Pre-Launch Fixes for AI-Generated Code
Every AI coding assistant has blind spots. Browse practical, copy-paste fixes and 1-click Cursor prompts for all 108 launch readiness checks.
No Live Stripe Secret Keys in Source Code
AI agents frequently paste sample sk_live_ keys directly into lib/stripe.ts or API route handlers instead of reading from process.env.
No OpenAI, Anthropic, or AI Provider API Keys Committed
When testing LLM calls, AI assistants often write raw sk-ant-... or sk-proj-... strings directly into client components or scripts.
Database Connection URIs Hidden from Client Bundles
Agents often configure Prisma or Postgres pools inside shared utility files imported by both client and server code.
No AWS / Cloud Storage Secret Keys in Git
When configuring S3 or cloud upload buckets, AI agents place raw AKIA access keys and secret tokens directly in client upload utilities.
Supabase Service Role Key Excluded from Client Code
AI tools mix up the public anon key with the full-access service_role key, pasting the service key into client Supabase clients.
No NEXT_PUBLIC_ or VITE_ Prefixes on Private Secrets
When an environment variable is undefined in client code, agents prefix it with NEXT_PUBLIC_ without recognizing it exposes private secrets.
JWT Signing Secrets Isolated on Server
Agents write fallback secret strings like secret = process.env.JWT_SECRET || "default_jwt_secret" which allows trivial signature forging.
Transactional Email Service Keys (SendGrid/Resend) Protected
Email sending logic is often placed in frontend utilities or webhook helpers with hardcoded re_ or SG. keys.
.env Files Added to .gitignore Before Initial Commit
AI scaffolding scripts create .env or .env.local files before initializing git, causing them to be tracked in history.
Public Webhook Signing Secrets Verified on Backend Only
Agents sometimes import webhook secrets into shared types or configuration files accessible by frontend builders.
Authentication Middleware Covers All Private API Routes
AI agents create new API routes in subfolders (e.g. app/api/user/settings/route.ts) that bypass the middleware matcher regex.
Rate Limiting Enforced on Login, Signup & Reset Endpoints
AI models write straightforward credential check handlers without considering brute-force or credential-stuffing attacks.
No Wildcard CORS on Authenticated API Endpoints
To fix cross-origin browser errors during development, agents frequently add Access-Control-Allow-Origin: * to all responses.
Row Level Security (RLS) Enabled on Supabase / PostgreSQL Tables
Lovable and Bolt create database tables via migrations but frequently forget to execute ALTER TABLE ... ENABLE ROW LEVEL SECURITY.
Object-Level Access Control (IDOR / BOLA Prevention)
AI route handlers read an id from the URL params and query db.find(id) without verifying the record belongs to the logged-in user.
Session Cookies Configured with HttpOnly, Secure, and SameSite
Agents set cookies using basic document.cookie or simple response headers without security flags.
Strict Redirect URL Allowlist on OAuth Callbacks
AI code accepts a redirect query param from the user and passes it directly to router.push() or res.redirect(), enabling open redirects.
Session Token Expiry and Revocation Handlers Present
Agents generate JWT tokens with infinite or multi-year expiry times so users never have to re-login.
Passwords Hashed with Argon2 or Bcrypt (Minimum 10 Rounds)
Custom auth code written by AI sometimes uses SHA256 or MD5 hashes without salt instead of standard password hashing algorithms.
No Role Escalation Flaws in User Registration
AI endpoints accept req.body directly into user creation, allowing users to pass role: "admin" in the signup JSON payload.
State-Changing Actions Restricted to POST/PUT/DELETE
Agents sometimes create GET endpoints like /api/delete-item?id=123 for convenience, exposing them to prefetching and CSRF.
Multi-Tenant Data Isolation Enforced in Database Queries
In multi-tenant or team apps, AI forgets to include org_id or team_id in sub-entity queries.
Stripe Webhook Signature Verification Mandatory
Agents parse req.body as plain JSON and process checkout events without running stripe.webhooks.constructEvent().
Webhook Idempotency Prevents Double-Credit or Double-Grant
Stripe delivers events multiple times during retries. AI handlers increment balances directly without tracking event.id.
customer.subscription.deleted Handled to Revoke Access
AI boilerplate handles checkout.session.completed but forgets customer.subscription.deleted, leaving cancelled users on paid tiers indefinitely.
invoice.payment_failed Handled to Notify User & Restrict Features
AI templates assume all recurring payments succeed, ignoring declined cards and expired payment methods.
Prices Defined Server-Side (No Client-Provided Price Overrides)
Frontend checkout forms written by AI sometimes pass price or amount in the checkout POST body, enabling client price tampering.
Raw Request Body Preserved for Webhook Handler in Next.js
In Next.js App Router, agents use req.json() on webhook routes which breaks Stripe signature cryptographic checks.
Stripe Customer ID Mapped Reliably to User Account
AI routes match users by billing email alone. When a user checks out with a different Apple Pay or PayPal email, the account is never upgraded.
Checkout Session Creation Rate-Limited
Unprotected checkout session endpoints allow malicious bots to spam Stripe API calls and hit provider rate limits.
Payment Entitlements Verified Server-Side in Database
Some AI apps read user tier from a client localStorage item or unverified session claim, allowing users to unlock features with DevTools.
No Hallucinated npm or PyPI Package Imports
LLMs invent plausible package names like @auth/next-guard or react-smart-filter that do not exist. Attackers can register these (slopsquatting) to inject malware.
Committed Lockfile Present (package-lock.json or pnpm-lock.yaml)
AI coding tools sometimes generate a package.json without running a package install, omitting the lockfile from the repository.
No Unpinned Asterisk (*) or Loose Major Ranges on Critical Packages
Agents put "stripe": "*" or "express": "latest" in package manifests, which breaks production builds when dependencies release breaking changes.
No Known Critical CVEs in Production Dependencies
AI models frequently recommend outdated package versions trained into their weights (e.g. Next.js 13 or vulnerable jsonwebtoken releases).
No Conflicting Lockfiles (Single Package Manager Enforced)
Developers switch between npm, yarn, and pnpm during AI prompts, leaving multiple conflicting lockfiles in the repository.
No Bloated or Abandoned Utility Libraries (e.g. Full Lodash Imports)
AI writes import _ from "lodash" for a single helper function, bundling 70KB of unused legacy utilities into frontend scripts.
DevDependencies Properly Separated from Production Dependencies
AI tools add build tooling, testing frameworks (jest, vitest), and types directly into dependencies instead of devDependencies.
No Untrusted Third-Party CDN Script Tags in index.html
To add features quickly, agents paste unversioned <script src="https://cdn..."> tags into root layouts without integrity hashes.
Duplicate Functionality Libraries Consolidated
AI prompts across different sessions import both axios and native fetch, or date-fns and dayjs in the same codebase.
No Unused Packages Left in package.json
When AI replaces a feature or refactors an approach, it leaves the previous packages in package.json.
Parameterized Queries on All Database Operations (No Raw SQL Concatenation)
AI writes template string queries like `SELECT * FROM users WHERE email = '${req.body.email}'` which allows trivial SQL injection.
No dangerouslySetInnerHTML Without Strict Sanitization
When rendering markdown or rich text, agents render raw strings directly through dangerouslySetInnerHTML={{ __html: content }}.
Runtime Schema Validation on All Incoming API Requests (Zod/Valibot)
Agents typecast request bodies using TypeScript interfaces (const body = await req.json() as UserInput) with zero runtime validation.
No child_process.exec with Unsanitized User Input
AI scripts that invoke shell commands often concatenate user parameters into exec(`ffmpeg -i ${filename}`) enabling arbitrary command injection.
Path Traversal Prevention on File Downloads and Uploads
Agents read files using path.join(uploadDir, req.query.file) without stripping ../ sequences, allowing attackers to read system files.
Server-Side Request Forgery (SSRF) Protection on URL Fetchers
When building preview scrapers or webhook testers, AI uses fetch(req.body.url) without blocking loopback IPs or cloud metadata endpoints.
File Upload Extension and MIME Type Verification
Agents validate only the client-reported file extension (.jpg) without verifying magic bytes or blocking executable extensions (.svg, .html, .exe).
Maximum Request Payload Size Limits Enforced
AI route handlers do not specify body size limits, exposing serverless workers to memory exhaustion and denial-of-service.
No Regex Denial of Service (ReDoS) Vulnerabilities
Agents write complex nested regular expressions like /([a-z]+)+$/ for email or URL checks that hang on crafted input.
Input String Trimming and Length Bounding
AI forms accept arbitrarily long strings without max-length limits, causing database column truncation or layout breaks.
No Passwords or Tokens Logged in console.log Statements
During debugging, AI agents place console.log("Login payload:", req.body) in auth routes, leaking passwords into server log stores.
No Sensitive Query Parameters in Browser URLs
AI reset password flows sometimes put reset tokens or user emails in GET query parameters, leaking them into referrer headers.
Error Responses Strip Internal Server Stack Traces in Production
Catch blocks written by AI return res.status(500).json({ error: error.message, stack: error.stack }), leaking internal file paths.
PII Scrubbing in Client Analytics and Error Trackers (Sentry/PostHog)
AI scaffolding scripts send full page state and form input events directly to analytics trackers without PII masking.
Privacy Policy and Terms of Service Routes Live & Linked
AI apps often have dead footer links pointing to "#" or generic placeholders for /privacy and /terms.
Cookie Consent or Necessary-Only Cookie Classification Defined
AI templates drop third-party tracking pixels (Meta Pixel, Google Ads) without providing a banner or privacy opt-out mechanism.
Account Deletion Flow Implemented (GDPR / CCPA Right to Erasure)
AI apps build sign up and profile editing but omit the delete account endpoint, violating store guidelines and privacy laws.
Debug Logging Disabled in Production Builds
Developers leave verbose DEBUG=* or verbose logger configurations active when pushing to production hosts.
Content Security Policy (CSP) Defined on All HTML Pages
Default Next.js and Vite scaffolds do not include a Content Security Policy header unless explicitly configured in config files.
Strict-Transport-Security (HSTS) Active with 1-Year Max Age
AI templates do not set HSTS headers, leaving browsers vulnerable to SSL stripping attacks on initial visits.
X-Content-Type-Options: nosniff Header Enabled
Modern frameworks require custom header definitions to guarantee MIME sniffing protection on static and dynamic assets.
X-Frame-Options: DENY or SAMEORIGIN (Clickjacking Protection)
AI apps often overlook frame protection headers, allowing malicious websites to embed the app in invisible iframes.
Referrer-Policy Set to strict-origin-when-cross-origin
Without a Referrer-Policy header, outgoing links can leak private path names and query strings to external domains.
Permissions-Policy Disables Unused Hardware Features
AI boilerplates omit the Permissions-Policy header, leaving camera, microphone, and geolocation permissions open by default.
No Hardcoded "localhost" URLs in Production Code
Agents hardcode fetch("http://localhost:3000/api/...") during local testing and forget to replace it with dynamic environment variables.
NODE_ENV Explicitly Set to "production" in Deployment Settings
Hosting presets sometimes run dev scripts instead of production builds, leaving slow development diagnostics enabled.
No eval() or new Function() Dynamic Execution Sinks
When asked to parse dynamic expressions or formulas, AI code resorts to eval() or new Function(code)() which creates arbitrary code execution holes.
Unsanitized LLM Markdown Output Safely Rendered in UI
AI coding tools render streaming model output directly into DOM nodes without filtering out malicious script injection from external prompts.
System Prompts Protected from Direct Client-Side Exposure
In client-side AI apps, agents place detailed system instructions in frontend state, allowing users to extract proprietary prompts in DevTools.
Tool Calls and Function Calling Validated Before Execution
When AI agents generate tool calls (e.g. deleteUser, sendMoney), code executes the function arguments without user permission or boundary checks.
AI Output JSON Parsed with try/catch and Schema Validation
AI frequently outputs markdown code fences (```json ... ```) that break JSON.parse() and crash application route handlers.
Token Usage and Output Length Limits Enforced on Model Calls
AI templates omit max_tokens parameters, allowing unbounded prompt loops that exhaust API credit balances.
Prompt Injection Safeguards on User Input Before LLM Calls
Agents concatenate raw user input directly into system prompts (e.g. `System: ${userPrompt}`) without boundary delineation.
Fallback Logic for LLM API Timeouts and Rate Limits
When an AI provider returns 429 (rate limited) or 503 (overloaded), the app hangs or displays a blank screen.
No Monolithic "God Files" Exceeding 500 Lines of Code
AI tools prefer appending new code to existing files rather than refactoring, producing massive 1,000+ line components that break context windows.
Duplicate API Fetch Logic Refactored into Reusable Functions
Agents copy and paste the same fetch boilerplate (headers, error handling, token attachment) across dozens of components.
Unused Imports and Orphaned Files Removed
When AI replaces an approach, it leaves old component files, dead utility functions, and unused imports in the codebase.
No Lingering "TODO: Implement Later" in Critical User Paths
AI agents frequently place comments like // TODO: add real payment verification or // TODO: handle error in critical backend routes.
Deeply Nested Conditionals Refactored (Max 4 Levels)
Agents write deeply nested if/else ladders inside callbacks rather than using guard clauses or early returns.
Consistent State Management Pattern (Avoid Mixed Paradigms)
Across different prompt iterations, agents mix Redux, Zustand, React Context, and raw useState for the same application state.
TypeScript strict Mode Enabled in tsconfig.json
To silence compiler errors quickly, agents set "strict": false or sprinkle any types across complex interfaces.
No Mock Test Data Remaining in Production API Handlers
AI handlers frequently contain commented-out or active mock data (const users = [{ id: 1, name: "Test" }]) that overrides real database calls.
No Swallowed Catch Blocks (Empty catch (e) {})
When async code throws, AI agents wrap it in try { ... } catch (e) {} with no logging or error handling, making production bugs impossible to diagnose.
Global Error Boundary (error.tsx) Configured in Next.js
AI templates omit error.tsx and global-error.tsx, causing unexpected component crashes to render an unstyled white screen of death.
Custom 404 Not Found Page (not-found.tsx) Live
Default frameworks show generic 404 pages that break brand continuity and leave lost visitors with no navigation path back to the home page.
Asynchronous Promise Rejections Explicitly Handled
AI writes unhandled floating promises like doAsyncWork() without await or .catch(), triggering unhandledRejection crashes on Node.js.
Network Requests Implement Timeout Limits
Native fetch calls without an AbortController signal can hang indefinitely if a third-party API becomes unresponsive.
Form Submissions Show User-Friendly Validation Feedback
AI forms often log errors to console but fail to show visible error messages to the user when validation fails.
Database Reconnection and Pool Retry Configuration Active
AI sets up database clients that crash on transient network disconnects without automatic pool reconnection.
Graceful Degradation for Optional Third-Party Services
If an optional analytics or chat widget fails to load, the AI script crashes the entire page layout.
Next/Image or Optimized Formats Used (No Multi-Megabyte PNGs)
AI puts raw 4MB screenshot PNGs into /public/hero.png and uses raw <img> tags instead of responsive next/image components.
Web Fonts Self-Hosted or Preloaded via next/font
AI templates drop multiple heavy Google Fonts @import statements in globals.css, blocking first contentful paint by 1-2 seconds.
Heavy Component Modules Dynamically Imported (Code Splitting)
Heavy libraries like Monaco Editor, charting engines (Chart.js), or rich text editors are statically imported into initial bundles.
No N+1 Waterfall Queries in Server Components or Endpoints
Agents execute database queries in array.map(async (item) => await db.find(item.id)) loops rather than using single batch queries.
Static Assets Cached with Long-Lived Cache-Control Headers
Custom server configs and API routes serve static assets with no-cache headers, causing repeat downloads on every page view.
Gzip or Brotli Compression Enabled on Production Server
Custom Express or VPS configurations miss compression middleware, serving uncompressed text and JSON payloads.
No Infinite Re-render Loops in useEffect Hooks
AI frequently omits dependency arrays or updates state inside a useEffect that depends on the same state, spinning CPU cycles.
Third-Party Analytics and Pixels Deferred or Loaded via Strategy
Agents paste tracking scripts directly into the HTML <head> with synchronous execution, delaying time to interactive.
Core Web Vitals Pass Lighthouse Performance Baseline (75+)
Accumulated client scripts, unoptimized fonts, and missing image dimensions push Core Web Vitals into failing zones.
.env.example Documented with All Required Variable Names
When collaborating or deploying, AI adds new environment variables in code without updating .env.example, causing deployment failures.
Health Check Route (/api/health) Responds 200 OK
Hosting platforms like Render, AWS, or Railway require a lightweight health endpoint to confirm container uptime.
Robots.txt Configured with Production Host and Sitemap Link
AI projects often deploy with default robots.txt that blocks search engines (Disallow: /) or misses sitemap location.
Sitemap.xml Generated and Valid for All Key Marketing Routes
AI apps often have broken or outdated sitemaps that point to localhost or omit dynamic blog and tool pages.
OpenGraph Meta Tags & Social Share Card Previews Configured
When founders share their new app on Twitter/X or LinkedIn, the link shows a broken preview or default framework icon.
Favicon and App Icons Customized (No Framework Defaults)
Vibe-coded apps frequently deploy with the default Next.js, Vercel, or Vite triangular favicon in browser tabs.
Canonical URL Configured on All Major Landing Pages
Search engines see duplicate content penalties when both www and non-www or trailing slash versions of URLs are indexed.
Automated Database Backup and Restore Procedure Verified
AI developers set up cloud databases (Supabase, Neon, Render) without confirming point-in-time recovery (PITR) is active.
Don't verify 108 items manually before launch.
Run an automated audit across your entire repository with the Founder Pass ($15 one-time). Get exact file locations, severity rankings, and 1-click Cursor fix prompts in minutes.