App rescue

Vibe coding security checklist: 10 issues to fix before you launch

The security problems that show up again and again in AI-generated apps, and how to check for each one before real users and real data arrive.

Key takeaways

  • AI-generated apps repeat the same security mistakes, so one checklist catches most of them.
  • The big three: secrets in code, endpoints without authentication, and missing row-level security.
  • Never trust prices, roles or user IDs sent from the browser; re-check them on the server.
  • Add rate limits, backups and monitoring before launch, not after the first incident.
On this page
  1. 1. Secrets in the code or the browser
  2. 2. Endpoints without authentication
  3. 3. Access rules on the data itself
  4. 4. Trusting the browser
  5. 5. Input validation
  6. 6. Unsafe output
  7. 7. Outdated dependencies
  8. 8. Error messages that leak
  9. 9. No rate limiting
  10. 10. No backups or monitoring
  11. When to get help

Vibe coding, building an app by describing it to an AI tool, gets you a working product fast. It also tends to repeat the same security mistakes, because the models learned them from the same code. Security reviews of AI-generated apps report the same findings over and over: hardcoded secrets, missing authentication on endpoints, unvalidated input and outdated dependencies (Valletta Software, Code Like a Girl).

The good news: because the mistakes are predictable, so is the checklist.

1. Secrets in the code or the browser

Search the code and its git history for API keys, database URLs and tokens. Anything secret belongs in server-side environment variables. Rotate every key that was ever committed or sent to the browser.

2. Endpoints without authentication

List every API route and server function. Each one that reads or changes private data must check who is calling it, on the server.

3. Access rules on the data itself

If you use Supabase (as Lovable does), row-level security policies decide who can read and write each row. Make sure they exist on every table with user data, and test them as two different users.

4. Trusting the browser

Prices, roles, user IDs and permissions must never come from the browser unchecked. Recalculate and re-check them on the server.

5. Input validation

Validate every form field and API parameter on the server: type, length, format. This closes the door on injection attacks and broken records.

6. Unsafe output

Anything a user typed and the app later displays must be escaped, or it can run as code in someone else’s browser (cross-site scripting).

7. Outdated dependencies

AI tools often pick package versions they saw most in training, which can be old and carry known vulnerabilities. Run npm audit or pip-audit and upgrade carefully.

8. Error messages that leak

Stack traces and raw database errors tell attackers how your app works. Show users a plain message and log the details privately.

9. No rate limiting

Login, sign-up and contact forms without rate limits invite brute-force attempts and spam. Add limits and a bot check.

10. No backups or monitoring

Turn on database backups, test a restore once, and make sure you’ll find out when something breaks before your users tell you.

When to get help

If several of these are open on your app, a focused review before launch costs far less than fixing a breach after it. That review is the first step of an app rescue.

  • #vibe-coding
  • #security
  • #lovable
  • #replit
  • #base44
  • #checklist

Written by

Prayag Dalal

Freelance developer based in India. I build MVPs and SaaS apps, take Lovable, Bolt, Replit and Base44 apps to production, and build RAG chatbots for founders in the US and Europe.

Keep reading

More guides

All guides

Send me your prototype

A 30-minute call is enough to tell whether it fits, what the first version should include, and how long it takes.

Book a 30-minute call