Checklist
Vibe coding security checklist: 96 checks for AI-built apps
Every item is a check SafeWeave really runs: 59 on your code and 37 on your live app. Work through it by hand, or run a scan that checks them for you.
Free scan of a public GitHub repo · no signup · private repos and live apps with a free account
Why a checklist
The same mistakes, again and again
AI app builders write working code fast, and they repeat the same security mistakes: tables anyone can read, admin keys in the browser, AI routes anyone can call. You can’t see them by using your app. This list groups them by what you built with, in plain words, with a link to what each one means and how to fix it.
How SafeWeave Solves It
How to use it
Skip the groups for stacks you don’t use: a Supabase app doesn’t need the Firebase items.
Start with High and Critical items. Medium means fix soon, Low is good practice.
Click any item to read what it means and how to fix it.
Or let SafeWeave check them for you on each push and on your live URL.
In your code · 59 checks
Check your code
Supabase
Firebase
Next.js
Vite
Express
Stripe
AI apps
AI agents
Secrets
Python
SafeWeave runs these as vibe-coded app checks on cloud scans of your connected repositories.
In your live app · 37 checks
Make sure your live app has none of these
Routes and pages open without sign-in
- GraphQL schema is publicMedium
Keys visible in your website code
Files and settings anyone can download
- Source maps are publicMedium
Firebase, from the outside
Supabase, from the outside
SafeWeave runs these as live app checks on App URL scans on Cloud and Cloud Plus. They only read, never change anything, and keep none of the data they read.
Automate it
Let SafeWeave check the list for you
Your code, through GitHub
Your live app, from its URL
| Free | Cloud and Cloud Plus | |
|---|---|---|
| Connected repositories | 1 | 5 on Cloud, 15 on Cloud Plus |
| Cloud scans per repository a month | 5 | 15 on Cloud, no limit on Cloud Plus |
| Vibe-coded app checks on your code | Grade and finding counts | Every finding, with how to fix it |
| App URL scan | Score, grade and the first findings | All findings, with how to fix them |
| Live app checks (open tables, storage, keys, AI routes) | No | Yes |
| Daily or weekly monitoring with email alerts | No | Yes |
| Supabase connection (RLS and security advisors) | No | Yes |
Cloud is $29/month with a 14-day free trial; Cloud Plus is $59/month. See Choosing a plan.
FAQ
Common questions
What should a vibe coding security checklist cover?
The mistakes AI app builders make again and again: database tables anyone can read (Supabase Row Level Security, Firebase rules), secret keys in the browser, storage anyone can open, routes and Server Actions with no sign-in check, paywalls checked only in the browser, AI routes anyone can call, and files like /.env or .git that your site serves to anyone. This checklist lists each check SafeWeave runs for them.
Which items should I fix first?
Start with the items marked High or Critical: they mean fix now, like Row Level Security turned off or a service_role key in browser code. Medium means fix soon, and Low is good practice.
Can I run this checklist automatically?
Yes. SafeWeave runs the code checks on cloud scans of your connected GitHub repository and the live checks on App URL scans of your deployed app. Free shows your repository’s grade and finding counts; every finding with its fix, and the live app checks, are on Cloud and Cloud Plus.
Run the checklist automatically
Paste a public GitHub repository and get a grade with ranked findings in seconds, no account needed. For a private repository or your live app, create a free account.
Run a free scanView on GitHub