Blog
Security research, vulnerability deep-dives, and practical guides for developers building with AI tools.
Is Cursor-Generated Code Secure? We Scanned 100 Repos to Find Out
We ran ShipSafe on 100 real Cursor-built apps. 67% had at least one critical vulnerability. Here's what we found and how to fix it.
5 Security Vulnerabilities Every Lovable App Has (And How to Fix Them)
Lovable builds beautiful Supabase apps fast. But it consistently misses Row Level Security, leaks service role keys, and more. Here's the fix for each.
Bolt.new Security Guide: How to Ship Without Getting Hacked
Bolt.new generates full-stack apps in minutes. But without auth middleware and input validation, you're one exploit away from a breach. Here's the complete security guide.
AI-Generated Code Security: The Risks Nobody Talks About
Stanford research shows 45% of AI-generated code ships with vulnerabilities. Here's why, what types of bugs AI creates, and what you can do about it.
The Vibe Coding Security Checklist (2026): Ship Fast, Stay Safe
A complete security checklist for developers shipping AI-built apps. 20 checks across secrets, auth, injection, XSS, and configuration. Print it, pin it, use it.