Findings and fixes

Severities and fix deadlines

How VibeLock ranks a finding Critical, High, Medium or Low, the deadline each one sets, and what moves a finding up or down.

Opens at launch. VibeLock is not open yet. This page describes how it will work when it opens, and will change if a decision changes before then.

Every check has a default severity. VibeLock sets it, not the person being checked, and the same severities are printed in the free checklist.

The four severities

Critical, 7 days
Remote, cross-user or unauthenticated exposure of data, secrets or accounts, or code execution. A public storage bucket, one user reading another user’s records, a live secret in the served bundle.
High, 30 days
Serious exposure that needs one condition to be true, or abuse of money, sessions or the model.
Medium, 90 days
Hardening, privacy duties and defence in depth. A missing security header, logs that keep more than they need.
Low, no deadline
Hygiene. Fix it when you are next working in that area.

What moves a finding

Some checks carry a condition. A secret committed to history is high by default, and critical while it still works and the repository is public or shared. A route missing authentication is high, and critical if it grants a session, changes data or opens an admin panel. The condition is printed under the check.

Deadlines and the badge

A critical left open, or a high past its 30 day deadline, means the badge shows your last verified date instead of Verified. Medium and low findings never affect the badge on their own.

You cannot dismiss or downgrade a finding yourself. A Likely critical is cleared by a confirming rescan or by VibeLock review, never by the founder.

Something unclear or out of date? Email hello@vibelock.ai or see the FAQ.