QLTech
The vibe-coding security checklist
Twelve things to verify before an app built with Lovable, Cursor, Claude Code, Bolt.new, v0, Replit, Windsurf or Copilot goes live. Tick each one only once you have seen it with your own eyes, not because the tool said it was done.
- 01Row-level security is enabled, and the policies existEvery table holding user data has RLS on and a policy per operation that restricts rows to their owner. Tested with two accounts.
- 02No secrets in the client bundleNo hardcoded keys, nothing privileged behind a NEXT_PUBLIC_ style prefix, and the deployed JavaScript searched for the first characters of every key.
- 03Authorisation is checked on the server, not just in the browserEvery API the interface hides was called directly with curl while logged out or as another user, and returned nothing it should not.
- 04Admin routes and leftover debug endpoints are locked downSeed, reset, test and admin routes are deleted or behind server-side role checks, and access to them is logged.
- 05Webhooks verify their signaturesPayment and messaging handlers verify the signature on the raw body, reject failures, and are idempotent on replay.
- 06No queries are built by string concatenationNo SQL or query strings assembled with user input. Parameterised queries or the ORM's builder everywhere, including for IDs.
- 07Uploads are validated and buckets are not public by accidentType and size checked on the server, file names generated by you, private files served through signed URLs, bucket policies reviewed.
- 08Public endpoints are rate limitedLogin, sign-up, reset, forms, search and anything that calls a paid API have per-IP and per-account limits, bot protection, and spending caps.
- 09Dependencies are pinned, current and maintainedLockfile committed, versions pinned, the audit command clean, abandoned or single-maintainer critical packages replaced, updates automated.
- 10Logs do not contain personal data or secretsA full user journey's logs read end to end: no request bodies, tokens, passwords, ID numbers, card details or email addresses.
- 11Backups exist and you have restored from oneAutomated backups with point-in-time recovery where available, and one restore drill to a fresh instance completed before launch.
- 12CORS, cookies and sessions are configured deliberatelyOnly your own origins allowed, cookies secure, HTTP-only and same-site set explicitly, logout and expiry tested from a second browser.