Free Bolt security scanner
Bolt builds and deploys full-stack apps from a prompt. Most use Supabase for data and Vite for the frontend — and Vite inlines every VITE_-prefixed variable straight into the JavaScript your visitors download.
What we check on Bolt apps
Typical stack: Vite or Next.js + Supabase, deployed to Netlify
Anything named VITE_… is public by definition, including the keys an AI put there to “make it work”. VibeShield scans your shipped bundles for OpenAI, Stripe, AWS, Supabase service and other secret keys.
Your Supabase anon key ships to every visitor by design — that's fine only if Row Level Security is on. With RLS off, anyone can copy the key from the network tab and download every row. VibeShield checks each exposed table's row count (never the data itself).
Published .map files hand anyone your original, readable source code — including comments and internal API routes. VibeShield checks whether they're reachable.
No Content-Security-Policy, HSTS or clickjacking protection means one injected script or a framing attack goes unchecked. VibeShield tells you which headers are missing and what to set.
Found something? Fix it in Bolt.
- Scan your live URL in seconds — no signup for the first security scan
- Signed-in scans cover security, accessibility, SEO & AEO, and bundle in one report
- Every issue explained in plain English, ranked by what to fix first
- A copy-paste prompt that fixes each issue in the tool you built with
Want it watched for you? Pro adds weekly schedules, email alerts, and active attack checks. Business adds deploy webhooks, daily schedules, Slack/Discord, and GitHub scanning.