← Vibe Coding

Safety guide

Is vibe coding safe? When it’s fine, when it isn’t, and how to check

Building an app by describing it to an AI is genuinely useful — and the risks are real, documented and mostly avoidable. This guide is for people who don’t read code: what can go wrong, what usually causes it, and what to check before you share a link.

Short answer

Safe for personal projects and prototypes. Risky the moment real people’s data is involved. Most real leaks came from one mistake — a database anyone could read because its access rules were never set — plus secret keys left in the page. Both are checkable without reading code.

How risky is your project?

ProjectRiskWhy
A page that only shows information (portfolio, menu, event)LowNothing private is stored
A tool only you use, with your own made-up dataLowIf it breaks, only you are affected
A form that collects names, emails or messagesMediumYou’re now storing other people’s details
Anything with user loginsMedium–highAccess rules decide who sees whose data
Payments, health, children’s or financial dataHighGet a developer to review it before launch

What has actually gone wrong

WhenWhoWhat happened
Mar–May 2025Lovable apps170 of 1,645 scanned apps (about 10%) exposed emails, addresses, payment details and keys.
Jul 2025Base44A public app ID let anyone into private apps. The platform fixed it in under 24 hours.
Jul 2025Replit / SaaStrDuring a code freeze the agent deleted a live database of 1,200+ records, then made up data. It was later recovered.
Jan–Feb 2026MoltbookA key left in the web page exposed 1.5M API tokens and 35,000 emails. The founder had written no code himself.
Apr 2026PocketOSA coding agent used an over-powered key and deleted the live database and its backups in about 9 seconds.

Across the board, security firm Veracode found AI-written code failed its security tests 45% of the time in 2025, and the pass rate barely moved in 2026 (55% to 56%).

The three causes behind almost every incident

  1. Missing database access rules. Your app’s database needs rules saying who can read and change which rows. Without them, anyone who finds the address can read everything. (In Supabase, which many builders use, this is called Row Level Security.)
  2. Secret keys in the page. API keys belong in the platform’s “Secrets” or environment settings, never in the code that runs in the visitor’s browser.
  3. Agents with too much access. An AI agent connected to your real database can delete it. Give agents a test copy, never the live one.

Before you share the link: a checklist

  1. Ask the AI: “List every place this app stores data and the access rules on each. Which tables could a logged-out visitor read?” Then try it yourself in a private browser window.
  2. Ask: “Are any API keys or passwords visible in the front-end code?” Move any it finds into Secrets.
  3. Run your platform’s security scan and fix anything marked serious.
  4. Make two test accounts and check that one can’t see the other’s data.
  5. Keep test data and real data separate, and never give an agent the live database.
  6. Save a checkpoint you can roll back to.
  7. If it handles payments, health, children or money: pay a developer for a review. It costs far less than a leak.

For the full beginner workflow and the tools to start with, see our vibe coding guide. Using a coding agent instead of an app builder? Compare Codex and Claude Code.

Sources: CVE-2025-48757 (Lovable) · Lovable security docs · Wiz on Base44 · The Register on Replit · Wiz on Moltbook · The New Stack on PocketOS · Veracode · Supabase: Row Level Security

Quick answers

Is it okay to vibe code a website?

Yes, for a website that only shows information — a portfolio, a menu, an event page — the risk is low. It gets risky when the site has logins, stores what visitors type in, takes payments or holds anyone’s personal details. Then you need the checks on this page, and ideally a developer to review it.

What are the cons of vibe coding?

You can’t easily tell whether the code is secure; AI-written code failed security tests 45% of the time in Veracode’s 2025 study. Fixes can loop and burn credits, the app can be hard to change later, and an agent with too much access can delete real data.

Is vibe coding bad?

No — it’s a good way to build prototypes, personal tools and small projects quickly. It’s the wrong approach for anything that handles other people’s money, health or private data unless someone who can read the code reviews it.

Can vibe-coded apps be hacked?

Yes, and several have been. The most common cause is a database left readable by anyone because its access rules were never set, followed by secret keys left inside the web page.

Do the app builders scan for security problems?

Several do — Lovable, for example, offers a security scan. Run it and fix anything serious before sharing, but don’t treat a clean scan as proof: scans miss things.