Ship fast without shipping the vulnerabilities
Field notes on securing AI-generated apps - security headers, DMARC, TLS, performance, and the gaps that ship silently when you build in days instead of months.
7 articles
Replit App Security: What's Missing by Default
A public Repl doesn't just expose your app, it can expose your source and hardcoded secrets to anyone with the URL. Here's the checklist most builders skip.
Bolt.new App Security: What's Missing by Default
Bolt.new wires up Supabase in seconds, but Row-Level Security, headers, and DNS records still aren't set. The security checklist most builders skip.
v0 App Security: What's Missing by Default
v0 ships clean React and Next.js code fast, but one misplaced NEXT_PUBLIC_ variable can leak a secret key straight to the browser. Here's the checklist.
FlawPilot MCP Server & API: Coming Next Week
FlawPilot's MCP server and public API launch next week - scan from Claude Code or Cursor, or call the API directly. Here's what's coming and why it matters.
Lovable App Security: A Real App, 29 Issues Found
Lovable app security, tested on a real app: a Supabase table with no Row-Level Security, wide open to anyone. Here's exactly what we found and how to fix it.
Cursor App Security: What's Missing by Default
Cursor writes fast, production-ready code, but headers, TLS, and DNS records still need manual setup. The cursor app security checklist most builders skip.