Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- 가입 필요 없음
- 230+ passive checks per scan
- BaaS 인지
- 인증 안전(수동)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
스캐너 커버리지
- 240+
- 지원하는 취약점 클래스
- 230+
- 수동 체크 / 스캔
- 130+
- 능동 체크 / 스캔
- 190+
- GitHub 체크 / 스캔
지원 도구
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS 보안
Supabase RLS 스캐너: 행 수준 보안이 누락되었거나 망가진 테이블 찾기
Supabase 기반 앱을 출시할 때 고객 데이터와 인터넷 사이에 서 있는 유일한 것은 행 수준 보안(RLS)입니다. AI 코딩 도구는 컴파일되고 출시되며 조용히 데이터를 유출시키는 RLS 모양의 코드를 생성합니다 — RLS가 활성화되지 않은 채 생성된 테이블, 읽지만 제한하지 않는 정책, 열을 자기 자신과 비교하는 술어. 이 기사는 Supabase RLS 스캐너가 외부에서 무엇을 증명할 수 있는지, 바이브 코딩된 앱에 나타나는 네 가지 손상 RLS 패턴, 그리고 1분 이내에 자신의 배포를 스캔하는 방법을 보여줍니다.
- BaaS 보안
JavaScript에 노출된 Supabase 서비스 역할 키: 의미와 찾는 방법
Supabase 서비스 역할 키는 데이터베이스의 마스터 키입니다. 그것을 가진 사람은 누구나 행 수준 보안을 우회하고, 모든 테이블의 모든 열을 읽을 수 있으며, 원하는 무엇이든 쓰거나 삭제할 수 있습니다. 서버 측 코드에만 존재하도록 설계되었으며 — 결코 브라우저에 있어서는 안 됩니다. AI 코딩 도구가 그것을 JavaScript 번들에 출시하면 데이터베이스는 사실상 공개됩니다. 이 기사는 유출된 키를 식별하는 JWT 모양, 유출을 생성하는 세 가지 AI 도구 패턴, 탐지 후 첫 한 시간 내에 할 일, 그리고 사용자보다 먼저 자동으로 스캔하는 방법을 설명합니다.
- BaaS 보안
Firebase 규칙 스캐너: 열린 Firestore, Realtime Database, Storage 규칙 찾기
Firebase 앱은 일관된 방식으로 보안에 실패합니다: 테스트 모드 빠른 시작에서 남은 allow read, write: if true; 규칙이 프로덕션 전에 결코 교체되지 않습니다. AI 코딩 도구는 이러한 규칙을 문서 예제에서 그대로 생성하며 개발자에게 강화하도록 거의 안내하지 않습니다. 이 기사는 Firebase 규칙 스캐너가 Firestore, Realtime Database, Cloud Storage에 걸쳐 프로젝트 외부에서 열린 규칙을 어떻게 탐지하는지 — 그리고 발견된 것을 어떻게 고치는지를 보여줍니다.
- 보안 가이드
바이브 코딩 보안 체크리스트: 출시 전 51가지 항목
Cursor, Claude Code, Lovable, Bolt, v0, Replit 및 Windsurf로 구축된 앱을 위한 실용적이고 단계별로 구성된 체크리스트입니다. 각 항목은 5분 이내에 실행 가능합니다. 프로덕션으로 진행하기 전에 이를 검토한 다음 각 주요 릴리스 전에 다시 한번 살펴보십시오. 항목은 비밀, 데이터베이스, 인증, 헤더, 타사, 배포, 모니터링 등 7가지 범주로 그룹화되며 적용되는 배포 단계 태그가 지정됩니다.
- 보안 가이드
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- 보안 가이드
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
