VibeShield
Security scanner for Bolt apps

Free Bolt security scanner

Bolt builds and deploys full-stack apps from a prompt. Most use Supabase for data and Vite for the frontend — and Vite inlines every VITE_-prefixed variable straight into the JavaScript your visitors download.

What we check on Bolt apps

Typical stack: Vite or Next.js + Supabase, deployed to Netlify

Secrets in VITE_ variables

Anything named VITE_… is public by definition, including the keys an AI put there to “make it work”. VibeShield scans your shipped bundles for OpenAI, Stripe, AWS, Supabase service and other secret keys.

Supabase tables anyone can read

Your Supabase anon key ships to every visitor by design — that's fine only if Row Level Security is on. With RLS off, anyone can copy the key from the network tab and download every row. VibeShield checks each exposed table's row count (never the data itself).

Exposed source maps

Published .map files hand anyone your original, readable source code — including comments and internal API routes. VibeShield checks whether they're reachable.

Missing security headers

No Content-Security-Policy, HSTS or clickjacking protection means one injected script or a framing attack goes unchecked. VibeShield tells you which headers are missing and what to set.

Found something? Fix it in Bolt.

  • Scan your live URL in seconds — no signup for the first security scan
  • Signed-in scans cover security, accessibility, SEO & AEO, and bundle in one report
  • Every issue explained in plain English, ranked by what to fix first
  • A copy-paste prompt that fixes each issue in the tool you built with

Want it watched for you? Pro adds weekly schedules, email alerts, and active attack checks. Business adds deploy webhooks, daily schedules, Slack/Discord, and GitHub scanning.

Also built with: Lovable · v0 · Cursor · Replit