Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- Sin registro
- 230+ passive checks per scan
- Consciente de BaaS
- Seguro para auth (pasivo)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
Cobertura del escáner
- 240+
- clases de vulnerabilidad cubiertas
- 230+
- checks pasivos / escaneo
- 130+
- checks activos / escaneo
- 190+
- checks de GitHub / escaneo
Compatible con
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- Seguridad de BaaS
Escáner de RLS de Supabase: detecta tablas con seguridad a nivel de fila ausente o rota
La seguridad a nivel de fila (RLS) es lo único que se interpone entre los datos de tus clientes e internet cuando publicas una aplicación respaldada por Supabase. Las herramientas de codificación con IA generan código con forma de RLS que compila, se publica y filtra datos en silencio — tablas creadas sin RLS habilitado, políticas que leen pero nunca restringen, predicados que comparan una columna consigo misma. Este artículo muestra qué puede probar un escáner de RLS de Supabase desde el exterior, las cuatro formas de RLS rota que aparecen en aplicaciones generadas por IA y cómo escanear tu propio despliegue en menos de un minuto.
- Seguridad de BaaS
Clave de rol de servicio de Supabase expuesta en JavaScript: qué significa y cómo detectarla
La clave de rol de servicio de Supabase es la clave maestra de tu base de datos. Quien la posea se salta la seguridad a nivel de fila, puede leer cada columna de cada tabla y puede escribir o borrar lo que quiera. Está diseñada para vivir exclusivamente en código del lado del servidor — nunca en el navegador. Cuando una herramienta de codificación con IA la envía al bundle de JavaScript, tu base de datos queda, en efecto, pública. Este artículo explica la forma del JWT que identifica una clave filtrada, los tres patrones de herramientas de IA que producen la fuga, qué hacer en la primera hora tras la detección y cómo escanear automáticamente para detectarla antes que los usuarios.
- Seguridad de BaaS
Escáner de reglas de Firebase: detecta reglas abiertas en Firestore, Realtime Database y Storage
Las aplicaciones de Firebase fallan en seguridad de una forma consistente: reglas allow read, write: if true; que quedaron del arranque rápido de modo prueba, nunca reemplazadas antes de producción. Las herramientas de codificación con IA generan estas reglas literalmente desde los ejemplos de la documentación y rara vez piden al desarrollador endurecerlas. Este artículo muestra cómo un escáner de reglas de Firebase detecta reglas abiertas en Firestore, Realtime Database y Cloud Storage desde fuera del proyecto — y cómo corregir lo que encuentre.
- Guías de seguridad
La checklist de seguridad de vibe coding: 51 ítems antes de enviar
Una checklist práctica y organizada por fase para apps creadas con Cursor, Claude Code, Lovable, Bolt, v0, Replit y Windsurf. Cada ítem es accionable en menos de cinco minutos. Recórrela antes de enviar a producción y otra vez antes de cada release importante. Los ítems se agrupan en siete categorías — secretos, base de datos, autenticación, cabeceras, terceros, despliegue, monitoreo — y se etiquetan con la fase de deploy a la que aplican.
- Guías de seguridad
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- Guías de seguridad
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
