blog
Security for apps you built by prompting.
What leaks out of Lovable, Replit, Bolt, v0 and Cursor apps, how to check yours in a few minutes, and the exact prompts that fix it. Written for founders, not security teams.
RSS feed · new posts most weeks
Replit app security: six holes to check
Replit is trusted, with Secrets, Auth and its own scanner. Agent-built apps still ship with six holes: VITE_ keys, routes without auth checks, open CORS. Fix each.
API key exposed in your frontend JavaScript: the 10-minute response
Your API key is in the JavaScript every visitor downloads. The 10-minute response: rotate, check the damage, move the call server-side, clean VITE_ vars, verify.
Supabase RLS in Lovable apps: check every table
Find every Supabase table in your Lovable app with RLS disabled, spot policies that let everyone in, and fix them with copy-paste SQL or a Lovable prompt.
Is Lovable secure? And is your Lovable app?
Lovable is secure. Apps built with it leak in four ways: VITE_ keys, the service_role key, tables without RLS, GitHub sync. How to check yours and fix it.
The vibe coding security checklist
12 checks before strangers use your vibe-coded app: leaked keys, Supabase RLS, Firebase rules, .env in GitHub. Each with a 60-second check and a fix prompt.
Don't become a LinkedIn post
A founder ships an AI-built app Saturday. By Wednesday a stranger has the OpenAI key. By Thursday LinkedIn has 9,000 takes. The 10 minutes that prevent it.
Reading about it is step one.
Step two takes a minute: paste your app's address and see what it is actually showing strangers.