Build with your agent. Check what is live.
Start with a free passive scan. Find exposed credentials and risky web configuration. Give your coding agent the evidence, deploy your repair, and use a scoped recheck for supported header findings.
- 不需註冊
- 230+ passive checks per scan
- 理解 BaaS 風險
- Auth 安全(被動)
FixVibe is a security scanner for indie developers and small teams shipping web apps built with AI coding tools such as Lovable, Bolt, v0, Cursor and Claude Code. Paste a deployed URL to find exposed Supabase service-role keys, missing Row-Level Security, open Firebase rules, secrets in JavaScript bundles and weak headers. The passive scan is free.
How it fits your workflow
Your agent repairs it. Recheck the deployed header.
Start with a precise result you can inspect. The first verification pilot checks whether a supported x-content-type-options finding has been repaired on the same deployed page. Your agent makes the change; FixVibe measures the follow-up response.
This workflow example is currently available in English.
- 01
Inspect the deployed app
Run an authorized passive URL scan. A new supported header finding can provide the baseline for a scoped recheck. Review the report's evidence and any checks that could not run.
- 02
Repair in your existing workflow
Open the finding's fix-and-recheck options. Give the repair guidance to Claude, Codex, or your preferred agent, review its change, and deploy through your normal workflow.
- 03
Deploy, then request verification
See whether the expected header is present on a comparable response. The result can confirm this scope, report the issue still present, or stay inconclusive when a reliable comparison is not possible.
Synthetic example · not a customer report
Before: x-content-type-options is missing. After a comparable recheck: x-content-type-options: nosniff.
Illustrative result: “Verified for this page and header.” The report keeps the baseline, the later measurement, and any remaining responsibilities visible.
This pilot verifies one header on the same page's anonymous response. Other pages, signed-in roles, credential revocation, and unrelated vulnerabilities remain outside that result. It is not an app-wide security certificate.
Free reports show a top-two preview. For one eligible finding, the browser introduction includes repair guidance and one verification within seven days, plus one additional attempt after an inconclusive result. Full reports and API/MCP require a paid plan; scheduled scans require Pro or Unlimited.
掃描器涵蓋範圍
- 240+
- 已涵蓋漏洞類別
- 230+
- 被動檢查 / 每次掃描
- 130+
- 主動檢查 / 每次掃描
- 190+
- GitHub 檢查 / 每次掃描
相容於
A security check alongside your coding agent.
Coding agents can review and test security. FixVibe adds maintained checks, deployed-app evidence, and repeatable reports to your workflow. URL scans, eligible GitHub scans, and paid MCP access each have their own scope.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Guides
Secure your AI-built app.
- BaaS 安全
Supabase RLS 掃描器:找出缺少或損毀的資料列層級安全表
當你部署一個以 Supabase 為後端的應用程式時,資料列層級安全 (RLS) 是站在你客戶資料與網際網路之間的唯一屏障。AI 編碼工具會產生可編譯、上線並悄悄外洩資料的 RLS 形狀程式碼 — 建立時未啟用 RLS 的資料表、可讀卻從不限制的策略、將欄位與自身比較的述詞。本文展示 Supabase RLS 掃描器從外部可以證明什麼、在 vibe 編碼應用中出現的四種 RLS 損毀型態,以及如何在一分鐘內掃描你自己的部署。
- BaaS 安全
暴露在 JavaScript 中的 Supabase 服務角色金鑰:意義與如何找到它
Supabase 服務角色金鑰是你資料庫的主金鑰。任何持有它的人都能繞過資料列層級安全,可讀取每張資料表的每一欄,並可隨意寫入或刪除任何內容。它的設計是只存在於伺服器端程式碼中 — 絕不在瀏覽器中。當 AI 編碼工具將其發布到 JavaScript 套件時,你的資料庫實際上就是公開的。本文解釋辨識洩漏金鑰的 JWT 形狀、產生洩漏的三種 AI 工具模式、偵測後第一小時內該做什麼,以及如何在使用者之前自動掃描它。
- BaaS 安全
Firebase 規則掃描器:找出開放的 Firestore、Realtime Database 與 Storage 規則
Firebase 應用程式在安全性上以一致的方式失敗:allow read, write: if true; 規則是從測試模式快速入門留下、在進入生產前從未被替換的遺物。AI 編碼工具會從文件範例逐字產生這些規則,並很少提示開發者去強化它們。本文展示 Firebase 規則掃描器如何從專案外部偵測 Firestore、Realtime Database 與 Cloud Storage 上的開放規則 — 以及如何修復它發現的問題。
- 安全指南
Vibe coding 安全檢查清單:上線前 51 項
針對使用 Cursor、Claude Code、Lovable、Bolt、v0、Replit 和 Windsurf 建立的應用程式的實用的、分階段組織的清單。每個項目都可以在五分鐘內完成。在投入生產之前運行它,然後在每個主要版本之前再次運行它。專案分為七個類別——秘密、資料庫、身份驗證、標頭、第三方、部署、監控——並標記有它們適用的部署階段。
- 安全指南
Lovable security checklist: 25 items before launch
Lovable is a fast path from idea to a published full-stack app on Supabase and Vite. This checklist targets the risks that come with that stack: RLS that must be enabled and tightened on every table Lovable creates, test keys from integrations, import.meta.env leaking env vars into the Vite bundle, GitHub sync exposing secrets, and missing security headers. 25 items across secrets, database, auth, headers, deployment, and Lovable-specific gotchas.
- 安全指南
Bolt.new security checklist: 23 items before ship
Bolt.new (StackBlitz WebContainer) runs your dev environment in the browser, generates full-stack JS in minutes, and publishes to Bolt hosting by default or to Netlify (Bolt docs). This checklist targets Bolt-specific risks: secrets that were safe in the dev container leak once the project is exported, Express CORS defaults are permissive, session cookies need explicit HttpOnly flags, and credentials pasted into the terminal or chat are hard to take back. 23 items across secrets, database, auth, headers, deployment, and Bolt-specific gotchas.
