Vibe code security
Vibe code security, checked by an AI agent
Lovable, Bolt, Replit, v0, Cursor: AI tools ship fast, not safe. Check your vibe-coded app for leaked keys, open databases and unprotected APIs.
OpenAI secret key exposed in the browser bundle
src/lib/ai.ts:3
In src/lib/ai.ts, the OpenAI secret key is used directly in code that runs in the browser. Move the OpenAI call to a server route (or edge function) that reads the key from a server-side environment variable, and call that route from the front-end instead. Then remind me to revoke and replace the old key.
Every finding in your report comes with a prompt like this one.
What we find
What goes wrong when you ship at AI speed
- critical
Leaked API keys
Secret keys in the front-end or the Git history. Someone finds them, and you find out from your bill.
- critical
Open databases
Supabase tables without Row Level Security, or Firebase rules still in test mode, readable by anyone.
- high
Unprotected API routes
Endpoints that anyone can call, or that return other users’ data when you change an ID.
- high
Checks that only happen in the browser
Paywalls, plan limits and admin rights enforced in the interface, but not on the server.
- medium
Vulnerable dependencies
Outdated packages with public vulnerabilities, pulled in without anyone noticing.
- medium
Abusable AI features
AI endpoints with no rate limit or login check: anyone can use your credits.
Free scan or audit?
Two levels of checking
The free scan looks at your live app from the outside. The audit reads your code and your database rules.
Free scan
$0- Your platform (Lovable, Bolt, Vercel, Netlify…)
- Secret keys leaked in your public JavaScript
- Exposed .env files, Git folders and source maps
- Missing security headers and HTTPS problems
Express audit
$99- Your whole codebase and its Git history
- Database rules: Supabase RLS or Firebase rules
- Authentication and ownership checks on every route
- Dependencies, AI endpoints and server-side checks
Want to understand it first? Read our guide: Vulnerability scan vs code audit vs pentest
FAQ
Questions, answered
I’m not a developer. Will I understand the report?
Yes, it’s written for you. Each finding says what’s wrong, what could happen, and gives you a prompt to paste into the tool you built with.
Which AI tools do you cover?
Apps built with Lovable, Bolt, Replit, v0, Cursor or Windsurf, as long as they run on Next.js/Node, Laravel/PHP, Python, Supabase or Firebase.
Is vibe-coded software less secure?
Not by nature, but it’s built fast and often without a security review. The same mistakes come back again and again, which is why they’re easy to find and fix.
What does the free scan cost me?
Nothing. No signup, no card. You get your score and the external findings by email.
Check your app now
Start with the free scan. Go deeper with the $99 express audit.
Request the express audit