What shipped today:
— Paddle webhook handler built and working. When someone pays, their GitHub installation ID is written to a private JSON file automatically. Next PR they open, the bot runs the security scan. Zero manual intervention.
— Paddle checkout is live. Tested end to end. The flow works: private repo PR → subscription prompt → payment → auto-activation → security scan on next PR.
— GitHub Marketplace submission sent. VrothSec is now pending review under the Security category.
The full product in one paragraph:
VrothSec installs on your GitHub repo and reviews every PR for AI and cloud security issues — hardcoded API keys, overpermissioned IAM, unsafe S3 configs, missing rate limits on AI endpoints, prompt injection risks, sensitive prompt logging. Free for public repos. $15/month for private repos. Install once, runs forever.
What’s next:
10 founding member spots still open at $15/month, locked in forever: https://vrothsec.vercel.app
Install now (free for public repos): https://github.com/apps/vrothsec