# ShipSafe — sitemap

Every public page on ship-safe.co. Each entry links to the markdown mirror;
drop the `.md` for the HTML version. Machine-readable index: [https://ship-safe.co/sitemap.xml](https://ship-safe.co/sitemap.xml)

## Start here

- [ShipSafe — independent security verification for AI-built apps](https://ship-safe.co/index.md)
- [Pricing](https://ship-safe.co/pricing.md)
- [Detection benchmark — 1,147 labelled cases, every miss counted](https://ship-safe.co/benchmark.md)
- [Methodology — how the scan works](https://ship-safe.co/methodology.md)
- [Glossary — the terms used across this site](https://ship-safe.co/glossary.md)
- [Verify a ShipSafe badge](https://ship-safe.co/verify.md)
- [Contact](https://ship-safe.co/contact.md)

## Documentation

- [Documentation](https://ship-safe.co/docs.md)
- [Getting started](https://ship-safe.co/docs/getting-started.md)
- [CLI](https://ship-safe.co/docs/cli.md)
- [Configuration](https://ship-safe.co/docs/configuration.md)
- [Rules](https://ship-safe.co/docs/rules.md)
- [GitHub Actions](https://ship-safe.co/docs/github-actions.md)
- [GitHub App](https://ship-safe.co/docs/github-app.md)
- [MCP server](https://ship-safe.co/docs/mcp.md)
- [Live URL scanning](https://ship-safe.co/docs/live-url-scanning.md)
- [DAST scanning](https://ship-safe.co/docs/dast-scanning.md)
- [Git history scanning](https://ship-safe.co/docs/git-history-scanning.md)
- [Vulnerabilities by platform](https://ship-safe.co/docs/vulnerabilities-by-platform.md)

## Blog

- [Blog](https://ship-safe.co/blog.md)
- [Cursor Security Risks: CVEs, Prompt Injection, and Code Vulnerabilities (2026)](https://ship-safe.co/blog/cursor-security-risks.md)
- [Is Cursor Safe? We Scanned 100 Apps — 67% Had Critical Vulnerabilities](https://ship-safe.co/blog/is-cursor-code-secure.md)
- [5 Security Vulnerabilities Every Lovable App Has (And How to Fix Them)](https://ship-safe.co/blog/lovable-security-vulnerabilities.md)
- [Bolt.new Security Guide: How to Ship Without Getting Hacked](https://ship-safe.co/blog/bolt-new-security-guide.md)
- [AI-Generated Code Security: The Risks Nobody Talks About](https://ship-safe.co/blog/ai-generated-code-security-risks.md)
- [The Vibe Coding Security Checklist (2026): Ship Fast, Stay Safe](https://ship-safe.co/blog/vibe-coding-security-checklist.md)
- [v0 by Vercel: 4 Security Gaps in Every Generated App (And the Fixes)](https://ship-safe.co/blog/v0-vercel-security-risks.md)
- [Replit Agent Security Guide: What It Misses and How to Fix It](https://ship-safe.co/blog/replit-agent-security-guide.md)
- [Your Supabase App Has No Row Level Security: A Vibe Coder's Fix Guide](https://ship-safe.co/blog/supabase-rls-vibe-coding.md)
- [Windsurf's Zero-Click RCE: How an HTML Page Owns Your IDE (CVE-2026-30615)](https://ship-safe.co/blog/windsurf-zero-click-mcp-rce-cve-2026-30615.md)
- [Clinejection: How One PR Compromised an AI Coding Agent Used by Millions](https://ship-safe.co/blog/clinejection-supply-chain-attack.md)
- [Comment and Control: One PR Title Drained Their Anthropic Bill](https://ship-safe.co/blog/comment-and-control-pr-injection.md)
- [MCP Tool Poisoning and Rug Pulls: The New Trust Problem in AI Tools](https://ship-safe.co/blog/mcp-tool-poisoning-rug-pull.md)
- [The Invisible Backdoor: Hidden Unicode in .cursorrules and CLAUDE.md](https://ship-safe.co/blog/invisible-unicode-rules-file-attack.md)
- [Cursor's Git Hook Trap: One Clone, Full RCE (CVE-2026-26268)](https://ship-safe.co/blog/cursor-git-hook-rce-cve-2026-26268.md)
- [The Lovable April 2026 Breach: What Got Leaked and What to Check](https://ship-safe.co/blog/lovable-april-2026-breach.md)
- [Three LangChain CVEs in 30 Days: SSRF, Path Traversal, and SQL Injection](https://ship-safe.co/blog/langchain-cves-2026-ssrf-path-traversal.md)
- [Pwn Request Meets AI Agents: How GitHub Workflows Leak Your Secrets](https://ship-safe.co/blog/pwn-request-ai-agents.md)
- [Your $4,200 Weekend: When Prompt Injection Drains Your Anthropic Bill](https://ship-safe.co/blog/ai-cost-exhaustion-attack.md)

## By platform

- [By platform](https://ship-safe.co/for.md)
- [Security for apps built with Cursor](https://ship-safe.co/for/cursor.md)
- [Security for apps built with Lovable](https://ship-safe.co/for/lovable.md)
- [Security for apps built with Bolt](https://ship-safe.co/for/bolt.md)
- [Security for apps built with v0](https://ship-safe.co/for/v0.md)
- [Security for apps built with Replit](https://ship-safe.co/for/replit.md)

## Comparisons

- [Comparisons](https://ship-safe.co/vs.md)
- [ShipSafe vs Semgrep](https://ship-safe.co/vs/semgrep.md)
- [ShipSafe vs Snyk](https://ship-safe.co/vs/snyk.md)
- [ShipSafe vs SonarQube](https://ship-safe.co/vs/sonarqube.md)
- [ShipSafe vs GitHub CodeQL](https://ship-safe.co/vs/github-codeql.md)
- [ShipSafe vs Aikido Security](https://ship-safe.co/vs/aikido.md)
- [ShipSafe vs Corgea](https://ship-safe.co/vs/corgea.md)
- [ShipSafe vs GitGuardian](https://ship-safe.co/vs/gitguardian.md)
- [ShipSafe vs Asking ChatGPT or Claude](https://ship-safe.co/vs/chatgpt-claude-code-review.md)
- [ShipSafe vs URL & Website Scanners](https://ship-safe.co/vs/url-scanners.md)

## Legal

- [Terms of Service](https://ship-safe.co/terms.md)
- [Privacy Policy](https://ship-safe.co/privacy.md)
