Security scanningfor AI-built apps
Finds exposed secrets, misconfigured RLS, and auth bugs in apps built with Lovable, Bolt, Cursor, or Claude. No GitHub access needed.
53 of 61 lacked standard headers·14 critical findings·May 2026 early samplemethodology →
Example finding
Supabase RLS disabled on users
Anon key exposed in client bundle. Any visitor can read and write all rows without auth.
Fast first-pass review. Not a penetration test. Checks the public surface and artifacts you provide. Cannot prove your app is fully secure. See our research on AI-built app vulnerabilities →
Traditional scanners
- Require GitHub OAuth before scanning
- Miss AI-generated patterns like open RLS policies
- Return findings with no fix guidance
VibeScan URL Scan
- Checks live surface. No repo access needed
- Catches RLS gaps, inverted auth, exposed secrets
- Fix prompts you paste back into your builder
From the same maker
Two tools. One guarantee: no secrets leak.
VibeScan · Web
Scan your deployed app
Checks your live app's surface for exposed API keys, misconfigured Supabase RLS, missing security headers, and more. No code or repo access needed.
Sieve · macOS
Guard your local secrets
Before you push: scan local AI coding histories and environment files for leaked API keys and credentials. Processing stays on your Mac.
Get Sieve for MacVibeScan catches what's already live. Sieve catches what's about to ship. Use both.
AI tools generate code fast. The security gaps they leave behind are systematic — the same patterns appear across Lovable, Bolt, Cursor, and Claude-built apps. VibeScan checks for the most common ones without requiring access to your source code.
VibeScan's first 61 completed scans found 14 critical findings, including live Stripe secrets and Twilio credentials in public JavaScript. VibeScan fetches your deployed bundle, scans for credential patterns, and decodes JWTs to check for privileged roles.