An independent website security audit for sites built with Lovable, v0, Bolt, Cursor, Replit, ChatGPT or Claude — covering the security holes, broken dependencies, and missing fundamentals that only surface once real users arrive.
Building a site with an LLM genuinely works, and it has put shipping within reach of people who could never have shipped before. That is a real shift, and we are not here to talk you out of it.
The failure mode is specific: the model optimises for code that runs, and a site that runs is not the same as a site that is secure, fast, findable, or maintainable. Nothing in the process flags an exposed API key or a form that writes to your database without validation, because the page still loads perfectly.
This is why website security questions about AI builders keep surfacing — searches for Lovable app security, v0 security, and whether vibe coding is safe have climbed steadily as more generated apps reach production. The concern is well founded, and it is answerable: the code exists, it can be read, and the common failure patterns are known.
So the problems stay invisible until the wrong person finds them. We look at what your AI actually built, with the adversarial eye a model applied to its own output cannot provide.
No tiered feature lists. The scope below is the standard engagement — anything beyond it gets quoted separately and agreed before we start.
Exposed secrets, unvalidated inputs, injection vectors, missing authentication checks, permissive CORS, and dependency vulnerabilities — the categories AI-generated code fails most reliably.
Packages that are outdated, abandoned, vulnerable, or simply hallucinated into existence by the model and never really needed.
Unoptimised images, render-blocking scripts, oversized bundles, and the layout shift that generated markup tends to produce by default.
WCAG-level issues across keyboard navigation, colour contrast, focus states, form labelling, and semantic structure — routinely skipped in generated markup.
Titles, meta descriptions, heading hierarchy, canonicals, structured data, sitemap and robots configuration. Usually either absent or duplicated across every page.
An honest assessment of whether a developer can pick this up and extend it, or whether you are heading for a rebuild in six months.
Each AI builder fails in its own characteristic way. Knowing which tool produced the code tells us where to look first.
Lovable app security questions almost always come down to Supabase: row-level security left disabled, the anon key treated as a secret, and client-side checks standing in for server-side authorisation. We verify the database rules directly rather than trusting the app's behaviour.
Generated Next.js and React apps commonly leak server-only environment variables into client bundles, ship unprotected API routes, and skip input validation on server actions. We trace every route that touches data.
Assistant-written code across a long session drifts — auth patterns applied inconsistently, validation on some endpoints and not others, and dependencies added and forgotten. We check for the gaps between sessions.
Deployment configuration is the usual weak point: secrets in plain environment files, permissive CORS, debug modes left enabled in production, and databases exposed beyond the app.
Hand-assembled snippets from a chat session rarely share a coherent security model. Each piece works; the seams between them are where injection, auth bypass, and unvalidated input live.
AI-generated themes and plugins routinely miss nonce verification, capability checks, and output escaping — the exact issues that fail a WordPress.org security review and get sites compromised at scale.
You know what happens at each point, what we need from you, and when.
You give us repository access or a deployed URL, and tell us which tools built it. Knowing whether the output came from Lovable or from Cursor genuinely changes where we look first.
Static analysis, dependency scanning, Lighthouse, and accessibility tooling run across the whole codebase to establish the baseline quickly.
A human reads the code paths that handle data, authentication, and user input — precisely the areas automated tools miss and generated code gets wrong.
Findings ranked as fix now, fix soon, or acceptable, with a call to walk through anything urgent. Critical security findings are reported the moment we find them, not held for the report.
Typical marketing sites and small apps. Complex applications quoted individually.
Every engagement is scoped and priced individually against your site — the figure above is where projects like yours typically start, not a placeholder for an upsell. You get a fixed quote in writing before any work begins.
Request Your QuoteNo obligation · First response within 48 hours · Timeline scoped to your project
Send us a few details and we'll come back within 48 hours to scope it properly.
No obligation · No sales sequence · A real person replies