---
title: "Bolt.new security: independent verification | ShipSafe scanner | ShipSafe"
description: "ShipSafe independently verifies your Bolt.new app: unauthenticated API routes, exposed secrets, and data left readable with no login, proven from the outside. The security scanner built for Bolt.new."
doc_version: 2026-10-05
last_updated: 2026-10-05T04:17:38.554Z
canonical: https://ship-safe.co/for/bolt
---

# Bolt.new security: independent verification | ShipSafe scanner | ShipSafe

VITE\_ prefixes ship your secrets to the browser

# Security Scanner forBolt.new Apps

Bolt.new ships full-stack apps in seconds. But unauthenticated API routes and exposed secrets mean your app could be compromised in seconds too. ShipSafe finds what Bolt's AI missed.

[See What Bolt.new Missed](https://ship-safe.co/)[View Pricing](https://ship-safe.co/pricing)

Free scan2 minutesNo card needed

shipsafe / bolt.new scanwhat we screen for

What we screen for in Bolt.new repos

4recurring findings we screen for

Critical02

High02

Every finding ships with a plain-English fix.

![](https://ship-safe.co/_next/image?url=%2Fmascot%2Fbosun-spyglass.jpg&w=256&q=75&dpl=dpl_5pByymSL71c6TgZqxKfxU69421ME)

The short answer

## The Security Cost of Instant Full-Stack Apps

Bolt.new is impressive. You describe what you want, and it generates a complete application with frontend, backend, and database in one shot. The problem is that the AI skips the boring but critical security plumbing that separates a demo from a production app.

Every API route Bolt creates is a potential entry point for attackers. Without auth checks, anyone can call them. Without input validation, malicious payloads flow straight through. And because Bolt uses Vite, any secret prefixed with VITE\_ ends up in your users' browsers.

We've documented the specific patterns in our [Bolt.new security guide](https://ship-safe.co/blog/bolt-new-security-guide) and the [vulnerabilities by platform](https://ship-safe.co/docs/vulnerabilities-by-platform) reference.

Common vulnerabilities

## Common Vulnerabilities in Bolt.new Projects

These are the four patterns we screen Bolt.new projects for, and what each one exposes.

1. 01  
### Unauthenticated API Routes  
Critical  
Bolt.new generates API endpoints that handle data mutations (create, update, delete) without verifying that the caller is logged in. Anyone who discovers the route can call it directly with curl or Postman, bypassing your entire frontend.
2. 02  
### Secrets in VITE\_ Environment Variables  
Critical  
Bolt.new uses Vite as its build tool, and any env var prefixed with VITE\_ gets bundled into the frontend JavaScript. The AI can put API keys, database URLs, and webhook secrets behind VITE\_ prefixes, making them visible to anyone who opens browser DevTools.
3. 03  
### Missing Input Validation  
High  
Bolt-generated endpoints can trust all incoming data. There is no schema validation, no type checking, and no sanitization. Malformed payloads, oversized inputs, and injection attempts pass straight through to your database.
4. 04  
### No CSRF Protection  
High  
Bolt.new does not generate CSRF tokens or SameSite cookie configurations. State-changing requests can be triggered from any website by embedding a hidden form, letting attackers perform actions on behalf of logged-in users.

## How ShipSafe Verifies Your Bolt.new App

1

### Connect Your Bolt.new Project

Bolt can push your project to GitHub in a couple of clicks — connect that repo. ShipSafe recognizes Bolt.new's Vite-based project structure and understands how it handles routing and env vars.

2

### Full-Stack Security Analysis

ShipSafe scans both frontend and backend code. It maps every API route, checks for auth middleware, validates env var scoping, and tests for CSRF and input validation gaps.

3

### Prioritized Fix Guide

Receive a severity-ranked report with concrete code examples showing exactly what to change. Copy-paste the fixes directly into your Bolt.new project.

## Frequently Asked Questions

Is Bolt.new code secure?

Not by default. Bolt.new focuses on generating functional full-stack apps quickly, and security tends not to be the priority. Patterns to check for: API routes without an authentication check, secrets exposed in the client bundle through VITE\_ env vars, and missing input validation.

What security issues does Bolt.new create?

The four most frequent vulnerabilities are: (1) API routes that accept requests without verifying authentication, (2) sensitive secrets placed in VITE\_ prefixed environment variables that get bundled into frontend code, (3) missing input validation on form submissions and API payloads, and (4) no CSRF protection on state-changing endpoints.

How do I secure my Bolt.new app?

Start by running a ShipSafe scan to identify all vulnerabilities. Then address them in priority order: add authentication middleware to every API route, move secrets to server-only env vars (remove the VITE\_ prefix), add input validation using a library like Zod, and implement CSRF protection.

Does ShipSafe work with Bolt.new projects?

Yes. ShipSafe is specifically tuned to understand Bolt.new's project structure, including its Vite configuration, API route patterns, and environment variable handling. Bolt can push your project to GitHub in a couple of clicks — connect that repo and you're scanning.

## Find Out What Your Bolt.new App Leaves Open

Paste a GitHub URL. The report names what we found, and what this scan could not reach.

[Scan My Bolt.new App Free](https://ship-safe.co/scan)

No credit card required. [See all plans](https://ship-safe.co/pricing)

This is an independent comparison provided for informational purposes. All product names, logos, and brands are the property of their respective owners; ShipSafe is not affiliated with, endorsed by, or sponsored by them. Statements about other products reflect publicly available information at the time of writing and may change, so please verify current details on each provider’s own website.

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
