Snippet · Shipping & running it
Security pass
The handful of holes that account for most break-ins.
Review this for security holes: <paste> Check specifically for: - User input reaching a database query or a shell command unescaped. - User input reaching the page unescaped. - Any route that changes data without checking who is asking. - Any route that returns someone else's data if I change an ID in the URL. - Secrets in the source, and errors that leak internals to the user. For each finding: the line, what an attacker does with it, the fix. Rank by how easy it would be to exploit with no special access.
Changing an ID in a URL and getting someone else's record is the most common real-world flaw in vibe-coded apps. Check that one first, every time.