Back to All Insights
🔒

App Security

Security audits, vulnerability findings, and hardening guidance for AI-built and vibe-coded applications.

12 articles
Aug 14, 20267 min read

Security Scan Tools for AI-Built Apps Compared: 8 Options for 2026

8 ways to security-scan an AI-built or vibe-coded app compared: Semgrep, Snyk, GitHub code scanning, SonarQube, Aikido, OWASP ZAP, manual pentests, and config-level scans. What each catches, what each misses, and typical 2026 pricing.

AI code securityvibe coding securitysecurity scanner comparison
Jul 31, 20266 min read

How to Secure a Vibe-Coded App Before You Tell Anyone It Exists

A pre-launch security pass for AI-built apps: bundled keys, missing RLS, open API routes. What I check in 20 reviews, and how to do it yourself in 90 minutes.

vibe codingapp securitysupabase rls
Jul 28, 20266 min read

Why Your API Key Ends Up in the Frontend Bundle (And How to Catch It)

The exact mechanism that ships secret keys to the browser in AI-built apps, and the 5-minute grep that catches it before launch.

api key in frontendenvironment variablesai-built apps
Jul 27, 20266 min read

Your Supabase Anon Key Is Public. Here's What That Does and Doesn't Mean

Someone found your anon key in the bundle. Is that a breach? Here's what the anon key actually grants, and the RLS mistake that turns it into one.

supabaseanon keyrow level security
Jul 22, 20267 min read

Is v0 Safe to Ship From? What Vercel's Generator Does (and Doesn't) Check

v0 generates real Next.js on real Vercel infra. Here's the env var that leaks to the browser, the service role key, and the server action nobody checks.

v0 securityvercel ai app buildervibe coded app security
Jul 16, 20265 min read

Is Bolt.new Safe for Production Apps? Reading the Security Fine Print

Bolt.new ships full-stack apps in minutes. Here's the RLS default and env-var trap its speed skips, plus a 90-second self-check.

bolt.new securityvibe coded app securitysupabase rls
Jul 13, 20266 min read

Is My Supabase Secure? A Practical Checklist Before You Launch

A working checklist for Supabase security: RLS policies, anon keys, service role leaks, and the mistakes I keep finding in AI-built apps.

supabaserlsrow-level-security
Jul 5, 20269 min read

I Scanned 66 AI-Built Apps: 4 in 10 Supabase Backends Had a Readable Table

A data report on 66 live apps built with Lovable, Bolt, Cursor, base44, and Tempo. 41% of the Supabase-backed apps had at least one table anyone could read with the public anon key. Methodology, findings, and a 60-second self-check.

vibe coded app securitysupabase rls exposedai built app data leak
Invalid Date1 min read

Invalid Date1 min read

Invalid Date7 min read

Invalid Date1 min read