Vibe coding security

Vibe coding security: check your AI-built app’s code and live site

You built it with Lovable, Bolt, v0, Replit or Cursor and it works. SafeWeave checks whether it also leaves your database, storage or keys open, in the code and in the app people actually use.

Free scan of a public GitHub repo · no signup · private repos and live apps with a free account

Why it matters

An app that works can still be wide open

AI app builders make the same security mistakes again and again: database tables anyone can read, admin keys shipped to the browser, AI routes anyone can call. None of these break the app, so you don’t notice them. Anyone who opens your site’s code in their browser can.

How SafeWeave Solves It

What SafeWeave does about it

  • 59 checks written for the stacks AI builders use: Supabase, Firebase, Next.js, Vite, Express, Stripe, AI features, Python, MCP servers and secrets.

  • Scans the code in your GitHub repository on each push, so new mistakes show up when they are made.

  • Checks your live app from the outside, the way anyone on the internet can see it, and only reads.

  • On Cloud and Cloud Plus, each finding comes with how to fix it, and a prompt you can paste back into your AI tool.

The common risks

What goes wrong in vibe-coded apps, and what SafeWeave checks

Database tables anyone can read

Supabase tables with Row Level Security off or a policy that lets every row through, and Firestore or Realtime Database rules with no condition. In code, and from the outside: the live checks look for tables and collections your public key can read.

Secret keys shipped to the browser

The Supabase service_role key, AI provider keys or other secrets in NEXT_PUBLIC_ or VITE_ variables or browser code. The live checks look in your website code for keys such as Stripe secret, OpenAI, Anthropic and Supabase service keys.

Storage anyone can open

Supabase buckets created as public, and Firebase Storage rules with no condition. From the outside: public Supabase buckets and Firebase buckets that list their files to anyone.

Routes and actions with no sign-in check

Next.js Route Handlers and Server Actions that change data without checking the user, inverted auth checks, Edge Functions using the service_role key for anyone, and /admin routes with no auth. From the outside: API routes that return personal data and debug pages that answer without sign-in.

AI routes anyone can use

Routes that call an AI model without checking who is calling or without a rate limit, user input in the system prompt, and model output sent straight into HTML, a shell or SQL. From the outside: AI routes that answer without sign-in.

Paywalls and roles checked only in the browser

Plans, paywalls and admin access decided in client code or from user_metadata, plans set from what the browser sends instead of Stripe, and Stripe webhooks that don’t verify the signature.

Files that should never be public

From the outside (live checks on Cloud): /.env files, the .git folder, backups, Supabase and Firebase config files, and source maps your site serves to anyone.

The checks “from the outside” are live app checks, on Cloud and Cloud Plus. Every check is listed with what it means and how to fix it in the docs: vibe-coded app checks and live app checks. Or work through them as a vibe coding security checklist.

How it works

Two ways in: the code and the live app

Your code, through GitHub

Connect the GitHub repository your builder syncs to. Each push is scanned, within your plan's monthly scan limit. On top of the standard scanners, 59 vibe-coded app checks look for the mistakes AI builders make with Supabase, Firebase, Next.js, Vite, Express, Stripe, AI features, Python, MCP servers and secrets.

Your live app, from its URL

An App URL scan looks at your deployed app the way anyone on the internet can: security headers, the TLS certificate, email records and exposed files. On Cloud and Cloud Plus it also runs live app checks for open tables, storage, keys and AI routes. They only read; they never change anything.

You don’t connect your builder itself. If it can put your project on GitHub, use both; if it can’t, scan the live app. On Supabase? On Cloud and Cloud Plus you can also connect Supabase to check the database itself for tables without Row Level Security.

By builder

Built with a specific tool?

Plans

What’s free and what’s on Cloud

FreeCloud and Cloud Plus
Connected repositories15 on Cloud, 15 on Cloud Plus
Cloud scans per repository a month515 on Cloud, no limit on Cloud Plus
Vibe-coded app checks on your codeGrade and finding countsEvery finding, with how to fix it
App URL scanScore, grade and the first findingsAll findings, with how to fix them
Live app checks (open tables, storage, keys, AI routes)NoYes
Daily or weekly monitoring with email alertsNoYes
Supabase connection (RLS and security advisors)NoYes

Cloud is $29/month with a 14-day free trial; Cloud Plus is $59/month. See Choosing a plan.

FAQ

Common questions

What is vibe coding security?

It is making sure an app you built by prompting an AI tool, such as Lovable, Bolt.new, v0, Replit or Cursor, doesn’t leave your data or keys open. AI app builders tend to repeat the same mistakes: database tables anyone can read, admin keys shipped to the browser and AI routes anyone can call. Those are what SafeWeave’s vibe-coded app checks look for.

Is my vibe-coded app secure?

You can’t tell by using it: an app can work perfectly and still let anyone read its database. Scan it. SafeWeave checks the code in your GitHub repository and the live app at its URL, and shows each finding with how to fix it on Cloud and Cloud Plus.

Does SafeWeave change anything in my app or database?

No. Live app checks only read: they use only the keys your app already ships publicly, never write, update or delete anything, and keep none of the data they read. The Supabase connection only reads Supabase’s own security checks and never reads the data in your tables.

What can I check for free?

Without an account, you can scan a public GitHub repository at safeweave.dev/scan. With a free account, you can connect one repository and see its grade and finding counts, and scan your app’s URL for a score and the first findings. Every finding with its fix, the live app checks and the Supabase connection are on Cloud and Cloud Plus.

See what your app leaves open

Paste a public GitHub repository and get a grade with ranked findings in seconds, no account needed. For a private repository or your live app, create a free account.

Run a free scanView on GitHub