Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- 无需注册
- 230+ passive checks per scan
- 理解 BaaS 风险
- 认证安全(被动)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
扫描器覆盖范围
- 240+
- 已覆盖漏洞类别
- 230+
- 被动检查 / 每次扫描
- 130+
- 主动检查 / 每次扫描
- 190+
- GitHub 检查 / 每次扫描
兼容
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS 安全
Supabase RLS 扫描器:发现缺失或损坏的行级安全表
当你部署一个由 Supabase 支持的应用时,行级安全 (RLS) 是站在你的客户数据和互联网之间的唯一屏障。AI 编码工具生成可以编译、发布并悄悄泄露数据的 RLS 形状代码 — 创建时未启用 RLS 的表、可读但从不限制的策略、将列与自身比较的谓词。本文展示 Supabase RLS 扫描器从外部可以证明什么、出现在 vibe 编码应用中的四种损坏 RLS 形态,以及如何在不到一分钟内扫描你自己的部署。
- BaaS 安全
暴露在 JavaScript 中的 Supabase 服务角色密钥:含义和发现方法
Supabase 服务角色密钥是你数据库的主密钥。任何持有它的人都能绕过行级安全,可以读取每个表的每一列,并且可以随意写入或删除任何内容。它被设计为只存在于服务器端代码中 — 绝不在浏览器中。当 AI 编码工具将其发布到 JavaScript 包时,你的数据库实际上就是公开的。本文解释标识泄露密钥的 JWT 形状、产生泄露的三种 AI 工具模式、检测后第一小时内应采取的行动,以及如何在用户之前自动扫描它。
- BaaS 安全
Firebase 规则扫描器:发现开放的 Firestore、Realtime Database 和 Storage 规则
Firebase 应用以一种一致的方式在安全性上失败:allow read, write: if true; 规则是从测试模式快速开始的遗留物,从未在生产前替换。AI 编码工具会逐字从文档示例中重新生成这些规则,而很少提示开发者去加固它们。本文展示 Firebase 规则扫描器如何从项目外部检测 Firestore、Realtime Database 和 Cloud Storage 中的开放规则 — 以及如何修复它发现的问题。
- 安全指南
Vibe coding 安全检查清单:上线前 51 项
针对使用 Cursor、Claude Code、Lovable、Bolt、v0、Replit 和 Windsurf 构建的应用程序的实用的、分阶段组织的清单。每个项目都可以在五分钟内完成。在投入生产之前运行它,然后在每个主要版本之前再次运行它。项目分为七个类别——秘密、数据库、身份验证、标头、第三方、部署、监控——并标记有它们适用的部署阶段。
- 安全指南
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- 安全指南
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
