Roy Morken

Roy Morken

Indie security dev ismycodesafe.com

About

I'm an indie security practitioner based in Norway. I build ismycodesafe.com — a free passive scanner that runs 160+ checks (SSL/TLS, security headers, exposed paths, threat intel) on any URL in 30 seconds. Started it after seeing too many small teams ship production sites with the same handful of misconfigurations and pay five-figure consulting fees to find them. Last week I audited 100 YC startups (W25, S24, W24) — 94% missing basic security headers, 91% no CSP. Writeup: ismycodesafe.com/reports/yc-security-audit-2026 Outside of ismycodesafe I run Datafolka, a small code security consultancy. Launching on Product Hunt May 12.

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking

Forums

3mo ago

How are you dealing with vibe coding security risks in AI-generated code?

I ve been using a lot of AI-generated code lately, and while it definitely speeds things up, security feels like a weak spot.

I ve run into issues like missing auth, exposed endpoints, and weak configs stuff that AI doesn t really flag unless you explicitly ask.

Curious how others are handling this:

  • Do you rely more on manual reviews or tools?

  • Any workflows that consistently catch vulnerabilities?

  • Have you faced any real incidents because of AI-generated code?

View more