I’ve vibe coded 18+ MVPs for clients using Cursor. Security was the...

Security was the one lesson I learned the hard way.
Here’s the checklist I wish I had from day one ↓
If you skip this, bots or bad actors can hit your backend 100s of times per second.
This can:
• Crash your database
• Drain your Supabase usage
• Spike costs or open you to attacks
Tools to use:
• Supabase Edge Functions with a rate limiter
• Vercel Middleware
• Basic IP throttling with Next.js middleware
If you’re using Supabase, turn on RLS on every table from day one.
Without it, users can query other people’s data.
And yes, this happens way more than you’d think.
To set it up:
• Go to Table → RLS → Enable
• Use policies like user_id = auth.uid()
No RLS = no data security.
Pro Tip: Try asking Cursor for these policies based on your DB design and PRD. It will help you write them correctly.
AI bots can generate thousands of fake signups in minutes.
Add CAPTCHA to:
• Signup forms
• Login pages
• Forgot password flows
Use hCaptcha or reCAPTCHA. Both are quick to implement.
If you’re deploying with Vercel, you’re just 1 click away from basic protection.
Go to:
• Vercel → Settings → Security → Web Application Firewall
• Enable “Attack Challenge” on all routes
It blocks bad traffic before it hits your app. No code required.
Never expose secrets in frontend code.
Instead:
• Store keys in .env files
• Use server-only functions for anything sensitive
• Scan AI-generated code (it often forgets this)
If it runs on the client, assume it’s public.
Don’t trust the frontend even if Cursor or Lovable does the UI validation.
Always validate:
• Emails
• Passwords
• Uploaded files
• Custom form inputs
• API payloads
A single missed check = potential vulnerability.
Cursor moves fast. But it doesn’t clean up after itself.
Before launch:
• Run npm audit fix or yarn audit
• Remove unused packages
• Check for critical vulnerabilities
• Use minimal dependencies to reduce your attack surface
You can’t fix what you can’t see.
Use:
• Supabase Logs
• Vercel Analytics
• Simple server-side logs with timestamps and IP
Track:
• Failed logins
• High traffic spikes
• 500s and unhandled errors
Even a basic log table in Supabase helps.
Cursor lets you code fast.
But you’re still responsible for keeping your MVP safe.
Before you launch:
• Rate limit
• RLS
• CAPTCHA
• WAF
• Secret management
• Input validation
• Dependency cleanup
• Monitoring
Don’t skip this.
i started a private community for builders like us.
220+ members already.
we share AI workflows, launch real MVPs, and help each other grow.
if you’re building, you should be in here ↓
skool.com/ai-mvp-builders