Find security holes AI tools left behind.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 500+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 240+
- vulnerability classes covered
- 280+
- passive checks / scan
- 130+
- active checks / scan
- 160+
- GitHub checks / scan
Compatible with
Scan websites and apps built with AI coding tools.
Deploy from Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit, and more. FixVibe checks the shipped URL and repo for security gaps AI-generated apps tend to miss.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Latest research
New vulnerabilities, every day.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- criticalnot automatically checked
Orkes Conductor Pre-Authentication RCE CVE-2026-58138
CVE-2026-58138 is a critical remote code execution vulnerability affecting Orkes Conductor versions 3.21.21 through 3.30.1. An unauthenticated remote attacker can reach unsafe workflow expression evaluation and execute operating-system commands. Version 3.30.2 contains the relevant evaluator restrictions, so affected deployments should upgrade promptly and review access to the service.
- criticalnot automatically checked
React Router File Session Storage Path Traversal CVE-2025-61686
CVE-2025-61686 is a critical path traversal issue in React Router file session storage. Applications using createFileSessionStorage with an unsigned cookie can be made to access paths outside the configured session directory; @react-router/node 7.9.4 contains the fix.
- highnot automatically checked
Linux Kernel TLS Receive Path Vulnerability CVE-2025-39682
CVE-2025-39682 is a Linux kernel TLS receive-path flaw involving zero-length records. CISA added it to the Known Exploited Vulnerabilities catalog on September 18, 2026, and affected systems should move to a vendor-fixed kernel.
Current research, practical context, and coverage updates when checks ship.
All research →