Security blog
Learn before you get pwned
Practical security writing for people who build websites and apps—not people who read CVE feeds for fun.
Founder GuidesOWASPCMS & AppsWebsite Security
Founder Guides6 min
Why vibe coders need security scans before launch
You shipped with Cursor, Lovable, or Bolt—but attackers don't care how fast you built. Here's what to check before you share the link.
Mar 28, 2026, 12:00 AMRead
OWASP8 min
OWASP basics for website owners (no jargon version)
Injection, broken access control, misconfigurations—what OWASP Top 10 means when you run a WordPress site or a vibe-coded app.
Mar 22, 2026, 12:00 AMRead
CMS & Apps7 min
WordPress vs custom sites: what VibeScan checks differently
CMS fingerprinting, plugin exposure, and vibe-coded SPA blind spots—how scans adapt to how your site was actually built.
Mar 15, 2026, 12:00 AMRead
Website Security5 min
HTTPS and security headers in plain English
HSTS, CSP, X-Frame-Options—what these headers do for your visitors and why 'looks fine in Chrome' isn't enough.
Mar 8, 2026, 12:00 AMRead
Founder Guides4 min
Pre-launch security checklist for indie apps
Fifteen minutes before you post on Product Hunt: domain, TLS, headers, forms, and the scans worth running.
Mar 1, 2026, 12:00 AMRead