Observed arrival · 2026-09-20
Clod: Security Checks for Vibe-Coded Apps
Clod offers a one-time security scan for deployed Next.js and Supabase apps, with prioritized findings and practical fixes.
- For
- Independent builders shipping Next.js and Supabase apps
- Worth noticing
- The scan requires DNS or HTML ownership verification before deeper checks and does not require a repository connection.
Field notes
Clod starts with a deployed application URL rather than a repository connection, then asks the owner to verify control through DNS or an HTML meta tag. Its sample report separates findings such as client-side privileged keys and missing content security policy headers, pairing each with evidence and a remediation step. The homepage names Next.js and Supabase as core targets and cautions that a clean result would cover only the checks performed, not every possible vulnerability.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue