VibeShield
Security scanner for Cursor apps

Free Cursor security scanner

Cursor writes code fast, and you deploy it wherever you like. That flexibility means nothing is secure by default: the checks a hosted builder might do for you are now your job.

What we check on Cursor apps

Typical stack: Any stack — AI-written code you deploy yourself

Exposed .env and .git files

A misconfigured server can serve your .env or your whole git history to anyone who asks. VibeShield checks for these and other sensitive files, and reports only that they're reachable — never their contents.

Hardcoded keys and tokens

AI assistants happily inline an API key to get a demo working. VibeShield scans your shipped JavaScript and page data for real credentials.

Permissive CORS

“Access-Control-Allow-Origin: *” pasted in to fix a dev error, combined with credentials, turns your API into everyone's API.

Missing security headers

No Content-Security-Policy, HSTS or clickjacking protection means one injected script or a framing attack goes unchecked. VibeShield tells you which headers are missing and what to set.

Found something? Fix it in Cursor.

  • Scan your live URL in seconds — no signup for the first security scan
  • Signed-in scans cover security, accessibility, SEO & AEO, and bundle in one report
  • Every issue explained in plain English, ranked by what to fix first
  • A copy-paste prompt that fixes each issue in the tool you built with

Want it watched for you? Pro adds weekly schedules, email alerts, and active attack checks. Business adds deploy webhooks, daily schedules, Slack/Discord, and GitHub scanning.

Also built with: Lovable · Bolt · v0 · Replit