The Vibe-Coding Security Checklist: 12 Things to Fix Before Launch
By Pouyan · Updated August 2026
AI coding tools, Claude Code, Cursor, Lovable, Bolt, Replit, v0, are astonishingly good at turning an idea into a working app. What they don't do is guarantee that app is safe for real users. This checklist is the gap between a working prototype and a product you can launch without leaking your users' data.
Work through it in order, the first few are the ones that actually get apps breached. Each item says what to check and why it matters.
The critical five: do these before anyone signs up
1. No open database tables
The single most common breach in AI-built apps: a Supabase (or Firebase) table anyone can read without logging in. Turn on Row-Level Security for every table and add a policy per table. Full walkthrough: check your Supabase RLS.
2. No secrets in your frontend
View your live app's source and search its JavaScript for anything like sk_live_, service_role, AWS keys, or PRIVATE KEY. Secret keys belong only in server-side code, never in what the browser downloads. Anything visible can be copied and used.
3. Every private API route checks for a login, on the server
Hiding a page in the interface is not protection. The endpoint underneath must reject requests that aren't authenticated. Test it: call your data endpoints without a session and confirm they return "unauthorized," not data.
4. Admin routes are locked down
Open your admin and dashboard pages in an incognito window (logged out). They should redirect to login. If admin data loads, the guard is cosmetic, move it to the server.
5. Authentication actually works
Confirm the obvious things really hold: you can't reach another user's data by changing an id in the URL, password reset can't be abused, and sessions expire. AI tools sometimes wire auth logic backwards, blocking logged-in users and letting anonymous ones through, so test both paths.
The next seven: before you scale
6. Rate limiting
Without limits, endpoints can be brute-forced, scraped, or abused to run up bills, especially any route that calls a paid AI or email service. Add sensible per-user and per-IP limits.
7. Security headers
Set Content-Security-Policy, Strict-Transport-Security, and X-Content-Type-Options. They're a free layer against content injection and protocol downgrade.
8. HTTPS everywhere
The whole app must be served over HTTPS, with HTTP redirecting to it. On modern hosts (Vercel, Netlify) this is usually automatic, confirm it's actually enforced.
9. CORS locked to your own domain
An API that answers Access-Control-Allow-Origin: * combined with cookie-based login can let a malicious site act on your users' behalf. Restrict it to your own origin.
10. Backups you've actually tested
Confirm your database is backed up and that you know how to restore it. An untested backup is a hope, not a safety net.
11. Error tracking
Add something (Sentry, your host's logs) that tells you when the app breaks in production, otherwise your users are your monitoring, and they leave instead of reporting.
12. Cost controls
Set spending caps and alerts on any paid service the app calls. "It cost $20 to build" can quietly become "$2,000 this month" when an unprotected endpoint gets discovered.
How to run the whole list at once
You can work through the list above yourself, and this guide is meant to let you do exactly that. If you would rather have someone look at it, send me your app's address and I will go through it myself before we speak, then tell you what I found in half an hour. It is free, there is no pitch at the end, and if your app is in good shape I will tell you that.
Building specifically with Lovable? Start with is my Lovable app secure?
Common questions
What does 'production-ready' actually mean for a vibe-coded app?
It means the app is safe and stable enough for real users and real data: no exposed secrets, no open database tables, every private route requires a login, sensible rate limits, backups, and error tracking so you find out when something breaks. A prototype proves the idea works; production-ready means it won't leak data or fall over when strangers arrive.
Which of these checks are the real emergencies?
Anything that exposes user data or a live secret right now: an open database table, a leaked API key in your frontend, an admin or data endpoint that responds without a login. Fix those before you invite anyone. Missing headers, no rate limits, and no backups are important but not same-day emergencies.
I'm not technical, can I do this myself?
You can do the checks (view source for secrets, open your database dashboard, try admin pages logged out), but interpreting and fixing the findings is where an engineer helps. If you want a second opinion, a senior engineer can look at your live app and tell you in half an hour whether you have a real problem, before you spend money fixing one.
Does this apply to Bolt, Replit, Cursor and v0 too, or just one tool?
All of them. Lovable, Bolt, Replit, v0, Cursor, Claude Code, Windsurf, they generate the same underlying stacks (React, Next.js, Supabase, Firebase, Vercel), so they share the same failure modes. This checklist applies whatever you built with.
Not sure if yours is affected?
Send me your app's address. I'll look at it myself before we speak, then we take half an hour and I'll tell you what I found in normal words. Free, no pitch, and if it's in good shape I'll tell you that too.
Pouyan Ahmadpour · engineer · Amsterdam
Keep reading
- Is My AI-Built App Ready for Real Users? What Breaks First
The parts that only fail on the day you succeed.
- Is My Claude Code App Secure? What Agents Quietly Skip
What the agent built, and what it never mentioned it skipped.
- Is My Lovable App Secure? A Plain-English Safety Check
The checks that matter before you let real users in.
- Supabase Row-Level Security
The single most common way vibe-coded apps leak user data.
- My Vibe-Coded App Got Hacked
The calm, step-by-step response when the worst has happened.
- My Supabase API Key Is Exposed
Found your key in the code? Here's what's actually at risk.
- Is My Bolt App Secure? The Checks That Matter Before Launch
What to check on a Bolt.new app before real users arrive.
- Is My Replit App Secure? A Plain-English Safety Check
The Replit-specific gotchas, plus the universal checks.
- Firebase Security Rules
The Firebase version of the open-database problem.
- What Does It Cost to Secure a Vibe-Coded App?
What an audit and fixes actually cost, and what you get.