Find security holes AI tools left behind.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 500+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 210+
- vulnerability classes covered
- 270+
- passive checks / scan
- 120+
- active checks / scan
- 150+
- GitHub checks / scan
Compatible with
Scan websites and apps built with AI coding tools.
Deploy from Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit, and more. FixVibe checks the shipped URL and repo for security gaps AI-generated apps tend to miss.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Latest research
New vulnerabilities, every day.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- highresearch note
Anthropic's Fever Dream: Claude's Package That Stole Real Keys
Recent security research highlights risks in AI-assisted development and software supply chains, where dependency confusion or malicious package injections can lead to the exfiltration of sensitive credentials [S1].
- mediumresearch note
Stored XSS in osTicket Installation Script (CVE-2019-14750)
A stored cross-site scripting (XSS) vulnerability was identified in osTicket versions prior to 1.10.7 and 1.12.x before 1.12.1. The flaw exists in the setup/install.php script due to a lack of input sanitization in the firstname and lastname fields. Attackers can exploit this to inject malicious scripts that execute in the context of other users' browsers.
- criticalresearch note
Remote Code Execution in Sourcecodester Doctor's Appointment System 1.0 (CVE-2022-28568)
Sourcecodester Doctor's Appointment System 1.0 contains a critical vulnerability (CVE-2022-28568) that allows authenticated administrators to upload malicious files via the image upload feature, leading to Remote Code Execution (RCE).
Current research, practical context, and coverage updates when checks ship.
All research →