Security checklist
The vibe-coding security checklist
11 things to check before you launch an app built with Lovable, Bolt, v0, Cursor or Replit. Most of them VibeShield checks for you in one free scan.
1Turn on Row Level Security for every Supabase table
Checked: Free scanWhy: Your Supabase public key ships to every visitor. Without RLS, anyone can use it to download your whole table.
Enable RLS on each table and add policies that check auth.uid() against the row's owner.
2Keep secret keys out of the browser
Checked: Free scanWhy: An OpenAI, Stripe secret or Supabase service_role key in your JavaScript can be copied by anyone and run up your bill or open your data.
Call those APIs from a server route or edge function, and use only publishable keys in the frontend.
3Never put secrets in VITE_ or NEXT_PUBLIC_ variables
Checked: Free scanWhy: Build tools copy these straight into the code your visitors download.
Rename secret variables without the public prefix and read them only on the server.
4Require email confirmation on sign-up
Checked: Free scanWhy: Otherwise anyone can create accounts with email addresses they don't own.
In Supabase: Authentication → Providers → Email → turn on “Confirm email”.
5Set the security headers
Checked: Free scanWhy: Content-Security-Policy, HSTS, X-Frame-Options and X-Content-Type-Options block whole classes of attacks for free.
Add them in your host's config (vercel.json, netlify.toml) or your framework's headers setting.
6Make sure .env, .git and backups aren't public
Checked: Free scanWhy: A misconfigured host can hand out your environment file or entire git history.
Keep them out of your public/ folder and deploy output; block dotfiles at the server.
7Lock down CORS
Checked: Free scanWhy: Reflecting any origin while allowing credentials lets other sites act as your logged-in users.
Allow only your own domains, and never combine a wildcard with credentials.
8Rate-limit login, sign-up, password reset and AI endpoints
Checked: ProWhy: Unlimited attempts invite credential stuffing — and an open AI route can burn through your API budget overnight.
Add rate limiting at the edge (Vercel, Cloudflare) or in middleware.
9Check permissions on the server, not only in the UI
Checked: ProWhy: Hiding an admin button isn't protection — the page or API behind it must refuse requests too.
Verify the user's session and role in every server route and database policy.
10Rotate any key that was ever exposed
Do it yourselfWhy: Deleting a leaked key from your code doesn't un-leak it — it's in your git history and possibly in someone's hands.
Generate a new key in the provider's dashboard and revoke the old one.
11Re-check after every deploy
Checked: BusinessWhy: Every new prompt can change your app — and quietly undo a fix.
Use a deploy webhook (Vercel, Netlify, or any CI) so each successful deploy triggers a scan and alerts on new critical/high issues.
Check your app against this list in seconds
Free, no signup, using only your public URL.