Find security holes AI tools left behind.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 500+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 240+
- vulnerability classes covered
- 280+
- passive checks / scan
- 130+
- active checks / scan
- 160+
- GitHub checks / scan
Compatible with
Scan websites and apps built with AI coding tools.
Deploy from Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit, and more. FixVibe checks the shipped URL and repo for security gaps AI-generated apps tend to miss.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Latest research
New vulnerabilities, every day.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- informationalnot automatically checked
Why Open WebUI CVE-2024-7959 Was Rejected
The SSRF advisory associated with Open WebUI's /openai/models endpoint was withdrawn. GitHub says the advisory does not describe a valid vulnerability, and NVD records that the CVE Numbering Authority rejected or withdrew CVE-2024-7959.
- criticalresearch note
Spring Web Services XXE Vulnerability CVE-2019-3773
CVE-2019-3773 is a critical XML External Entity vulnerability in older Spring Web Services releases that process untrusted XML. Spring advises upgrading the spring-ws and spring-xml components to 2.4.4, 3.0.6, or later.
- criticalnot automatically checked
Lantronix EDS5000 CVE-2025-67038 Command Injection
CVE-2025-67038 is a critical command-injection vulnerability affecting several Lantronix device families, including EDS5000. CISA lists the issue as known exploited, and Lantronix has published fixed firmware and network-restriction guidance.
Current research, practical context, and coverage updates when checks ship.
All research →