Free security check · no signup

Is your Cursor project secure?

Cursor writes a lot of code fast, and it will happily hardcode an API key or leave a database wide open if you let it. Run a quick security check before you ship the app you built in Cursor.

Scan my Cursor app free →

Runs in your browser · your code never uploads · results in seconds

What it checks for

Hardcoded API keys, tokens, and passwords in the code

Databases left wide open (Firebase / Supabase rules)

A .env file that isn’t protected from upload

Secrets shipped to the browser, SQL injection, and open CORS