Vibe coding security scanner

Vibe coding security scanner

VibeSafe is a security scanner built for apps made with AI: Lovable, Bolt, Cursor, Replit and v0. It reads the code your AI tool wrote, finds the mistakes those tools repeatedly ship, and tells you in plain English what an attacker could do and how to fix it.

Scan your vibe-coded app free →

No signup to try · 10 free scans a month with an account · Code is not stored

Why vibe-coded apps need their own scanner

In our study of 400 public repositories built with Lovable, Bolt and v0, 18.5% had committed a .env file. Among the repositories whose source we scanned, 59% had at least one critical issue. These aren't exotic bugs: they're the same few mistakes, made the same way, because AI tools optimise for an app that runs rather than one that holds up when someone probes it.

General security tools can find some of these, but they're built for security teams and bury the critical items in noise. A founder who didn't write the code needs the few things that matter, ranked, in words they can act on.

What the scanner checks

CheckWhat it catches in AI-built apps
Database access rulesSupabase or Postgres tables without Row-Level Security, policies that only cover reads, and filtering done in app code instead of the database. More on RLS scanning.
Secret credentialsService-role keys, secret Stripe keys, database passwords and private tokens in code that ships to the browser. Keys that are meant to be public are not flagged.
Broken access controlAPI routes that let a logged-in user read or change or delete someone else's record by swapping an ID, and checks that only exist in the UI.
Injection and XSSSQL built from user input, unsafe HTML rendering, and path traversal.
DependenciesPackages with known vulnerabilities, and imports of packages that don't exist, a supply-chain risk when AI invents a name.
Live site (Launch Check)Security headers, HTTPS, CORS, and exposed paths such as /.env or /.git on your deployed URL. Login-protected pages are reported as protected, not exposed.

How to run it

Tool-specific guides

Each builder has its own habits. These cover what to check for the tool you used:

Wondering whether building this way is a good idea at all? Read Is vibe coding safe? An honest answer. Comparing tools? See the best vibe coding security scanners.

Questions builders ask

What is a vibe coding security scanner?

A vibe coding security scanner reads the code that AI app builders such as Lovable, Bolt, Cursor, Replit and v0 produce, and flags the security mistakes those tools repeatedly make: exposed secret keys, database tables without access rules, routes that do not check who is calling them, and risky dependencies. VibeSafe explains each finding in plain English with a suggested fix.

How is it different from Snyk or a general SAST tool?

General tools are built for security teams and report many findings in security language. A vibe coding scanner is tuned to the handful of mistakes AI builders make most often and is written for founders who did not write the code. For a large engineering team, a general tool is still worth running alongside it.

Does it flag my Supabase anon key?

No. Supabase anon and publishable keys, Firebase config and publishable Stripe keys are public by design, so VibeSafe does not report them. It does flag service_role keys, secret Stripe keys and other server-only credentials that end up in client code.

Is the scan free?

Yes. A free account includes 10 code scans a month and one Launch Check, with no card required. You can also try a scan without signing up.

Does VibeSafe store my code?

No. Code is analysed and discarded; VibeSafe keeps the findings so you can see your history.

An honest note. VibeSafe is a fast pre-launch safety check for the most common risks in AI-built apps. It isn't a penetration test, and it doesn't replace a professional audit for apps handling payments at scale or health data.

Related: