Security guidance for vibe apps
Signing in within the browser does not protect your backend
A React route guard improves navigation but is bypassable. APIs and databases must authenticate and authorise every request independently of the visible UI state.
Reviewed by René Matis · MATIS LABS · Updated 15 August 2026
The scan is free and takes about twenty seconds. You see straight away how many findings there are and how serious they are.
Scan your own app for freeHow to recognise the problem
Risk patterns include roles in localStorage, unverified JWT claims, hidden admin buttons and endpoints without a server-side session check.
A working happy path does not prove this boundary. Always test with a second user, while signed out or with an intentionally forbidden input.
How to fix it reliably
Verify tokens cryptographically on the server, authorise the concrete object and use secure HttpOnly sessions or robust bearer tokens.
The control belongs at the server-side trust boundary. A hidden button, different client copy or browser-only validation is not a security control.
Re-test instead of hoping
MLVibeScan checks session, cookie, JWT and auth-guard configuration. A re-test compares the stable protection target with the previous result and reports fixed, partially fixed, unchanged or regression.
Automated checks cover recurring patterns. High-risk business logic may additionally require an individually scoped penetration test.
What we check automatically
- session, cookie, JWT and auth-guard configuration
- Confidence and counter-checking
- Stable fingerprints for re-tests
Frequently asked questions
- Can this be tested from the outside?
- Partly. MLVibeScan checks session, cookie, JWT and auth-guard configuration; source and deep checks require purchase, domain verification and explicit consent.
- Is blocking access in the UI enough?
- No. Security decisions must be enforced server-side for every request, regardless of the client an attacker uses.
- When is the finding fixed?
- Only when the control holds in a controlled re-test and no contradictory source/runtime observation remains.