Checklist

Vibe coding security checklist: 96 checks for AI-built apps

Every item is a check SafeWeave really runs: 59 on your code and 37 on your live app. Work through it by hand, or run a scan that checks them for you.

Free scan of a public GitHub repo · no signup · private repos and live apps with a free account

Why a checklist

The same mistakes, again and again

AI app builders write working code fast, and they repeat the same security mistakes: tables anyone can read, admin keys in the browser, AI routes anyone can call. You can’t see them by using your app. This list groups them by what you built with, in plain words, with a link to what each one means and how to fix it.

How SafeWeave Solves It

How to use it

  • Skip the groups for stacks you don’t use: a Supabase app doesn’t need the Firebase items.

  • Start with High and Critical items. Medium means fix soon, Low is good practice.

  • Click any item to read what it means and how to fix it.

  • Or let SafeWeave check them for you on each push and on your live URL.

In your code · 59 checks

Check your code

SafeWeave runs these as vibe-coded app checks on cloud scans of your connected repositories.

In your live app · 37 checks

Make sure your live app has none of these

SafeWeave runs these as live app checks on App URL scans on Cloud and Cloud Plus. They only read, never change anything, and keep none of the data they read.

Automate it

Let SafeWeave check the list for you

Your code, through GitHub

Connect the GitHub repository your builder syncs to. Each push is scanned, within your plan's monthly scan limit. On top of the standard scanners, 59 vibe-coded app checks look for the mistakes AI builders make with Supabase, Firebase, Next.js, Vite, Express, Stripe, AI features, Python, MCP servers and secrets.

Your live app, from its URL

An App URL scan looks at your deployed app the way anyone on the internet can: security headers, the TLS certificate, email records and exposed files. On Cloud and Cloud Plus it also runs live app checks for open tables, storage, keys and AI routes. They only read; they never change anything.
FreeCloud and Cloud Plus
Connected repositories15 on Cloud, 15 on Cloud Plus
Cloud scans per repository a month515 on Cloud, no limit on Cloud Plus
Vibe-coded app checks on your codeGrade and finding countsEvery finding, with how to fix it
App URL scanScore, grade and the first findingsAll findings, with how to fix them
Live app checks (open tables, storage, keys, AI routes)NoYes
Daily or weekly monitoring with email alertsNoYes
Supabase connection (RLS and security advisors)NoYes

Cloud is $29/month with a 14-day free trial; Cloud Plus is $59/month. See Choosing a plan.

FAQ

Common questions

What should a vibe coding security checklist cover?

The mistakes AI app builders make again and again: database tables anyone can read (Supabase Row Level Security, Firebase rules), secret keys in the browser, storage anyone can open, routes and Server Actions with no sign-in check, paywalls checked only in the browser, AI routes anyone can call, and files like /.env or .git that your site serves to anyone. This checklist lists each check SafeWeave runs for them.

Which items should I fix first?

Start with the items marked High or Critical: they mean fix now, like Row Level Security turned off or a service_role key in browser code. Medium means fix soon, and Low is good practice.

Can I run this checklist automatically?

Yes. SafeWeave runs the code checks on cloud scans of your connected GitHub repository and the live checks on App URL scans of your deployed app. Free shows your repository’s grade and finding counts; every finding with its fix, and the live app checks, are on Cloud and Cloud Plus.

Run the checklist automatically

Paste a public GitHub repository and get a grade with ranked findings in seconds, no account needed. For a private repository or your live app, create a free account.

Run a free scanView on GitHub