Skip to main content
UNPWNED
ai builder

IS BOLT.NEW SAFE?

Bolt.new lets you build and deploy web apps entirely in the browser using AI code generation. The speed of development often comes at the cost of security fundamentals - generated code regularly includes hardcoded API keys, unauthenticated routes, and missing input validation. Since apps deploy instantly, these vulnerabilities go live before any security review happens.

72%
No CSP header
74%
No rate limiting
47%
No DMARC
447+
Sites analyzed
Scan your Bolt.new app free

TOP SECURITY RISKS

critical

API Keys Hardcoded in Generated Code

Bolt.new frequently generates code with API keys, database credentials, and third-party service tokens embedded directly in source files. These secrets end up in client-side bundles and version control, where anyone can extract and abuse them.

critical

Missing Authentication on API Routes

Generated API endpoints often lack any authentication or authorization checks. This means any user or bot can call sensitive endpoints directly, bypassing the intended UI flow to access or modify data without logging in.

high

No Input Validation on Forms and APIs

Bolt.new generates forms and API handlers that accept user input without sanitization or validation. This opens the door to SQL injection, cross-site scripting, and data corruption through malformed inputs.

high

Exposed Firebase or Supabase Credentials

Backend-as-a-service credentials are often placed in client-accessible configuration files without proper security rules. Without Firestore rules or RLS policies, these exposed credentials grant direct database access to attackers.

medium

No CORS Restrictions

Generated applications typically ship without CORS configuration, allowing any website to make requests to your API. This enables cross-origin data theft and unauthorized actions on behalf of authenticated users.

SECURITY CHECKLIST

Move all API keys and secrets to server-side environment variables
Add authentication middleware to every API route that handles user data
Validate and sanitize all form inputs on both client and server side
Configure CORS to allow only your own domain origins
Add Content Security Policy and other security headers
Enable HTTPS redirect and ensure no mixed content
Check for exposed .env files and configuration files in the deployed build
Review Firebase Security Rules or Supabase RLS policies for every collection and table
Remove any debug or development endpoints before going to production
Audit third-party dependencies for known vulnerabilities
The currently enabled UNPWNED Deep Scan covers up to 702 configured checks after current ownership proof.

SCAN YOUR BOLT.NEW APP

Start with a bounded public check. The currently enabled Deep Scan has up to 702 configured checks after current ownership proof. Free entry point, no credit card required.

Run free security scan

FREQUENTLY ASKED QUESTIONS

Is Bolt.new safe for building production applications?

Bolt.new is excellent for prototyping and MVPs, but the generated code needs a security review before production use. Common issues include hardcoded secrets, missing auth, and no input validation. Run an UNPWNED scan to assess externally observable client-secret, header, endpoint, dependency, CORS, form, rate-limit, and error-disclosure signals. Paid reports prioritize remediation for completed findings; authentication and validation require direct review.

What security issues does Bolt.new code typically have?

The most common issues are hardcoded API keys in client code, API routes with no authentication, and forms with no input validation. Firebase and Supabase credentials are often exposed without proper security rules. UNPWNED identifies externally observable exposure, endpoint, database-rule, configuration, and form signals. Paid reports provide fix guidance for each completed finding.

Does Bolt.new configure security headers?

No, Bolt.new does not add security headers like CSP, X-Frame-Options, or Strict-Transport-Security to generated projects. You need to configure these manually in your hosting platform or middleware. UNPWNED assesses its configured security-header set and reports observed gaps. Paid reports add configuration guidance.

How can I secure my Bolt.new app before launch?

First, extract all hardcoded secrets to server-side environment variables. Then add authentication to every API route, input validation to every form, and CORS restrictions to your API. UNPWNED provides a bounded outside-in assessment of client-secret, header, endpoint, dependency, CORS, form, rate-limit, and error-disclosure signals. Paid reports add prioritized remediation guidance; internal authentication and validation require direct review.

Can UNPWNED detect Bolt.new-specific vulnerabilities?

Yes. UNPWNED checks externally observable client-secret, public-endpoint, security-header, CORS, form, dependency, rate-limit, and error-disclosure signals. Its currently enabled outside-in Deep Scan runs up to 702 configured checks after current ownership proof. Free reports show completed finding titles and severities; paid reports add full detail and stack-specific remediation guidance. Authentication, authorization, and server-side validation still require direct review.

Data based on 447+ website scans. Statistics reflect aggregate findings across all scanned websites, not Bolt.new exclusively.