// docs / security guides
Security guides
In-depth, framework-aware guides for securing applications built with Cursor, Claude Code, Lovable, Bolt, v0, Replit, and Windsurf. Each guide is written to stand alone — pick the one that matches what you're doing right now. More guides land here as new attack classes show up in the FixVibe scan engine.
// category overview
AI-generated code security scanning: DAST for vibe-coded apps
Why AI-generated apps need different scanning than traditional pentest tools. Covers the ten vulnerability classes that show up disproportionately in vibe-coded apps, DAST vs SAST when the codebase is half-machine-generated, what to look for in a scanner, and how FixVibe compares to Burp Suite, OWASP ZAP, and Nessus.
Read the scanner primer →
// pre-ship audit
The vibe coding security checklist: 51 items before you ship
A practical, phase-organised checklist for apps built with Cursor, Claude Code, Lovable, and Bolt. Seven categories — secrets, database, auth, headers, third-party, deployment, monitoring — with 51 actionable items, each tagged pre-deploy / at-deploy / post-deploy.
Open the checklist →
// step-by-step
How to secure an app built with AI coding tools
Step-by-step hardening with code snippets. Why AI-generated apps fail differently, an immediate codebase audit, deploy-time hardening (middleware, CSP, RLS, server-only auth), ongoing monitoring, and five real failure patterns with their actual fixes.
Start the hardening guide →
// cursor-specific checklist
Cursor app security checklist
A 25-item hardening guide targeting Cursor-specific patterns: autocomplete inlines service keys, generated multi-file edits land without review, Agent mode runs terminal commands, and project rules (
.cursor/rules) are your first security guardrail. Pre-deploy, at-deploy, and post-deploy checks for Cursor workflows.Read the Cursor guide →
// launch week go/no-go
Pre-launch SaaS security checklist
A comprehensive pre-ship audit for founders launching AI-built SaaS. Covers customer data isolation, billing + Stripe, authentication + sessions, PII + compliance, operational readiness, external attack surface, observability, and final verification — 36 actionable items designed to complete in one week.
Review the pre-launch checklist →
// structural analysis
Why AI coding tools leave security gaps
An honest analysis of the structural blindspots in Cursor, Claude Code, Lovable, Bolt, and v0. Training-data bias, autocomplete dynamics, no long-term context, and speed-as-metric create predictable security gaps. Learn the root cause of each gap class and the remediation pattern that closes it.
Read the gap analysis →
// scanner selection
Choosing a security scanner for AI-built apps
Comparison and decision framework for picking the right scanner — FixVibe, Burp Suite, ZAP, Snyk, Semgrep and Aikido. Covers the evaluation criteria that matter for AI-generated SaaS (BaaS coverage, JS bundle inspection, framework awareness, active-probe gating), a side-by-side table, and a decision matrix for six common scenarios.
Compare scanners →
// platform checklist
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations,
import.meta.envleaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.Open the checklist →
// platform checklist
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
Open the checklist →
// platform checklist
v0 security checklist: 22 items for Next.js
v0 generates React + Tailwind + shadcn/ui components and full Next.js apps for Vercel. This checklist targets v0-specific risks: design iterations that re-add dangerouslySetInnerHTML, exported codebases that lose middleware, Server Actions that skip auth verification, and environment variables that have to be set again once the code lives in your own repo. 22 items across secrets, database, auth, headers, deployment, and v0-specific gotchas.
Open the checklist →
