Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- Kayıt gerekmez
- 230+ passive checks per scan
- BaaS farkındalıklı
- Auth-safe (pasif)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
Scanner kapsamı
- 240+
- kapsanan açık sınıfları
- 230+
- pasif check’ler / tarama
- 130+
- aktif check’ler / tarama
- 190+
- GitHub check’leri / tarama
Uyumlu olduğu araçlar
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS güvenliği
Supabase RLS tarayıcısı: eksik veya bozuk row-level security olan tabloları bulun
Row-level security (RLS), bir Supabase tabanlı uygulamayı yayınladığınızda müşterilerinizin verileri ile internet arasında duran tek şeydir. Yapay zeka kodlama araçları derlenen, dağıtılan ve sessizce veri sızdıran RLS biçimli kod üretir — RLS etkinleştirilmeden oluşturulmuş tablolar, okuyan ama asla kısıtlamayan policy'ler, bir sütunu kendisiyle karşılaştıran yüklemler. Bu makale, bir Supabase RLS tarayıcısının dışarıdan neyi kanıtlayabildiğini, vibe-coded uygulamalarda görülen dört bozuk RLS biçimini ve kendi deployment'ınızı bir dakikadan kısa sürede nasıl tarayacağınızı gösterir.
- BaaS güvenliği
JavaScript'te ifşa olan Supabase service role anahtarı: ne anlama geldiği ve nasıl bulunacağı
Supabase service role anahtarı veritabanınızın ana anahtarıdır. Onu elinde tutan herkes Row-Level Security'yi atlar, her tablonun her sütununu okuyabilir ve seçtiği her şeyi yazabilir veya silebilir. Yalnızca sunucu tarafı kodda yaşaması için tasarlanmıştır — asla tarayıcıda değil. Bir yapay zeka kodlama aracı onu JavaScript paketine gönderdiğinde, veritabanınız aslında halka açıktır. Bu makale, sızdırılmış bir anahtarı tanımlayan JWT şeklini, sızıntıyı üreten üç yapay zeka aracı desenini, tespit sonrası ilk saatte ne yapılacağını ve kullanıcılar yapmadan önce otomatik olarak nasıl taranacağını açıklar.
- BaaS güvenliği
Firebase kuralları tarayıcısı: açık Firestore, Realtime Database ve Storage kurallarını bulun
Firebase uygulamaları tutarlı bir şekilde güvenlikte başarısız olur: test-modu hızlı başlangıcından kalan, üretime geçmeden önce hiç değiştirilmemiş allow read, write: if true; kuralları. Yapay zeka kodlama araçları bu kuralları kelime kelime dokümantasyon örneklerinden üretir ve geliştiriciyi sertleştirmeye nadiren teşvik eder. Bu makale, bir Firebase kuralları tarayıcısının Firestore, Realtime Database ve Cloud Storage'da açık kuralları proje dışından nasıl tespit ettiğini — ve bulduklarını nasıl düzelteceğinizi gösterir.
- Güvenlik kılavuzları
Vibe coding güvenlik kontrol listesi: gönderim öncesi 51 madde
Cursor, Claude Code, Lovable, Bolt, v0, Replit ve Windsurf ile oluşturulan uygulamalar için pratik, aşamalara göre düzenlenmiş bir kontrol listesi. Her öğe beş dakikadan kısa sürede işleme koyulabilir. Üretime geçmeden önce, ardından her büyük sürümden önce tekrar gözden geçirin. Öğeler yedi kategoride (gizli diziler, veritabanı, kimlik doğrulama, başlıklar, üçüncü taraf, dağıtım, izleme) gruplandırılır ve uygulandıkları dağıtım aşamasıyla etiketlenir.
- Güvenlik kılavuzları
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- Güvenlik kılavuzları
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
