Cursor security
Is your Cursor-built app secure?
Cursor writes code that works. Our AI agent checks that it’s also safe, and gives you fix prompts to paste straight back into Cursor.
API route returns any user’s orders without an ownership check
app/api/orders/[id]/route.ts:14
In app/api/orders/[id]/route.ts, the GET handler returns an order by id without checking who owns it. Get the current user from the session, return 401 if there is none, and only return the order if order.userId equals the user's id (404 otherwise). Do not change the response format.
Every finding in your report comes with a prompt like this one.
What we find
The flaws AI-written code tends to leave
An AI assistant does what you ask. Security is usually what nobody asked for.
- critical
Secrets pasted into the code
API keys added “just to make it work”, then committed. Removing them later doesn’t remove them from your Git history.
- high
Missing ownership checks
Routes that take an ID from the URL and return the record without checking it belongs to the logged-in user.
- high
Injection-prone code
SQL built by joining strings, or user content rendered as raw HTML, opening the door to data theft and account takeover.
- high
Outdated or invented packages
Dependencies with known vulnerabilities, or package names suggested by AI that don’t exist and can be registered by attackers.
- medium
Debug settings left on
Verbose errors, debug mode or wide-open CORS that reveal your internals or let any site call your API.
- medium
No limits on costly endpoints
Login, sign-up and AI endpoints without rate limits: easy to brute-force, and easy to run up your API bill.
Free scan or audit?
Two levels of checking
The free scan looks at your live app from the outside. The audit reads your code and your database rules.
Free scan
$0- API keys and secrets shipped in your public JavaScript
- Exposed .env files, Git folders and source maps
- Missing security headers and HTTPS problems
- Which platform and framework your app runs on
Express audit
$99- Every file of your repository, and its Git history for secrets
- Authentication and ownership checks on every route
- Injection risks and unsafe HTML rendering
- Known vulnerabilities in your dependencies
Want to understand it first? Read our guide: Vulnerability scan vs code audit vs pentest
FAQ
Questions, answered
Can’t I just ask Cursor to review its own code?
You can, and it helps. But the same assistant that wrote the code tends to miss the same things. We combine a fixed security checklist, a scanning engine and a separate AI pass, so nothing depends on asking the right question.
Will the fix prompts work in Cursor?
Yes. Each prompt names the file, describes the problem and the expected fix, and asks not to change anything else. Paste it into Cursor’s chat or agent.
Do you need access to my Cursor account?
No. We only need read-only access to your Git repository (or a zip of your code), and we delete it after the analysis.
Which languages do you cover?
Next.js/Node, Laravel/PHP, Python, and Supabase or Firebase backends.
Check your app now
Start with the free scan. Go deeper with the $99 express audit.
Request the express audit