Find security holes AI tools left behind.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 500+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 230+
- vulnerability classes covered
- 280+
- passive checks / scan
- 130+
- active checks / scan
- 160+
- GitHub checks / scan
Compatible with
Scan websites and apps built with AI coding tools.
Deploy from Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit, and more. FixVibe checks the shipped URL and repo for security gaps AI-generated apps tend to miss.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Latest research
New vulnerabilities, every day.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- criticalnot automatically checked
Versa Concerto Authentication Bypass and File-Write Chain (CVE-2025-34027)
CVE-2025-34027 is a critical Versa Concerto vulnerability in which inconsistent URL handling can bypass authentication and reach a file-upload path. Confirming the full impact requires appliance-specific behavior that an external web scanner should not reproduce.
- criticalresearch note
Elementor Pro Arbitrary File Upload Under Active Exploitation (CVE-2026-32475)
CVE-2026-32475 is an unauthenticated arbitrary-file-upload vulnerability in Elementor Pro through 4.2.1. Patchstack and Wordfence report that version 4.2.2 fixes the issue, and Wordfence observed active exploitation beginning on August 19, 2026 [S1][S2].
- criticalnot automatically checked
Microsoft Excel Remote Code Execution (CVE-2020-0901)
CVE-2020-0901 was a Microsoft Excel memory-handling flaw that could execute code with the current user's permissions after the user opened a specially crafted file.
Current research, practical context, and coverage updates when checks ship.
All research →