Skip to content
Blog
Checklist

The vibe coder's security checklist

You shipped fast. Here's the whole low-level hygiene list in one place — every item is something a scanner flags and a shakedown email pads with, and every one links to the five-minute fix.

The buckingfugs crewJuly 11, 20266 min read

None of this is a red-team exercise. It's the boring layer — config, DNS, and headers — that makes up roughly 80% of what strangers try to shake you down over. Work down the list; it's ordered by impact, so if you only have half an hour, the top three are where it goes.

Two things that aren't line items

First, know your enemy: most “critical vulnerability” emails are theater, and it helps to see how the fake bug bounty shakedown works so a scanner screenshot reads as a to-do list, not a threat.

Second, this is a checklist you run more than once. Hygiene drifts — a deploy drops a header, a cert lapses, a subdomain goes orphaned — so “done” is really “done for now.” And if you want to know how you stack up while you work through it, the State of the Swamp numbers show what everyone else is (and isn't) fixing.

The shortcut, of course, is to not check all of this by hand. A scan walks the entire list in about twenty seconds and hands you the fixes — which is the fastest way to turn this page into a green report.

Run the whole checklist at once — findings and fixes, free.

Scan your site free →