Eight questions on the habits that make vibe-coded apps leaky. Instant score - shareable, no account required.
How it works
Shipping AI-generated code without a security mindset is the most common vibe-coding failure mode. Models optimize for demos that look finished; they rarely insist on RLS, secret rotation, or least-privilege CORS unless you ask. This short quiz scores your instincts across auth verification, secrets handling, database access control, robots.txt myths, CORS with credentials, upload allowlists, dependency CVEs, and pre-launch checks. Each answer adds zero to three risk points - higher totals mean riskier defaults. Answer every question, then read the label honestly. There is no email wall before you see results; optionally leave an email afterward if you want a short tip and a link to scan your live URL. The quiz is educational and shareable, not a certification, insurance policy, or proof for investors. Two founders with the same score can still ship very different apps. When your product has a public URL, run an AtRisk scan to validate the live surface (headers, TLS, cookies, and more), then unlock full findings and fix prompts on Starter so your next AI session fixes real issues instead of guessing.
Self-assessment only. Correct quiz answers do not mean your app is secure. Validate with a live scan.