Vibe coding security scanner
Vibe coding security scanner
VibeSafe is a security scanner built for apps made with AI: Lovable, Bolt, Cursor, Replit and v0. It reads the code your AI tool wrote, finds the mistakes those tools repeatedly ship, and tells you in plain English what an attacker could do and how to fix it.
No signup to try · 10 free scans a month with an account · Code is not stored
Why vibe-coded apps need their own scanner
In our study of 400 public repositories built with Lovable, Bolt and v0, 18.5% had committed a .env file. Among the repositories whose source we scanned, 59% had at least one critical issue. These aren't exotic bugs: they're the same few mistakes, made the same way, because AI tools optimise for an app that runs rather than one that holds up when someone probes it.
General security tools can find some of these, but they're built for security teams and bury the critical items in noise. A founder who didn't write the code needs the few things that matter, ranked, in words they can act on.
What the scanner checks
| Check | What it catches in AI-built apps |
|---|---|
| Database access rules | Supabase or Postgres tables without Row-Level Security, policies that only cover reads, and filtering done in app code instead of the database. More on RLS scanning. |
| Secret credentials | Service-role keys, secret Stripe keys, database passwords and private tokens in code that ships to the browser. Keys that are meant to be public are not flagged. |
| Broken access control | API routes that let a logged-in user read or change or delete someone else's record by swapping an ID, and checks that only exist in the UI. |
| Injection and XSS | SQL built from user input, unsafe HTML rendering, and path traversal. |
| Dependencies | Packages with known vulnerabilities, and imports of packages that don't exist, a supply-chain risk when AI invents a name. |
| Live site (Launch Check) | Security headers, HTTPS, CORS, and exposed paths such as /.env or /.git on your deployed URL. Login-protected pages are reported as protected, not exposed. |
How to run it
- In the browser — paste code or connect a GitHub repo at vibesafe.info/try.
- In your editor — the VibeSafe extension for VS Code and Cursor (VS Marketplace and Open VSX).
- In CI — a GitHub Action that scans on every push, or the
vibesafe-scanCLI. - On your live site — Launch Check scans the deployed URL before you announce it.
Tool-specific guides
Each builder has its own habits. These cover what to check for the tool you used:
- Lovable security checklist — Supabase RLS and key handling.
- Bolt.new security checklist — what to check before pointing a domain at it.
- Is Cursor safe? How to secure Cursor — agent auto-run, secrets, MCP servers.
- Replit app security guide — Secrets, visibility and database rules.
Wondering whether building this way is a good idea at all? Read Is vibe coding safe? An honest answer. Comparing tools? See the best vibe coding security scanners.
Questions builders ask
What is a vibe coding security scanner?
A vibe coding security scanner reads the code that AI app builders such as Lovable, Bolt, Cursor, Replit and v0 produce, and flags the security mistakes those tools repeatedly make: exposed secret keys, database tables without access rules, routes that do not check who is calling them, and risky dependencies. VibeSafe explains each finding in plain English with a suggested fix.
How is it different from Snyk or a general SAST tool?
General tools are built for security teams and report many findings in security language. A vibe coding scanner is tuned to the handful of mistakes AI builders make most often and is written for founders who did not write the code. For a large engineering team, a general tool is still worth running alongside it.
Does it flag my Supabase anon key?
No. Supabase anon and publishable keys, Firebase config and publishable Stripe keys are public by design, so VibeSafe does not report them. It does flag service_role keys, secret Stripe keys and other server-only credentials that end up in client code.
Is the scan free?
Yes. A free account includes 10 code scans a month and one Launch Check, with no card required. You can also try a scan without signing up.
Does VibeSafe store my code?
No. Code is analysed and discarded; VibeSafe keeps the findings so you can see your history.
Related: