Security for apps from Lovable, Bolt, v0, Cursor and Replit
AI tools generate a working app in minutes — often with API keys in the JS bundle, an exposed .env file and production source maps switched on. Vibe Check scans your app from its public URL, fingerprints which tool built it (Lovable, Bolt, v0, Cursor, Replit) and offers a tool-specific fix.
200 deterministic checks across 8 categories: leaked keys, exposed .env, source maps, unprotected AI endpoints, missing security headers, CORS, exposed admin panels, malware detection and more. Every finding comes with a copy-paste fix. No code access; results in roughly 8 seconds.