# Vibe coding security checklist: 10 issues to fix before you launch

> The security problems that show up again and again in AI-generated apps, and how to check for each one before real users and real data arrive.

- Author: Prayag Dalal (https://shipfast.online/about/)
- Published: 2026-10-07
- Canonical: https://shipfast.online/blog/vibe-coding-security-checklist/

## Key takeaways

- AI-generated apps repeat the same security mistakes, so one checklist catches most of them.
- The big three: secrets in code, endpoints without authentication, and missing row-level security.
- Never trust prices, roles or user IDs sent from the browser; re-check them on the server.
- Add rate limits, backups and monitoring before launch, not after the first incident.

Vibe coding, building an app by describing it to an AI tool, gets you a working product fast. It also tends to repeat the same security mistakes, because the models learned them from the same code. Security reviews of AI-generated apps report the same findings over and over: hardcoded secrets, missing authentication on endpoints, unvalidated input and outdated dependencies ([Valletta Software](https://vallettasoftware.com/blog/post/vibe-coding-security-risks), [Code Like a Girl](https://codelikeagirl.substack.com/p/how-to-make-vibe-coding-production)).

The good news: because the mistakes are predictable, so is the checklist.

## 1. Secrets in the code or the browser

Search the code and its git history for API keys, database URLs and tokens. Anything secret belongs in server-side environment variables. Rotate every key that was ever committed or sent to the browser.

## 2. Endpoints without authentication

List every API route and server function. Each one that reads or changes private data must check who is calling it, on the server.

## 3. Access rules on the data itself

If you use Supabase (as Lovable does), row-level security policies decide who can read and write each row. Make sure they exist on every table with user data, and test them as two different users.

## 4. Trusting the browser

Prices, roles, user IDs and permissions must never come from the browser unchecked. Recalculate and re-check them on the server.

## 5. Input validation

Validate every form field and API parameter on the server: type, length, format. This closes the door on injection attacks and broken records.

## 6. Unsafe output

Anything a user typed and the app later displays must be escaped, or it can run as code in someone else's browser (cross-site scripting).

## 7. Outdated dependencies

AI tools often pick package versions they saw most in training, which can be old and carry known vulnerabilities. Run `npm audit` or `pip-audit` and upgrade carefully.

## 8. Error messages that leak

Stack traces and raw database errors tell attackers how your app works. Show users a plain message and log the details privately.

## 9. No rate limiting

Login, sign-up and contact forms without rate limits invite brute-force attempts and spam. Add limits and a bot check.

## 10. No backups or monitoring

Turn on database backups, test a restore once, and make sure you'll find out when something breaks before your users tell you.

## When to get help

If several of these are open on your app, a focused review before launch costs far less than fixing a breach after it. That review is the first step of an [app rescue](https://shipfast.online/services/app-rescue/).

---

Book a 30-minute call: https://cal.com/prayagdalal/30min
