App rescue
Vibe coding security checklist: 10 issues to fix before you launch
The security problems that show up again and again in AI-generated apps, and how to check for each one before real users and real data arrive.
Key takeaways
- AI-generated apps repeat the same security mistakes, so one checklist catches most of them.
- The big three: secrets in code, endpoints without authentication, and missing row-level security.
- Never trust prices, roles or user IDs sent from the browser; re-check them on the server.
- Add rate limits, backups and monitoring before launch, not after the first incident.
On this page
Vibe coding, building an app by describing it to an AI tool, gets you a working product fast. It also tends to repeat the same security mistakes, because the models learned them from the same code. Security reviews of AI-generated apps report the same findings over and over: hardcoded secrets, missing authentication on endpoints, unvalidated input and outdated dependencies (Valletta Software, Code Like a Girl).
The good news: because the mistakes are predictable, so is the checklist.
1. Secrets in the code or the browser
Search the code and its git history for API keys, database URLs and tokens. Anything secret belongs in server-side environment variables. Rotate every key that was ever committed or sent to the browser.
2. Endpoints without authentication
List every API route and server function. Each one that reads or changes private data must check who is calling it, on the server.
3. Access rules on the data itself
If you use Supabase (as Lovable does), row-level security policies decide who can read and write each row. Make sure they exist on every table with user data, and test them as two different users.
4. Trusting the browser
Prices, roles, user IDs and permissions must never come from the browser unchecked. Recalculate and re-check them on the server.
5. Input validation
Validate every form field and API parameter on the server: type, length, format. This closes the door on injection attacks and broken records.
6. Unsafe output
Anything a user typed and the app later displays must be escaped, or it can run as code in someone else’s browser (cross-site scripting).
7. Outdated dependencies
AI tools often pick package versions they saw most in training, which can be old and carry known vulnerabilities. Run npm audit or pip-audit and upgrade carefully.
8. Error messages that leak
Stack traces and raw database errors tell attackers how your app works. Show users a plain message and log the details privately.
9. No rate limiting
Login, sign-up and contact forms without rate limits invite brute-force attempts and spam. Add limits and a bot check.
10. No backups or monitoring
Turn on database backups, test a restore once, and make sure you’ll find out when something breaks before your users tell you.
When to get help
If several of these are open on your app, a focused review before launch costs far less than fixing a breach after it. That review is the first step of an app rescue.

