Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- No signup required
- 230+ passive checks per scan
- BaaS-aware
- Auth-safe (passive)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example Β· not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: βVerified for this page and header.β The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
Scanner coverage
- 240+
- vulnerability classes covered
- 230+
- passive checks / scan
- 130+
- active checks / scan
- 190+
- GitHub checks / scan
Compatible with
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS security
Supabase RLS scanner: find tables with missing or broken row-level security
Row-level security (RLS) is the only thing standing between your customers' data and the internet when you ship a Supabase-backed app. AI coding tools generate RLS-shaped code that compiles, ships, and silently leaks data β tables created without RLS enabled, policies that read but never restrict, predicates that compare a column to itself. This article shows what a Supabase RLS scanner can prove from the outside, the four broken-RLS shapes that show up in vibe-coded apps, and how to scan your own deployment in under a minute.
- BaaS security
Supabase service role key exposed in JavaScript: what it means and how to find it
The Supabase service role key is the master key to your database. Anyone holding it bypasses Row-Level Security, can read every column of every table, and can write or delete anything they choose. It is designed to live exclusively in server-side code β never in the browser. When an AI coding tool ships it to the JavaScript bundle, your database is, in effect, public. This article explains the JWT shape that identifies a leaked key, the three AI-tool patterns that produce the leak, what to do in the first hour after detection, and how to scan for it automatically before users do.
- BaaS security
Firebase rules scanner: find open Firestore, Realtime Database, and Storage rules
Firebase apps fail security in one consistent way: allow read, write: if true; rules left over from the test-mode quickstart, never replaced before production. AI coding tools generate these rules verbatim from documentation examples and rarely prompt the developer to harden them. This article shows how a Firebase rules scanner detects open rules across Firestore, Realtime Database, and Cloud Storage from outside the project β and how to fix what it finds.
- Security guides
The vibe coding security checklist: 51 items before you ship
A practical, phase-organised checklist for apps built with Cursor, Claude Code, Lovable, Bolt, v0, Replit, and Windsurf. Each item is actionable in under five minutes. Run through it before you push to production, then again before each major release. Items are grouped into seven categories β secrets, database, auth, headers, third-party, deployment, monitoring β and tagged with the deploy phase they apply to.
- Security guides
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- Security guides
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
