Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- 登録不要
- 230+ passive checks per scan
- BaaSを考慮
- 認証に安全(パッシブ)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
スキャナーのカバレッジ
- 240+
- 対応する脆弱性クラス
- 230+
- パッシブチェック / スキャン
- 130+
- アクティブチェック / スキャン
- 190+
- GitHubチェック / スキャン
対応ツール
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS セキュリティ
Supabase RLS スキャナ: 行レベルセキュリティが欠落または破損したテーブルを検出
Supabase をバックエンドにしたアプリをリリースしたとき、顧客のデータとインターネットの間に立ちはだかる唯一のものが行レベルセキュリティ (RLS) です。AI コーディングツールは、コンパイルが通り、デプロイされ、しかし静かにデータを漏洩させる RLS 風コードを生成します — RLS を有効化せずに作成されたテーブル、読み取りはできるが制限しないポリシー、列自体を比較する述語などです。本記事では、Supabase RLS スキャナが外部から何を証明できるか、バイブコードされたアプリに現れる 4 つの破損 RLS パターン、そして自分のデプロイ環境を 1 分以内にスキャンする方法を示します。
- BaaS セキュリティ
JavaScript に露出した Supabase サービスロールキー: 意味と発見方法
Supabase サービスロールキーはあなたのデータベースのマスターキーです。これを保持する者は誰でも行レベルセキュリティをバイパスし、すべてのテーブルのすべての列を読むことができ、好きなものを書き込みまたは削除できます。これはサーバーサイドコードだけに置かれるよう設計されており、ブラウザに置かれてはなりません。AI コーディングツールがこれを JavaScript バンドルに送り込むと、あなたのデータベースは実質的に公開されたことになります。本記事では、漏洩したキーを特定する JWT 形状、漏洩を生む 3 つの AI ツールパターン、検出後 1 時間以内にすべきこと、そしてユーザーよりも先に自動的にスキャンする方法を説明します。
- BaaS セキュリティ
Firebase ルールスキャナ: 開いている Firestore、Realtime Database、Storage ルールを検出
Firebase アプリは一貫した方法でセキュリティに失敗します: テストモードのクイックスタートから残された allow read, write: if true; ルールが、本番前に置き換えられないまま放置されるのです。AI コーディングツールはこれらのルールをドキュメント例から逐語的に生成し、開発者にハードニングを促すことはほとんどありません。本記事では、Firebase ルールスキャナがプロジェクトの外側から Firestore、Realtime Database、Cloud Storage 全体で開いたルールをどう検出するか、そして検出された内容をどう修正するかを示します。
- セキュリティガイド
Vibe コーディング セキュリティチェックリスト: リリース前の 51 項目
Cursor、Claude Code、Lovable、Bolt、v0、Replit、および Windsurf を使用して構築されたアプリ用の、フェーズ別に整理された実践的なチェックリスト。各項目は 5 分以内に実行可能です。運用環境にプッシュする前に、次に各メジャー リリースの前にもう一度実行してください。項目は、シークレット、データベース、認証、ヘッダー、サードパーティ、展開、監視の 7 つのカテゴリにグループ化され、適用される展開フェーズでタグ付けされます。
- セキュリティガイド
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- セキュリティガイド
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
