Pre-launch security checks, leaked secrets, auth mistakes and cloud misconfigurations, explained for solo developers shipping real apps.
Most apps that leak data were not attacked by anyone clever. They shipped with an API key in the bundle, a database with no access rules, or an auth check that reads a token without verifying it. These guides cover the failures that actually reach production in small projects, with the exact query, command or config to check each one before you point a domain at it.
Start with one of the pre-launch checklists if you are close to shipping, then work through the specific topics that match your stack. If you want a machine to do the first pass, IOnclad reads your source offline and returns a ranked list of findings. For how it sits next to the established tools, see IOnclad compared with Snyk, Semgrep and Trivy.
Two free checks for a live site: the security headers checker and the SPF, DKIM and DMARC checker.
Try the free IOnclad browser scannerA short, honest pre-launch security checklist for solo developers: the handful of issues that actually get indie apps breached, and how to catch them before you ship.
Read more →You built the API and it works on your machine. Here is the pre-launch security checklist for what a stranger finds in the first week: exposed keys, open databases, missing auth checks and the rest.
Read more →You are about to launch. Before you do, here is the fast, honest security pass that catches the issues that actually matter, in about a minute.
Read more →AI-generated code ships fast and looks plausible, which is exactly the problem. The specific insecure patterns that show up in vibe-coded apps, and how to catch them.
Read more →The OWASP Top 10 without the enterprise jargon: what each risk actually means for a one-person app, and the version of it you are most likely to ship.
Read more →Hardcoded API keys and tokens are the number one way small apps get breached. Where they hide, why entropy detection matters, and how to get them out before you ship.
Read more →Deleting a secret and committing the change does not remove it. It lives on in git history, fully recoverable. Why, and what to actually do about it.
Read more →Yes, the Supabase anon key is safe to expose in client code, but only when Row Level Security is on and correct. How to check yours before you launch.
Read more →Backends like Firebase and Supabase ship with permissive rules that are fine for a demo and a data breach in production. How to lock them down before launch.
Read more →JSON Web Tokens are simple to use and easy to use wrong. The auth mistakes that most often ship in indie apps, from decode-vs-verify to storing tokens in localStorage.
Read more →On serverless and pay-per-use infrastructure, a loop or a retry storm does not crash your app. It bankrupts you. What Denial of Wallet is and how to catch the patterns.
Read more →Infrastructure-as-code makes it easy to ship the same misconfiguration everywhere. The default-credential and open-port traps in Docker, Compose, and Terraform.
Read more →