Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- Nessuna registrazione
- 230+ passive checks per scan
- Consapevole del BaaS
- Sicuro per auth (passivo)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
Copertura dello scanner
- 240+
- classi di vulnerabilità coperte
- 230+
- check passivi / scan
- 130+
- check attivi / scan
- 190+
- check GitHub / scan
Compatibile con
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- Sicurezza BaaS
Scanner RLS Supabase: trova tabelle con sicurezza a livello di riga mancante o difettosa
La sicurezza a livello di riga (RLS) è l'unica cosa che sta tra i dati dei tuoi clienti e Internet quando metti in produzione un'applicazione supportata da Supabase. Gli strumenti di codifica IA generano codice in forma di RLS che compila, viene spedito e perde dati silenziosamente — tabelle create senza RLS abilitato, policy che leggono ma non restringono mai, predicati che confrontano una colonna con sé stessa. Questo articolo mostra cosa può dimostrare uno scanner RLS Supabase dall'esterno, le quattro forme di RLS difettosa che compaiono nelle app vibe-coded e come scansionare il tuo stesso deployment in meno di un minuto.
- Sicurezza BaaS
Chiave di service-role Supabase esposta in JavaScript: cosa significa e come trovarla
La chiave di service-role Supabase è la chiave master del tuo database. Chiunque la possegga bypassa la sicurezza a livello di riga, può leggere ogni colonna di ogni tabella e può scrivere o cancellare ciò che vuole. È progettata per vivere esclusivamente nel codice lato server — mai nel browser. Quando uno strumento di codifica IA la spedisce nel bundle JavaScript, il tuo database è, in effetti, pubblico. Questo articolo spiega la forma del JWT che identifica una chiave trapelata, i tre pattern di strumenti IA che producono il leak, cosa fare nella prima ora dopo la rilevazione e come scansionare automaticamente prima degli utenti.
- Sicurezza BaaS
Scanner di regole Firebase: trova regole aperte in Firestore, Realtime Database e Storage
Le app Firebase falliscono in sicurezza in un modo coerente: regole allow read, write: if true; rimaste dal quickstart in test-mode, mai sostituite prima della produzione. Gli strumenti di codifica IA generano queste regole letteralmente dagli esempi della documentazione e raramente sollecitano lo sviluppatore a indurirle. Questo articolo mostra come uno scanner di regole Firebase rileva regole aperte attraverso Firestore, Realtime Database e Cloud Storage da fuori del progetto — e come correggere ciò che trova.
- Guide di sicurezza
Checklist di sicurezza vibe coding: 51 voci prima del deploy
Un pratico elenco di controllo organizzato in fasi per le app create con Cursor, Claude Code, Lovable, Bolt, v0, Replit e Windsurf. Ogni elemento è utilizzabile in meno di cinque minuti. Eseguilo prima di passare alla produzione, quindi di nuovo prima di ogni versione principale. Gli elementi sono raggruppati in sette categorie (segreti, database, autenticazione, intestazioni, terze parti, distribuzione, monitoraggio) e contrassegnati con la fase di distribuzione a cui si applicano.
- Guide di sicurezza
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- Guide di sicurezza
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
