DevMeth

For everyone shipping AI-built apps

Vibe coding security, checked

Every Lovable app ships with Supabase RLS disabled by default. Yours probably did too. Find out in 2 minutes — free.

The pattern, not the paranoia

Vibe coding — building by prompting Lovable, Cursor, v0, Bolt, or plain ChatGPT — produces working apps with the same handful of security holes, because the models learned from the same tutorials and optimize for the demo. Independent checks keep finding it: a study of 170+ Lovable apps found recurring Supabase misconfigurations, and a developer who checked 50 Lovable apps' databases directly found most with no Row Level Security. The tools are getting better; the defaults are still not safe.

What actually goes wrong

Five failure classes cover most incidents: exposed secrets (API keys in source, bundles, and git history), databases readable by anyone (RLS and rules), routes that skip access checks, wide-open web configuration, and unvalidated input. Each is checkable by reading code — which is exactly what a pre-flight scan does, deterministically, before you ship.

Browse the failure patterns

  • Secrets scanning for AI-built apps — Hardcoded API keys, committed .env files, secrets in client bundles and git history — 10 checks that catch what AI tools leak. Scan free.
  • Authentication & access control, checked — Open admin pages, authless API routes, weak JWT secrets, IDOR, client-side role checks — 12 checks for the auth gaps AI tools leave behind.
  • Input validation & injection checks — SQL injection, XSS, SSRF, path traversal, mass assignment — 10 checks for the input-handling bugs AI-generated code ships with.
  • Web hardening before you launch — Wide-open CORS, live debug endpoints, exposed .git, stack-trace leaks, HTTPS and HSTS — 8 checks to run before an AI-built app goes live.
  • Supabase & Firebase security checks — Supabase RLS left disabled, permissive policies, Firebase rules, browser-direct database access — 5 checks for hosted-backend exposure in AI-built apps.
  • Dependency vulnerabilities & drift — Known CVEs in your dependency tree, framework CVEs with middleware-only fixes, and hallucinated packages that don't exist — 3 dependency checks.
  • It works. But what did the agent leave behind? — Dead code, copy-pasted blocks, hallucinated imports, untested routes, drift — the 12-check AI tech-debt scan with a Debt Score and fix prompts.

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan