I’ve vibe coded 18+ MVPs for clients using Cursor. Security was the...

@PrajwalTomar_
Prajwal Tomar@PrajwalTomar_
68 views Jun 02, 2025 ~3 min read
Advertisement
1
I’ve vibe coded 18+ MVPs for clients using Cursor.
Security was the one lesson I learned the hard way.

Here’s the checklist I wish I had from day one ↓
2
1. Rate limit your endpoints

If you skip this, bots or bad actors can hit your backend 100s of times per second.

This can:
• Crash your database
• Drain your Supabase usage
• Spike costs or open you to attacks

Tools to use:
• Supabase Edge Functions with a rate limiter
• Vercel Middleware
• Basic IP throttling with Next.js middleware
3
2. Enable Row-Level Security (RLS)

If you’re using Supabase, turn on RLS on every table from day one.

Without it, users can query other people’s data.
And yes, this happens way more than you’d think.

To set it up:
• Go to Table → RLS → Enable
• Use policies like user_id = auth.uid()

No RLS = no data security.

Pro Tip: Try asking Cursor for these policies based on your DB design and PRD. It will help you write them correctly.
4
3. Add CAPTCHA to your auth flows

AI bots can generate thousands of fake signups in minutes.

Add CAPTCHA to:
• Signup forms
• Login pages
• Forgot password flows

Use hCaptcha or reCAPTCHA. Both are quick to implement.
5
4. Enable WAF (Web Application Firewall)

If you’re deploying with Vercel, you’re just 1 click away from basic protection.

Go to:
• Vercel → Settings → Security → Web Application Firewall
• Enable “Attack Challenge” on all routes

It blocks bad traffic before it hits your app. No code required.
6
5. Secure your API keys and secrets

Never expose secrets in frontend code.

Instead:
• Store keys in .env files
• Use server-only functions for anything sensitive
• Scan AI-generated code (it often forgets this)

If it runs on the client, assume it’s public.
7
6. Validate all inputs on the backend

Don’t trust the frontend even if Cursor or Lovable does the UI validation.

Always validate:
• Emails
• Passwords
• Uploaded files
• Custom form inputs
• API payloads

A single missed check = potential vulnerability.
8
7. Clean up dependencies

Cursor moves fast. But it doesn’t clean up after itself.

Before launch:
• Run npm audit fix or yarn audit
• Remove unused packages
• Check for critical vulnerabilities
• Use minimal dependencies to reduce your attack surface
9
8. Add basic monitoring and logs

You can’t fix what you can’t see.

Use:
• Supabase Logs
• Vercel Analytics
• Simple server-side logs with timestamps and IP

Track:
• Failed logins
• High traffic spikes
• 500s and unhandled errors

Even a basic log table in Supabase helps.
10
TLDR

Cursor lets you code fast.
But you’re still responsible for keeping your MVP safe.

Before you launch:
• Rate limit
• RLS
• CAPTCHA
• WAF
• Secret management
• Input validation
• Dependency cleanup
• Monitoring

Don’t skip this.
11
btw…

i started a private community for builders like us.
220+ members already.

we share AI workflows, launch real MVPs, and help each other grow.

if you’re building, you should be in here ↓

skool.com/ai-mvp-builders
Actions
What You Can Do
  • Export as PDF or Markdown
  • Batch Export to Notion
  • Bookmark & Highlight
  • LinkedIn & Instagram Carousel Maker
Create Free Account

Includes 7-day Premium trial

Advertisement