← ALL DOCS

FAQ & TROUBLESHOOTING

Short answers to the questions support hears most. If yours is not here, email support@vibe-eval.com or use the chat widget in the app.

Where to look first

  • Scan status help — hover the status badge on any scan for a one-line explanation. Definitions are listed under Running scans.
  • On-call review note — the card at the top of a completed scan says what the reviewer confirmed and what was out of scope.
  • Report inaccuracy — on the scan header; the fastest way to get a detection issue in front of the team.

Common situations

Findings look preliminary

While a scan is in review, findings carry a Preliminary badge and may change. Wait for the review email before filing tickets. See Findings.

The scan tested fewer pages than expected

Give the crawler a Sitemap URL in the Target step, raise Crawl depth in Options, widen Scan scope to the whole domain or subdomains, and make sure Excluded paths is not too broad. Pages behind login need Authentication set.

An API is missing from the results

Use the API Scan profile and supply an OpenAPI/Swagger URL, or add the base path to the target. GraphQL endpoints are discovered from the app’s network traffic; an endpoint the frontend never calls will not be found without a spec.

I want to hide a finding I have accepted

Use Ignore to hide it in your own browser, or set the status to False positive to exclude it for the whole team and from the risk score.

A teammate cannot see the organization

Check Team for their status: Pending means the activation link has not been used; Deactivated means access was revoked. Roles change on next login. See Team and roles.

Contact

Email support@vibe-eval.com or open the chat widget in the bottom-right corner of the app. Sales and enterprise questions: contact sales.

COMMON QUESTIONS

01
My URL was refused. Why?
The host is not publicly routable (localhost, private IP, .local), is on a restricted TLD such as .gov, or is on the denylist. Deploy to a public preview URL and try again. Full rules on the Targets page.
Q&A
02
The scan has been 'pending review' for a while. Is it stuck?
No. Pending review means the automated pass finished and a security researcher is verifying findings by hand. Review time depends on queue depth and app size; you get an email the moment it completes and findings are final.
Q&A
03
Why did a finding disappear after review?
The reviewer determined it was a false positive or duplicate and removed it. The review note on the scan page explains what was checked and what was out of scope.
Q&A
04
I fixed the issue but Retest still shows it open.
Confirm the fix is deployed to the exact URL that was scanned, not a preview. Check for CDN caching of the vulnerable response. If the retest is still wrong, use Report inaccuracy on the scan.
Q&A
05
Why can't I claim a badge?
The latest completed scan must score 15 or lower and your organization must not already hold a badge. Fix the highest-severity findings, re-run, and claim from the review card.
Q&A
06
Will scanning slow down or break my app?
Scans are production-safe by default and rate-limited to 50 requests per second, which you can lower. Use Passive only and Excluded Paths for sensitive routes. Destructive payloads are never sent unless explicitly enabled.
Q&A
07
How do I delete my data?
Archive or delete scans from the scan page, remove targets from Targets, and request a full export from Settings → Data before you go. For account deletion or a GDPR request, email support@vibe-eval.com.
Q&A

SEE IT ON YOUR OWN APP

Docs explain the product. A scan shows you what it finds on your deployed URL — keys, RLS, auth, and API gaps in under 60 seconds.

14-day free trial · No credit card · Cancel anytime

START FREE SCAN