Vibe coding security
Vibe coding security: check your AI-built app’s code and live site
You built it with Lovable, Bolt, v0, Replit or Cursor and it works. SafeWeave checks whether it also leaves your database, storage or keys open, in the code and in the app people actually use.
Free scan of a public GitHub repo · no signup · private repos and live apps with a free account
Why it matters
An app that works can still be wide open
AI app builders make the same security mistakes again and again: database tables anyone can read, admin keys shipped to the browser, AI routes anyone can call. None of these break the app, so you don’t notice them. Anyone who opens your site’s code in their browser can.
How SafeWeave Solves It
What SafeWeave does about it
59 checks written for the stacks AI builders use: Supabase, Firebase, Next.js, Vite, Express, Stripe, AI features, Python, MCP servers and secrets.
Scans the code in your GitHub repository on each push, so new mistakes show up when they are made.
Checks your live app from the outside, the way anyone on the internet can see it, and only reads.
On Cloud and Cloud Plus, each finding comes with how to fix it, and a prompt you can paste back into your AI tool.
The common risks
What goes wrong in vibe-coded apps, and what SafeWeave checks
Database tables anyone can read
Secret keys shipped to the browser
Storage anyone can open
Routes and actions with no sign-in check
AI routes anyone can use
Paywalls and roles checked only in the browser
Files that should never be public
The checks “from the outside” are live app checks, on Cloud and Cloud Plus. Every check is listed with what it means and how to fix it in the docs: vibe-coded app checks and live app checks. Or work through them as a vibe coding security checklist.
How it works
Two ways in: the code and the live app
Your code, through GitHub
Your live app, from its URL
You don’t connect your builder itself. If it can put your project on GitHub, use both; if it can’t, scan the live app. On Supabase? On Cloud and Cloud Plus you can also connect Supabase to check the database itself for tables without Row Level Security.
By builder
Built with a specific tool?
Step-by-step setup for each builder is in the docs: Scan Lovable, Bolt, v0 & Replit apps.
Plans
What’s free and what’s on Cloud
| Free | Cloud and Cloud Plus | |
|---|---|---|
| Connected repositories | 1 | 5 on Cloud, 15 on Cloud Plus |
| Cloud scans per repository a month | 5 | 15 on Cloud, no limit on Cloud Plus |
| Vibe-coded app checks on your code | Grade and finding counts | Every finding, with how to fix it |
| App URL scan | Score, grade and the first findings | All findings, with how to fix them |
| Live app checks (open tables, storage, keys, AI routes) | No | Yes |
| Daily or weekly monitoring with email alerts | No | Yes |
| Supabase connection (RLS and security advisors) | No | Yes |
Cloud is $29/month with a 14-day free trial; Cloud Plus is $59/month. See Choosing a plan.
Coding with an AI editor?
More on AI code security
FAQ
Common questions
What is vibe coding security?
It is making sure an app you built by prompting an AI tool, such as Lovable, Bolt.new, v0, Replit or Cursor, doesn’t leave your data or keys open. AI app builders tend to repeat the same mistakes: database tables anyone can read, admin keys shipped to the browser and AI routes anyone can call. Those are what SafeWeave’s vibe-coded app checks look for.
Is my vibe-coded app secure?
You can’t tell by using it: an app can work perfectly and still let anyone read its database. Scan it. SafeWeave checks the code in your GitHub repository and the live app at its URL, and shows each finding with how to fix it on Cloud and Cloud Plus.
Does SafeWeave change anything in my app or database?
No. Live app checks only read: they use only the keys your app already ships publicly, never write, update or delete anything, and keep none of the data they read. The Supabase connection only reads Supabase’s own security checks and never reads the data in your tables.
What can I check for free?
Without an account, you can scan a public GitHub repository at safeweave.dev/scan. With a free account, you can connect one repository and see its grade and finding counts, and scan your app’s URL for a score and the first findings. Every finding with its fix, the live app checks and the Supabase connection are on Cloud and Cloud Plus.
See what your app leaves open
Paste a public GitHub repository and get a grade with ranked findings in seconds, no account needed. For a private repository or your live app, create a free account.
Run a free scanView on GitHub