GuardVibe by goklab

Security MCP for vibe coding. 390 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis for Next.js, Supabase, Clerk, Stripe, Prisma, Drizzle, Hono, GraphQL, AI SDK, MCP, and the full AI-native stack.

ai-securityclaudeclerkcursormcpnextjsowaspprismasastsecuritystripesupabase
Verdict 48/100 health $4.13/mo cheapest, hetzner 3/5 setup difficulty Last release 4 days ago

Self-host GuardVibe on hetzner CAX11 for $4.13/mo.

Health score
48 /100
6-dim composite
Self-hosts from
$4.13 /mo
hetzner · CAX11
Difficulty
3 /5
External DB / setup
GitHub stars
1
0 forks

About GuardVibe

From the project's README at github.com/goklab/guardvibe. Lightly cleaned for readability; for the full source see the upstream repo.

[](https://www.npmjs.com/package/guardvibe) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/goklab/guardvibe/actions/workflows/ci.yml) [](https://www.npmjs.com/package/guardvibe) [](https://codecov.io/gh/goklab/guardvibe)

The security MCP built for vibe coding. 390 security rules, 36 tools covering the entire AI-generated code journey, from first line to production deployment.

Works with Claude Code, Cursor, Gemini CLI, Codex, VS Code (Copilot), Windsurf, and any MCP-compatible coding agent. Why GuardVibe

Most security tools are built for enterprise security teams. GuardVibe is built for you, the developer using AI to build and ship web apps fast. 390 security rules, 36 tools purpose-built for the stacks AI agents generate Zero setup friction, and you're scanning No account required, runs 100% locally, no API keys, no cloud Understands your stack, not generic SAST, but rules that know Next.js, Supabase, Stripe, Clerk, and the tools you actually use CVE version intelligence, detects 23 known vulnerable package versions

Health score breakdown

6-dimension composite. See methodology for formula and weights.

activity
66
maturity
71
community
34
security
85
sustainability
45
adoption
2

Adoption signals

Real-world usage data, pulled from each registry. The bigger the numbers, the more battle-tested the project.

SignalValueSource
GitHub stars 1 github.com/goklab/guardvibe
GitHub forks 0 github.com/goklab/guardvibe
NPM downloads (last month) 10k guardvibe

Release & maintenance

Is this project actively maintained, or about to die? Check the recency of last commit and last release.

Project age0.1 yearssince Mar 2026
Last commit4 days agoMay 3, 2026
Releases shipped132last: 4 days ago
Security policySECURITY.mddeclared by maintainers

Self-hosting cost across providers

Detected requirements: 4GB RAM, 40GB disk minimum. Cheapest plan per provider that meets the requirement.

ProviderPlanSpecsMonthly
hetzner CAX11 2c · 4GB · 40GB $4.13 USD Deploy →
vultr VC2 1c · 1GB · 25GB $5 USD Deploy →
linode Nanode 1GB 1c · 1GB · 25GB $5.12 USD Deploy →
digitalocean Basic Regular 1GB 1c · 1GB · 25GB $6 USD Deploy →

What people say on Hacker News

Replaces these paid SaaS

GuardVibe is one of the open-source alternatives to:

Stripe alternatives Supabase alternatives

Ready to self-host GuardVibe?

Spin up a hetzner CAX11 (4GB RAM, 40GB disk) for $4.13/mo and follow the project's official install docs.

Data last refreshed May 7, 2026.

Similar open-source projects

Projects in our directory that replace the same SaaS or share topics with GuardVibe.

Frequently asked questions

Last verified . Data refreshes every 30 minutes.