Tell Me When Down
How it worksWhat we checkPricing
BlogFree toolsCompareDocs
Log inGet started
All posts
Vibe security

Security for vibe-coded apps

The risks specific to AI-generated apps, and a plain-English checklist to close them before someone else finds them.

A vaulted stone cloister in low light — a database only as secure as the walls built around it.
Vibe security·July 18, 2026·7 min

How to secure a Supabase app: the five settings that matter

A Supabase app can be wide open, almost always for the same handful of reasons: RLS off, the service_role key in the browser, public buckets, unguarded functions, secrets in the bundle. Here's the map to closing each one.

A glowing neon "OPEN" sign in the dark — a database left open to anyone who holds the public key.
Vibe security·July 18, 2026·6 min

Is my Supabase database public? RLS, and how to check

Your Supabase anon key is public by design — safe only if RLS is on with a real policy. Tables made outside the Table Editor ship with it off, and USING(true) is still open. Here's how to check if your data is public.

Antique keys scattered on black — a credential left in plain sight among many.
Vibe security·July 18, 2026·6 min

My API key is showing on my website — is that bad?

An API key visible in your frontend is a shrug or an emergency depending on which kind it is. Public keys (anon, pk_, Maps) are meant to be seen; secret keys are compromised the instant they ship. How to tell, and what to do.

A grand house facade lit at night — an app that looks finished, its doors not yet checked.
Vibe security·July 18, 2026·6 min

Is my app built with AI safe? A non-developer's check

You built an app with AI, it works, and you're quietly worried it's not safe — but you can't read code. Here are the four plain-English questions that matter, and how to check each one without being a developer.

An open door spilling light into a dark room — a database left reachable without its access rules set.
Vibe security·July 18, 2026·6 min

Is Lovable secure? The one setting that decides it

A Lovable app can be wide open, and the difference is one setting most builders never touch. The anon-key/RLS model, the gap behind a 2025 CVE, and how to check yours.

A half-built structure lit at night — an app generated fast, with the doors not yet locked.
Vibe security·July 18, 2026·6 min

Is Bolt.new secure? What the generated app leaves open

Bolt.new builds a working full-stack app fast — which is why the security gets skipped. The usual gaps: a Supabase database with RLS off, secrets in the bundle, UI-only authorization. Here's how to audit yours.

A lit window seen from outside in the dark — a generated app whose internals may show more than intended.
Vibe security·July 18, 2026·6 min

Is v0 secure? Keeping a generated Next.js app's secrets in

v0's Next.js output looks production-ready, which is the trap. NEXT_PUBLIC_ bakes a var into the bundle, and a secret in a client component ships to the browser. Here's how to check a v0 app keeps its secrets in.

An unlocked padlock resting on a laptop keyboard in low light — an app shipped without its defenses set.
Vibe security·July 18, 2026·6 min

Vibe coding security risks: the checklist nobody runs

The appeal of vibe coding is that you don't read every line — which is exactly why the holes get through. Exposed secrets, a database anyone can read, rules enforced only in the UI, and how to close each one.

more topics
Free-tier sleepSecurity checksSilent cronStripe webhooksSite down
Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botSupportPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com