Is your app shipshape?
You built something brilliant. Now make sure it's ready for the open water. Seaworthy scans your project for security gaps, misconfigurations, and exposed secrets before you hit deploy.
Runs from your terminal, VS Code, or your AI coding agent (Claude Code, Cursor, Windsurf).
Built for builders who move fast
You're a vibe coder. You ship on intuition and iteration. Seaworthy is your first mate — a quick pre-launch scan that catches the stuff you didn't think to check: leaked API keys, missing security headers, exposed secrets, and misconfigurations that could bite you after you go live. Everything runs locally on your machine. For LLM-assisted checks you bring your own API key — we never touch your code or bill you for AI usage.
Now your AI agent can run the scan too. Nearly half of AI-generated code ships with security vulnerabilities, and most developers say they don't fully trust AI output — Seaworthy's MCP server puts a pre-deploy security check inside your agent's loop, so you can ship what it builds with confidence.
Supported Languages
Seaworthy analyzes code across 13 major programming languages, frameworks, and configuration syntaxes. We support full taint tracking for runtime environments and static AST checks for markup, styles, and configs.
⚡ Runtime & Backend (Full Taint Tracking)
📁 Configuration & Static (AST Scanning)
What we check
Seaworthy runs a suite of automated checks — no manual steps, no config files needed.
Security
Hardcoded secrets, committed .env files, missing auth, permissive CORS, SQL injection surfaces, and sensitive data appearing in logs.
Resilience
Rate limiting gaps, missing input validation, unhandled errors, missing pagination, no HTTP timeouts, and absent retry logic on critical calls.
Ops Basics
Missing health check, hardcoded localhost URLs, debug mode left on, unstructured logging, and no graceful shutdown handling.
Dependency Hygiene
Known CVEs in dependencies, missing or outdated lockfile, dev dependencies bundled into production, and floating version pins.
Configuration
Secrets hardcoded in source files, no separation of environment configs, and default credentials left unchanged.
Data Exposure
Verbose error messages leaking internals, PII returned in API responses, and no response filtering on list endpoints.
Three steps to clear skies
Run the scan
One command, zero config. npx seaworthycode [path] — scans your project locally and privately. Or just ask your AI agent to run it.
→Review findings
Categorised, severity-ranked report in your terminal, browser, or editor. Clear, prioritised, no noise.
→Ship with confidence
Fix the gaps before they reach production. Know your app is seaworthy before you deploy.
Your agent writes the code. Seaworthy checks it.
Seaworthy ships a built-in MCP (Model Context Protocol) server, so your AI coding agent can run a security scan without leaving its loop. Everything runs locally — only license authentication ever touches our servers.
Agent calls scan
Your agent invokes the scan tool on the directory it's working in — no terminal, no context switch.
→Reads the findings
Compact, prioritised findings land straight in the agent's context: leaked secrets, missing auth, insecure patterns.
→Fixes and re-scans
The agent fixes the code and re-scans until it's clean — security becomes part of the loop, not an afterthought.
Works with the agents you already use
Add Seaworthy to your MCP config
Pick your plan
Start free. Upgrade when you need the full picture.
Every plan includes: CLI · VS Code extension · MCP server
Free
- ✓Core security checks (~12)
- ✓Unlimited projects
- ✓Secrets & CVE detection
- ✓No account needed
Pro
- ✓Full check catalog + BYOK LLM*
- ✓Unlimited projects
- ✓Auth, rate limits & resilience
- ✓HTML + JSON reports
* LLM checks run using your own agent with your key.
Ready to set sail? 🌊
Run your first scan free. Drop it in your terminal or install the VS Code extension — no account needed.
💻 CLI (npx)
Runs in any project directory. No install needed.
🔌 VS Code Extension
Scan from inside your editor, with inline findings.
🤖 AI Agents (MCP)
Let Claude Code, Cursor, or any MCP client run the scan for you.