Three months ago: Used ChatGPT to build a feature in 3 hours. Felt like a 10x developer. Shipped it. Users loved it.
Last week: Actually read the code. Found hardcoded API keys in my React components. SQL queries begging to be injected. Auth middleware that sometimes just doesn't run.
If this hit production at scale, I would've been done.
The problem
We're all using AI to move faster. But CodeRabbit's research shows AI code has 1.7x more bugs than human code. We're trading velocity for technical debt we don't even see.
Professional code review tools exist. They cost $15-50/month. I'm a student bootstrapping projects. That's not happening.
What I built
CodeVibes - free, open-source AI code auditor that actually explains security issues in plain English.
Priority scanning analyzes critical files first (auth, APIs, database) Real-time streaming shows issues as they're found Vibe Score gives your codebase a 0-100 health metric GitHub OAuth for one-click repo import Your code stays in the session, never stored
Powered by DeepSeek v3.2 with custom security-focused prompts.
Why it matters
If you're indie hacking, you're probably:
Using AI to ship faster
Working solo without code review
Can't afford enterprise security tools
One vulnerability away from losing everything you built
CodeVibes catches the stuff that causes 2am incidents. Exposed secrets, injection vulns, broken auth, insecure APIs.
Early results
50+ repos scanned in beta 68% had critical vulnerabilities 45 second average scan time All caught before production
Still rough around the edges. Working on auto-fix suggestions and Claude integration. But it's already saved me twice from shipping embarrassing bugs.
Try it
codevibes.akadanish.dev - 3 free scans in demo, unlimited with GitHub
github.com/danish296/codevibes - open source, contributions welcome
The reality
AI isn't going away. The move isn't "AI or no AI." It's "AI with guardrails or production incidents."
Built this because I needed it. Open sourcing it because other indie hackers probably do too.
What security checks matter most in your workflow? Always looking for feedback on what would make this actually useful.