Free security scan for vibe-coded apps

Built your app with AI? A stranger could get in or wipe it out tonight.

Many AI-built apps leave the door wide open without you knowing. Anyone could peek at your customers' private info, or even erase everything you've built. Paste your link and find out in seconds. Free, no tech skills needed.

Free · no signup · instant result
report · my-app.com 3 issues found
Data Breach — Anyone on the internet can read your users' private data.
Exposed API key — Your OpenAI key is public. Anyone can spend on your account.
Weak database rules — Strangers could write junk into your database.
See the full report & how to fix it →
100apps scanned
12%exposed something critical
7technologies covered
~10sper scan

What we detect

One engine per technology. Each one hunts the flaw that's typical of AI-generated apps: exposed Supabase keys, open Firebase rules, leaked API keys.

Supabase
open RLS · service_role
Firebase
open database rules
Replit
leaked Replit DB URL
Stripe
secret sk_live key
OpenAI
exposed API key
Anthropic
exposed sk-ant key
OpenRouter
exposed sk-or key
+ more coming

How it works

01

Paste your URL

Nothing to install. Drop in your app's address and go.

02

We check it

We look at your app and your database — with your permission — for anything left exposed.

03

Fix it

We show you the exact fix in plain steps — no jargon, no guessing.

You don't need to be a developer to fix it.

We explain what's wrong in plain English, then walk you through the fix in a few simple steps — or hand you a ready-made note to send to whoever built your app.

How to fix it — no jargon
1

We show you exactly what's putting your data at risk.

2

Follow a few simple steps to close it — we show you where to click.

3

Scan again to check. Green means you're safe.

Rather not touch it yourself? Copy our ready-made note and send it to whoever built your app.

Simple pricing

Scanning is free. You only pay if you want the detail and the fix.

Free
See if you have a problem
€0
Surface scan Detects whether there are flaws No signup
Monitoring
Make sure it stays fixed
€12 / month
Weekly re-scan Email alert if something changes Cancel anytime

Frequently asked questions

How do I know if my app is leaking data?

Paste your app's URL into the free scan. In about 10 seconds we check whether your database, API keys or user data are readable by anyone on the internet — the most common security flaw in AI-built apps.

I built my app with Lovable, Bolt or Replit. Is it safe?

Often not by default. AI app builders like Lovable, Bolt.new, Replit or v0 can ship with open database rules or API keys embedded in the frontend. That's exactly what our scanner checks for.

What is an exposed Supabase key and why does it matter?

If your Supabase project has open Row Level Security or a service_role key visible in your app's code, anyone can read — or delete — your entire database. The same applies to open Firebase rules.

Is the scan safe to run on my app?

Yes. We only read what's already publicly visible — the same things an attacker would see. We never modify your app or your data, and you should only scan apps you own or have permission to test.

See for yourself in 10 seconds

Scan your own app for free. If we find nothing, good for you.