Skip to content
All comparisons & guides
Best of 2026

What is the best security scanner for Bolt.new apps?

Quick answer

The best security scanner for Bolt.new apps tests the deployed site, not just the code. CheckVibe (from $0) leads for Bolt: 100+ checks including the Bolt-signature failure modes, plus SEO/AEO scanning no competitor offers. VibeEval, Vibe App Scanner, and Scanbee are strong security-only options.

TL;DR

  • Bolt's `VITE_` env-var convention makes key exposure the signature Bolt vulnerability — visible only in the served bundle, which is what URL-based scanners read.
  • CheckVibe: free tier (4 scans/mo), $24–59/mo paid; the only option that also scans SEO + AEO visibility.
  • VibeEval ($19/mo, $199 lifetime) goes deepest on autonomous agent-based security testing.
  • Vibe App Scanner ($9–19 one-time) is the cheapest single pre-launch audit.
  • All picks verified against vendor sites on June 12, 2026 — sources at the bottom.

Bolt.new optimizes for "running" over "hardened": scaffolds routinely inline API keys into the client bundle (anything `VITE_`-prefixed ships to the browser), skip Supabase RLS, leave CORS wide open, and ship zero security headers. Because the damage lives in the deployed bundle and backend config, URL-based scanning catches what code review misses.

How we picked

  • Tests the deployed app from the outside (what attackers and crawlers actually see), with Bolt.new listed as a supported platform or stack-relevant coverage.
  • Catches the platform's signature failure modes, not just generic OWASP items.
  • Honest pricing with a usable free option where available.
  • Output a vibe coder can act on — fix guidance, ideally AI-editor-ready.

The picks

1.CheckVibe

Free (4 scans/mo) · $24–59/mo

Paste your deployed Bolt.new URL and get 100+ security checks plus 68 SEO and 46 AEO checks in about 30 seconds — no repo access, no setup. For Bolt specifically: it scans every served static asset for 100+ API key patterns (the classic Bolt failure mode) and verifies Supabase RLS and CORS configuration on the live app. Findings ship as copy-paste AI fix prompts, and monitoring (uptime, vitals, threats) covers you after launch.

Best for: All-in-one security + visibility, from $0

2.VibeEval

Free surface scan · $19/mo · $199 lifetime

Autonomous browser-agent security testing of the live app — including behind auth walls and CAPTCHAs (their claim). Security-only. Lists Bolt.new as a supported platform.

Best for: Deep agent-based security testing

3.Vibe App Scanner

$9–19 one-time · $99/mo continuous

One-time security audits of the deployed app: exposed secrets, database access rules (Supabase/Firebase), headers, auth. No free scan tier listed as of June 2026. Lists Bolt.new as a supported platform.

Best for: A cheap one-off pre-launch security audit

4.Scanbee

Free (3 targets, 20 scans/mo) · paid tiers listed "Coming Soon"

Five security scanner types — DAST, SAST, SCA, CSPM (AWS), vulnerability assessment — accepting both URLs and GitHub repos, with a native Supabase integration. Lists Bolt as a supported platform.

Best for: Source + live + cloud security in one product

5.VibeWrench

Free (3 scans/mo) · $9–19/mo

Eighteen tools in one cheap subscription — a 9-area security scan, basic SEO scan, Lighthouse speed, and utility generators. Lighter per category. Covers Bolt.new on its homepage; its 9-area security scan includes hardcoded secrets.

Best for: Budget multi-tool quick checks

Start with the free scan.

100+ security checks, 68 SEO checks, 46 AEO checks. One URL, about 30 seconds.

Run a free CheckVibe scan

FAQ

Do I really need a security scanner for a Bolt.new app?

If the app has users, data, or payments — yes. AI-generated apps ship with a consistent set of gaps (exposed keys, missing access control, no headers), and every tool on this list catches issues a manual click-through never will. Start with a free scan; the result settles the question.

Are free security scans enough?

A free scan is enough to find out where you stand today. Paid tiers buy continuity (scheduled scans, monitoring, alerts) and depth (more pages crawled, more checks). For a side project, free-tier scans before each launch may genuinely suffice.

Why do Bolt.new apps leak API keys so often?

Bolt scaffolds Vite apps, and Vite ships every environment variable prefixed `VITE_` into the public JavaScript bundle. AI scaffolds frequently put real keys there "to make it work". A URL-based scan reads the same bundle an attacker would and flags every recognizable key shape.

Is one scan before launch enough for a Bolt app?

A pre-launch scan catches the launch-day disasters. But Bolt apps tend to change daily while you iterate, and each regeneration can reintroduce an old mistake — continuous or per-deploy scanning (CheckVibe scheduled scans, Vibe App Scanner's $99/mo plan) covers the drift.

Keep reading

Sources

Pricing and feature claims verified against these pages on June 12, 2026.