MLVibeScan

Security guidance for vibe apps

Public source maps hand out your application map

Source maps help development but should not be served publicly. They can reconstruct readable original source from minified bundles.

Reviewed by René Matis · MATIS LABS · Updated 15 August 2026

The scan is free and takes about twenty seconds. You see straight away how many findings there are and how serious they are.

Scan your own app for free

How to recognise the problem

Attackers can identify internal routes, comments, components and protection logic faster; embedded sources may contain complete files.

A working happy path does not prove this boundary. Always test with a second user, while signed out or with an intentionally forbidden input.

How to fix it reliably

Disable public production source maps or upload them privately to your error service, and block `.map` delivery.

The control belongs at the server-side trust boundary. A hidden button, different client copy or browser-only validation is not a security control.

Re-test instead of hoping

MLVibeScan checks sourceMappingURL references and reachable .map files. A re-test compares the stable protection target with the previous result and reports fixed, partially fixed, unchanged or regression.

Automated checks cover recurring patterns. High-risk business logic may additionally require an individually scoped penetration test.

What we check automatically

  • sourceMappingURL references and reachable .map files
  • Confidence and counter-checking
  • Stable fingerprints for re-tests

Frequently asked questions

Can this be tested from the outside?
Partly. MLVibeScan checks sourceMappingURL references and reachable .map files; source and deep checks require purchase, domain verification and explicit consent.
Is blocking access in the UI enough?
No. Security decisions must be enforced server-side for every request, regardless of the client an attacker uses.
When is the finding fixed?
Only when the control holds in a controlled re-test and no contradictory source/runtime observation remains.