Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityCrystal Display Systems übernimmt Assets von Display & Control(29.09.2026 um 13:20 Uhr)
•
Windows Tipps & SecurityDFB und ZVEI veröffentlichen Leitfaden zur Stadionbeschallung(29.09.2026 um 13:30 Uhr)
•
Sicherheitslücken (CVE)DSA-6528-1 linux - security update(29.09.2026 um 02:00 Uhr)
••
Sichere ProgrammierungCronflower: Turn a Spring Boot app into a distributed cron cluster(29.09.2026 um 13:32 Uhr)
•
Sichere ProgrammierungRetry Is Not Recovery: A Practical Failure Model for Odoo Integrations(29.09.2026 um 13:33 Uhr)
•
Sichere ProgrammierungOne Rails App, Multiple Customers(29.09.2026 um 13:33 Uhr)
•
Sichere ProgrammierungHello dev.to! Here is my BenchmarkingRealWork series case 01.(29.09.2026 um 13:34 Uhr)
•
Sichere ProgrammierungHow to Automatically Turn Voice Notes Into To-Dos on Your Mac in 2026(29.09.2026 um 13:36 Uhr)
••
Windows Tipps & SecurityCrystal Display Systems übernimmt Assets von Display & Control(29.09.2026 um 13:20 Uhr)
•
Windows Tipps & SecurityDFB und ZVEI veröffentlichen Leitfaden zur Stadionbeschallung(29.09.2026 um 13:30 Uhr)
•
Sicherheitslücken (CVE)DSA-6528-1 linux - security update(29.09.2026 um 02:00 Uhr)
••
Sichere ProgrammierungCronflower: Turn a Spring Boot app into a distributed cron cluster(29.09.2026 um 13:32 Uhr)
•
Sichere ProgrammierungRetry Is Not Recovery: A Practical Failure Model for Odoo Integrations(29.09.2026 um 13:33 Uhr)
•
Sichere ProgrammierungOne Rails App, Multiple Customers(29.09.2026 um 13:33 Uhr)
•
Sichere ProgrammierungHello dev.to! Here is my BenchmarkingRealWork series case 01.(29.09.2026 um 13:34 Uhr)
•
Sichere ProgrammierungHow to Automatically Turn Voice Notes Into To-Dos on Your Mac in 2026(29.09.2026 um 13:36 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

I built a security scanner specifically for vibe coded apps

Last summer I started messing around with Cursor, Bolt, Lovable - the usual suspects. Built a few small projects. Shipped fast. Felt great. Then my day job brain kicked in. I'm a security engineer. So I started poking at my own apps. Not…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Last summer I started messing around with Cursor, Bolt, Lovable - the usual suspects. Built a few small projects. Shipped fast. Felt great.



Then my day job brain kicked in. I'm a security engineer. So I started poking at my own apps.



Not great.



Then I started looking at other vibe-coded apps. Worse.



The same issues kept showing up:




  • Missing Supabase RLS policies - This one's everywhere. Your database is basically public. Anyone with the Supabase URL can read/write whatever they want.


  • Weak or missing HTTP security headers - No CSP, no X-Frame-Options, nothing. Low-hanging fruit for attackers.


  • No rate limiting - Your login page will happily accept 10,000 password attempts per second.


  • Weak password policies - "password123" is perfectly acceptable.




AI tools are incredible at building features fast. They're not great at thinking about who might try to break those features.






So I built a scanner specifically for this.



It's an external scan - just paste your URL and it runs. The core scan takes about 5 minutes and is free. Full results are $5.



I optimized it for the specific patterns and mistakes AI-generated code tends to make. It's not a generic "enterprise security audit" - it's built for people who shipped something with Bolt last weekend and want to know if it's leaking data.



→ vibeappscanner.com



Would love feedback from this community. What security stuff are you worried about with your vibe-coded projects? What would you want a tool like this to check for?

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I built a security scanner specifically for vibe coded apps

Thematisch verwandte Begriffe: built, security, scanner, specifically · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102247 | A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag