platform.com

Alternativas a VICE

ByteAsk icon

ByteAsk

ByteAsk is a terminal-first AI coding agent for C and C++ that edits repositories and verifies changes with the real compiler, debugger, sanitizers, and tests before showing a diff. It offers a free tier plus paid plans, with editor connectors and zero-retention handling described in the source.

Manta AI icon

Manta AI

Manta AI is an autonomous web app testing tool for teams that want to map application behavior, catch regressions, and generate tests without writing scripts or maintaining selectors. It works from a URL and supports plain-English test flows, run results with screenshots, and scheduled or deployment-triggered checks.

PromptScout icon

PromptScout

PromptScout tracks how ChatGPT, Gemini, Google AI Overviews, and Perplexity mention your brand or competitors, then pairs those results with source analysis and website audits. It helps teams decide what to fix in content, positioning, or site readiness next.

CreateOS Sandbox icon

CreateOS Sandbox

CreateOS Sandbox is an isolated compute environment for running code and agent workloads inside Firecracker micro-VMs. It is designed for workflows that need machine-level isolation, private networking between sandboxes, and programmatic control through SDK, CLI, or MCP.

Sleek Analytics icon

Sleek Analytics

Sleek Analytics is a privacy-friendly web analytics tool with real-time visitor tracking, Core Web Vitals, and revenue attribution. It helps site owners understand traffic and conversions without cookie banners or a heavy setup.

hob icon

hob

hob is an independent workspace for coding agents that keeps agent sessions, terminals, history, and follow-up work organized around the tools and providers you already use. It is aimed at developers who want local control over routing, history, and workspace structure rather than a bundled model stack.