找出 AI 工具留下的安全漏洞。
免费即时扫描。 发现暴露的 Supabase service-role key、缺失的 RLS、开放的 Firebase 规则、JS bundle 中泄露的密钥等问题。
- 无需注册
- 500+ 项检查 已执行
- 理解 BaaS 风险
- 认证安全(被动)
扫描器覆盖范围
- 160+
- 已覆盖漏洞类别
- 260+
- 被动检查 / 每次扫描
- 120+
- 主动检查 / 每次扫描
- 110+
- GitHub 检查 / 每次扫描
兼容
扫描使用 AI 编码工具构建的网站和应用。
无论你用 Cursor、Claude Code、Codex、Lovable、Bolt、v0、Replit 等工具发布,FixVibe 都会检查已上线的 URL 和代码仓库,找出 AI 生成应用常遗漏的安全缺口。
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
最新研究
每天都有新的漏洞。
我们持续追踪新披露的 CVE、GHSA 公告,以及对 AI 构建应用影响较大的 BaaS 错误配置模式。公开笔记从宏观层面说明影响范围与安全的修复思路。
- 高已被 FixVibe 覆盖
Mbed TLS Double-Free Vulnerability (CVE-2021-44732)
CVE-2021-44732 affects older Mbed TLS releases in a session-handling error path. FixVibe repo scans can now flag affected version evidence in source and build metadata, while making clear that the scan did not run Mbed TLS, force out-of-memory behavior, or prove exploitation.
- 严重已被 FixVibe 覆盖
Missing Authentication in Moxa NPort Series Devices (CVE-2016-9369)
Moxa NPort serial device servers before vendor fixed firmware releases are associated with CVE-2016-9369. FixVibe can flag strong HTTP model and firmware-version evidence as a version-based advisory during verified active scans without attempting firmware updates, unauthenticated administrative actions, or exploit confirmation.
- 严重已被 FixVibe 覆盖
Schneider Electric Modicon M221 Authentication Replay Advisory (CVE-2018-7790)
FixVibe can flag public Modicon M221 HTTP product and firmware-version evidence associated with CVE-2018-7790 as a version-based advisory. The scan does not replay authentication, query industrial protocols, upload PLC programs, or prove unauthorized access.
最新研究、实战背景,以及检查项上线时的覆盖范围更新。
全部研究 →