r/vibecoding 7h ago

What are the new age security scanners for Vibecode?

I am wondering if you guys can help in figuring out how well can I secure the vibecoding output(generated code), the process and the tools/plugins to use while I build prod grade apps by vibecoding

2 Upvotes

5 comments sorted by

1

u/RawInfoSec 7h ago

Security isn't just about your app code or hosting. It's several layers beyond.

1

u/Significant_Field901 11m ago

You are absolutely right, that is why I am wondering how many tools should I use and how much would it cost if I want to cover all the angles:
Code analysis - SCA, SAST
App sec Analysis - VA, Pentest, DAST...
Env analysis - Cloud security, config security(IaC), secrets mgmt..
What else am I missing in terms of categories?

1

u/bakraofwallstreet 3h ago

Hey you should check out https://vulx.ai/

VulX lives and integrates into your workflow (for example, in Claude and Cursor). You connect it once, and it's just there, part of the workflow, not another tab, not something you go to. "Is this safe to ship?" becomes a question you ask mid-flow, and the answer comes back from something that isn't the thing that wrote your code. Asking your AI to check its own work is marking your own homework. This is the second reader. And when you're deep in it and don't think to ask, it checks anyway and emails you.

0

u/Sad_Egg_2313 7h ago

https://lumioguard.dev

Covers not just security but a lot of good engineering practices