Hey IndieHackers!
I built my app with Cursor as a non-technical founder.
Before launching I wanted to make sure it was secure.
When I scanned it properly I found 9 critical issues:
🔴 3 API endpoints with zero authentication
🔴 No rate limiting (anyone could drain my API)
🔴 OAuth redirect vulnerability
🔴 No database RLS policies
🔴 Missing security headers
The scary part? I BUILT this app and had no idea.
AI tools build what you ASK for. Not what you NEED.
So I built ShipProof — it scans your GitHub repo
and gives you copy-paste fix prompts for Cursor,
Lovable, Bolt and v0.
You can see our real scan results here:
shipproof.app/demo
Free to try — 1 scan, no credit card needed.
shipproof.app
Would love feedback from this community!
What features would make this useful for you?