A 10-minute security checklist before you launch a vibe-coded app
· 6 min read
You built something real with Lovable, Bolt, Cursor or another AI tool, and people are about to sign up. Before you share the link, spend ten minutes on these checks. Each one closes a gap we see often in AI-built apps.
1. No secret keys in the front end
Open your site, press F12 and search all files for sk-, sk_live, service_role and sb_secret_. Anything secret you find is public. Rotate it and move the call to the server. Full walkthrough: how to check if your API keys are exposed.
2. Database rules are on
If your app talks to Supabase or Firebase from the browser, the database rules are your only lock. Every Supabase table needs Row Level Security with a policy based on the signed-in user. Firebase needs Security Rules that are not left in test mode. See anon vs service_role keys.
3. Private routes require a login
Try your API routes in a private browser window, signed out. Anything that returns user data should answer 401 or 403, not the data.
4. Expensive routes have limits
Routes that send email, call an AI model or charge money need rate limiting. Otherwise one script can run up your bill overnight.
5. Session cookies are locked down
In F12 → Application → Cookies, your session cookie should have Secure, HttpOnly and SameSite set.
6. Security headers are set
At minimum: Content-Security-Policy, Strict-Transport-Security, frame-ancestors, X-Content-Type-Options and Referrer-Policy. Values and where to set them: 6 security headers every AI-built app should send.
7. No files that should be private
Visit /.env, /.git/HEAD and /package.json on your live domain. Each one should return a 404, not a file.
8. No source maps in production
Source maps (.js.map files) let anyone read your original code. Turn them off for production builds unless you upload them privately to an error tracker.
9. Errors don't leak details
Trigger an error (a broken URL, a bad form value). The page should show a friendly message, not a stack trace, file paths or database errors.
10. Everything is HTTPS
http://yourdomain.com should redirect to https://, and no page should load images or scripts over plain http://.
Prompt for your coding agent
Run a pre-launch security review of this app and fix issues in priority order:
secrets in client code, database rules (Supabase RLS / Firebase Security Rules),
authentication on private API routes, rate limits on expensive routes, session cookie flags,
security headers, exposed .env/.git/package.json files, production source maps,
verbose error pages, and HTTPS redirects. Explain each fix and how to verify it.
Using a specific tool? Read the guide for Lovable, Bolt, Supabase, Cursor or Next.js.
Check your app in minutes
Paste your URL and get a plain-English report with prioritized risks and a fix prompt for your AI. Your first scan is free.
Scan my app free