Blog
Security guides for vibe-coded and AI-generated apps.
September 6, 2026
Vulnerability scanner tools: an honest overview
Nessus, OpenVAS, OWASP ZAP, Burp, Snyk and VibeCoden't, what each kind of scanner actually checks, and which one fits your app.
August 29, 2026
Case study: scanning a vibe-coded SaaS, from finding to fix
Eight findings on a typical AI-built subscription app, why each one mattered, the fixes applied, and what the re-scan showed.
August 21, 2026
Exposed API keys in frontend code: how to find and fix them
Which keys are safe to ship in the browser, which ones leak, how to spot them in your bundle, and what to do after a key is exposed.
August 12, 2026
7 row level security mistakes that leave your database public
RLS off, policies that pass for everyone, roles on the profile table, the database mistakes we find most often, and how to fix each.
August 5, 2026
HTTP security headers checklist (with copy-paste values)
The seven headers worth setting, safe starting values, and how to roll out a Content-Security-Policy without breaking your site.
July 27, 2026
What is vibe coding? Meaning, examples, and the security catch
What vibe coding really means, why it took off, and the security surface every vibe-coded app inherits.
July 12, 2026
What is a vulnerability scan? A plain-English guide
How vulnerability scans work, what they find, and why vibe-coded apps need one.
July 20, 2026
How to perform a website security check on your vibe-coded app
Step-by-step manual and automated checks any developer can run, no security background required.