Help & answers

Frequently asked questions

Everything about the free security scan for AI-built apps — how it works, what it checks, what it costs, and what happens to your data.

How do I know if my app is leaking data?

Paste your app's URL into the free scan at vibecodingsecure.com. In about 10 seconds we check whether your database, API keys or user data are readable by anyone on the internet — the most common security flaw in AI-built apps.

I built my app with Lovable, Bolt or Replit. Is it safe?

Often not by default. AI app builders like Lovable, Bolt.new, Replit or v0 can ship with open database rules or API keys embedded in the frontend. That's exactly what our scanner checks for.

What is an exposed Supabase key and why does it matter?

If your Supabase project has open Row Level Security or a service_role key visible in your app's code, anyone can read — or delete — your entire database. The same applies to open Firebase rules.

Is the scan safe to run on my app?

Yes. The scan is passive and read-only. We only read what's already publicly visible — the same things an attacker would see — and never modify your app or your data. You should only scan apps you own or have permission to test.

What does the free scan check for?

Open Supabase, Firebase and Base44 databases, leaked API keys (OpenAI, Anthropic, OpenRouter, Stripe and others), exposed secret keys, weak TLS or connection security, and missing browser security headers. The free scan tells you whether a problem exists; the paid report shows the exact flaw and how to fix it.

How much does VibeCodingSecure cost?

The scan is free with no signup. A full report for one domain — proof of each flaw plus a ready-to-paste fix — costs €19. Continuous monitoring, which re-scans your app weekly and emails you if something changes, starts at €20 per month (€200 per year), with a Monitoring Pro tier at €35 per month (€350 per year).

Do you store my data or the scan results?

The free scan does not store what it finds. We only report the impact of any flaw, not the exposed data itself. Paid reports and monitoring keep only what's needed to show you the flaw and track changes over time.

Which app builders and technologies do you support?

Any web app, whatever it was built with. We focus on the stacks common in AI-built apps: Supabase, Firebase, Base44, Replit, Stripe, and the major AI providers (OpenAI, Anthropic, OpenRouter). Apps made with Lovable, Bolt.new, v0 and similar tools are exactly who we built this for.

Check your app now

Free, no signup. If we find nothing, good for you.

Scan your app free