VibeShield

Security checklist

The vibe-coding security checklist

11 things to check before you launch an app built with Lovable, Bolt, v0, Cursor or Replit. Most of them VibeShield checks for you in one free scan.

  1. 1Turn on Row Level Security for every Supabase table

    Checked: Free scan

    Why: Your Supabase public key ships to every visitor. Without RLS, anyone can use it to download your whole table.

    Enable RLS on each table and add policies that check auth.uid() against the row's owner.

  2. 2Keep secret keys out of the browser

    Checked: Free scan

    Why: An OpenAI, Stripe secret or Supabase service_role key in your JavaScript can be copied by anyone and run up your bill or open your data.

    Call those APIs from a server route or edge function, and use only publishable keys in the frontend.

  3. 3Never put secrets in VITE_ or NEXT_PUBLIC_ variables

    Checked: Free scan

    Why: Build tools copy these straight into the code your visitors download.

    Rename secret variables without the public prefix and read them only on the server.

  4. 4Require email confirmation on sign-up

    Checked: Free scan

    Why: Otherwise anyone can create accounts with email addresses they don't own.

    In Supabase: Authentication → Providers → Email → turn on “Confirm email”.

  5. 5Set the security headers

    Checked: Free scan

    Why: Content-Security-Policy, HSTS, X-Frame-Options and X-Content-Type-Options block whole classes of attacks for free.

    Add them in your host's config (vercel.json, netlify.toml) or your framework's headers setting.

  6. 6Make sure .env, .git and backups aren't public

    Checked: Free scan

    Why: A misconfigured host can hand out your environment file or entire git history.

    Keep them out of your public/ folder and deploy output; block dotfiles at the server.

  7. 7Lock down CORS

    Checked: Free scan

    Why: Reflecting any origin while allowing credentials lets other sites act as your logged-in users.

    Allow only your own domains, and never combine a wildcard with credentials.

  8. 8Rate-limit login, sign-up, password reset and AI endpoints

    Checked: Pro

    Why: Unlimited attempts invite credential stuffing — and an open AI route can burn through your API budget overnight.

    Add rate limiting at the edge (Vercel, Cloudflare) or in middleware.

  9. 9Check permissions on the server, not only in the UI

    Checked: Pro

    Why: Hiding an admin button isn't protection — the page or API behind it must refuse requests too.

    Verify the user's session and role in every server route and database policy.

  10. 10Rotate any key that was ever exposed

    Do it yourself

    Why: Deleting a leaked key from your code doesn't un-leak it — it's in your git history and possibly in someone's hands.

    Generate a new key in the provider's dashboard and revoke the old one.

  11. 11Re-check after every deploy

    Checked: Business

    Why: Every new prompt can change your app — and quietly undo a fix.

    Use a deploy webhook (Vercel, Netlify, or any CI) so each successful deploy triggers a scan and alerts on new critical/high issues.

Check your app against this list in seconds

Free, no signup, using only your public URL.