Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••
Apple iOS & macOSDieses kleine Gadget für 19,95 Euro gehört in jedes Auto(01.10.2026 um 09:50 Uhr)
•
Android Tipps & SecurityJetzt ist auch Huawei bei neuen Smartphones betroffen(01.10.2026 um 10:07 Uhr)
•
Android Tipps & SecurityUSB verbessert: Neuer Fire TV Stick 4K jetzt ohne Android und Apps(01.10.2026 um 10:00 Uhr)
••••••••
Apple iOS & macOSDieses kleine Gadget für 19,95 Euro gehört in jedes Auto(01.10.2026 um 09:50 Uhr)
•
Android Tipps & SecurityJetzt ist auch Huawei bei neuen Smartphones betroffen(01.10.2026 um 10:07 Uhr)
•
Android Tipps & SecurityUSB verbessert: Neuer Fire TV Stick 4K jetzt ohne Android und Apps(01.10.2026 um 10:00 Uhr)
••••••
Intelligence View
⚡ tsecurity.de Intelligence

I built a security scanner specifically for vibe coded apps

Last summer I started messing around with Cursor, Bolt, Lovable - the usual suspects. Built a few small projects. Shipped fast. Felt great. Then my day job…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Last summer I started messing around with Cursor, Bolt, Lovable - the usual suspects. Built a few small projects. Shipped fast. Felt great.



Then my day job brain kicked in. I'm a security engineer. So I started poking at my own apps.



Not great.



Then I started looking at other vibe-coded apps. Worse.



The same issues kept showing up:




  • Missing Supabase RLS policies - This one's everywhere. Your database is basically public. Anyone with the Supabase URL can read/write whatever they want.


  • Weak or missing HTTP security headers - No CSP, no X-Frame-Options, nothing. Low-hanging fruit for attackers.


  • No rate limiting - Your login page will happily accept 10,000 password attempts per second.


  • Weak password policies - "password123" is perfectly acceptable.




AI tools are incredible at building features fast. They're not great at thinking about who might try to break those features.






So I built a scanner specifically for this.



It's an external scan - just paste your URL and it runs. The core scan takes about 5 minutes and is free. Full results are $5.



I optimized it for the specific patterns and mistakes AI-generated code tends to make. It's not a generic "enterprise security audit" - it's built for people who shipped something with Bolt last weekend and want to know if it's leaking data.



→ vibeappscanner.com



Would love feedback from this community. What security stuff are you worried about with your vibe-coded projects? What would you want a tool like this to check for?

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I built a security scanner specifically for vibe coded apps

Thematisch verwandte Begriffe: built, security, scanner, specifically · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag