Live security scan · AI-built apps

Your AI shipped fast. Is it safe to launch?

Paste your live URL. We probe exposed keys, Supabase gaps, weak headers, and public files the way an attacker would. Every finding ships with a fix prompt for Cursor or Lovable.

Free surface scan · read-only · no signup · results in about 60 seconds

noetfield-scan
$ noetfield-scan --target your-app.com
Waiting for URL…

What we catch

Built for Lovable, Bolt, Cursor, and Supabase stacks

We test the failure modes that show up again and again on AI-generated MVPs.

Critical

Exposed API keys

Stripe, OpenAI, Anthropic, and service_role JWTs leaked in JavaScript bundles.

Critical

Supabase surface

REST endpoints and RLS gaps that let anonymous clients read or write data.

High

Security headers

Missing CSP, HSTS, X-Frame-Options, and other transport protections.

High

CORS misconfig

Wildcard origins on endpoints that should be locked to your domain.

Medium

Exposed files

Public .env, .git, package.json, and config files reachable from the internet.

Medium

Transport gaps

HTTP-only deploys and missing hardening on cookies and TLS.

How it works

Three steps from URL to fix prompt

  1. 1

    Paste your live URL

    We only need the address your customers already use. No repo access.

  2. 2

    We probe like an attacker

    Headers, bundles, Supabase hosts, and common exposed paths. Read-only GET requests.

  3. 3

    Copy fixes into your AI editor

    Each finding includes a prompt you paste into Cursor, Claude, or Lovable.

Vibe coding security

Free security scanner for Lovable, Bolt, Cursor, and Supabase apps

Noetfield Scan is a vibe coding security scanner built for founders who ship with AI. It is the fastest way to check whether your Lovable app, Bolt.new prototype, or Cursor project leaks Stripe keys, leaves Supabase row-level security off, or ships without CSP and HSTS.

AI-generated app vulnerability scan

Unlike generic header checkers, we probe live JavaScript bundles, public API surfaces, and database endpoints the way attackers search vibe-coded SaaS on Vercel and Netlify.

Supabase RLS and exposed secrets

Broken Supabase RLS is the top critical finding on AI-built stacks. We surface open REST paths and client-side service_role tokens before your launch post goes viral for the wrong reason.

Fix prompts for your AI editor

Every finding includes a copy-paste prompt for Cursor, Claude Code, or Lovable so you close gaps without becoming a security engineer overnight.

FAQ

Common questions

Is this a penetration test?
No. This is a fast first-pass surface scan. It catches the issues that break most AI-built launches, but it cannot prove your app is fully secure.
Do you need my source code?
No. We scan the deployed site exactly as the public internet sees it.
What stacks do you support?
Any public web app. We tune checks for Supabase, Firebase-style BaaS, Next.js, and Vite bundles common on Lovable, Bolt, and Cursor deploys.
Who built this?
Noetfield Studio ships production AI SaaS for clients. Scan is the same checklist we run before handoff.