I will test your vibe coded app for security vulnerabilities


About this gig
Is your vibe-coded app actually secure?
Vibe coding ships fast. It also ships with broken access controls, exposed APIs, hardcoded secrets, and logic flaws that no linter will catch. I find them before someone else does.
I am an OSCP certified penetration tester with hands-on experience across 80+ real-world security engagements. I specialise in testing web applications built with tools like Claude, Cursor, Bolt, Lovable, and v0, where the attack surface is wide and the security hygiene is often zero.
What you get?
A manual and automated test tailored to your stack. Real vulnerabilities, not just scanner output.
A clear report with proof of concept and fix guidance. Straight talk, no fluff, no filler.
Whether you built a SaaS MVP, an internal tool, or a client project, I will tell you exactly what is broken and how to fix it.
Drop me a message before ordering if you have a large or complex app.
Get to know Yaqoob M
Penetration Tester
- FromUnited Kingdom
- Member sinceMay 2026
- Avg. response time1 hour
Languages
English
FAQ
What is vibe coding and why is it risky?
Vibe coding means building apps by prompting AI tools like Cursor, Bolt, or Lovable instead of writing code manually. The apps work, but the code often has no input validation, weak authentication, and exposed endpoints because the AI prioritises making things functional over making them secure.
What do I need to share with you to get started?
Just the live URL of your app. For deeper testing I may ask for a test account with full access. You never need to share source code unless you want me to review it.
Will you break my app or take it offline?
No. All testing is done carefully and non-destructively. I do not run denial of service attacks or anything that would disrupt your users. If something risky needs testing, I will ask you first.
What does the report look like?
You get a PDF report with every finding listed by severity, a plain English explanation of the risk, a proof of concept showing how it could be exploited, and a clear fix recommendation.
I already used a free scanner online. Do I still need this?
Yes. Automated scanners miss the vulnerabilities that matter most, things like broken access control, insecure direct object references, and flawed business logic. Those require a human to find. That is exactly what I test for.

