AI-built apps to production
Is vibe coding bad? Our verdict, and how to check your app before launch.
No. Vibe coding is fine for prototypes, demos, internal tools and testing whether anyone wants your idea. It turns risky when real users, payments or personal data arrive and nobody has checked login, database rules, secret keys, backups and error handling. Flamcom's Production Readiness Audit is that check.

Key takeaways
- Our verdict: vibe coding is a good way to build a first version and a poor way to ship one unchecked to paying customers.
- Most production failures sit in eight places: login, database access rules, secret keys, payment webhooks, error handling, backups, hosting costs and search visibility.
- Public reports back this up, from CVE-2025-48757 (insufficient row-level security in Lovable-generated sites, published May 2025 and disputed by Lovable) to a Replit agent deleting a production database in July 2025.
- Lovable gives you security scans; the settings of your own app are still your job.
- Flamcom's Production Readiness Audit is $299, fixed.
When is vibe coding fine, and when is it risky?
Vibe coding is good for speed and bad for unreviewed launches. That is our view.
Use it freely for a prototype, a sales demo, an internal tool or a landing page that tests demand, where a bug costs you an afternoon. That changes the day a stranger types a password into your app, a card gets charged, or you store someone's address, health details or payment history. From then on, a mistake leaks data, loses money or loses customers, and the demo code was never tested for any of that.
So the useful question is whether anyone has checked the app since it started holding real data. If nobody has, treat it as a prototype, however finished it looks.
What is vibe coding?
Vibe coding is building software by describing what you want to an AI tool in plain language and accepting the code it writes, often without reading it.
Andrej Karpathy, an OpenAI co-founder, named it in a post on X on February 2, 2025, describing a way of coding where you "fully give in to the vibes, embrace exponentials, and forget that the code even exists." Merriam-Webster lists the term and defines it as "writing computer code in a somewhat careless fashion, with AI assistance."
Tools such as Lovable, Bolt and Replit turn this into a product: you type a prompt, and you get a working web app with screens, a database and a login.
What is vibe coding good at?
Vibe coding is good at getting from idea to something clickable in days, for very little money. Here is what it does well.
- Testing demand. You can show a working app to ten possible customers before you hire anyone.
- Internal tools. A booking tracker or quote calculator used by five staff members rarely needs more.
- Clear specs. A working prototype explains what you want to a developer far better than a written brief.
- Readable starting code. Lovable, for example, produces standard React code you can sync to GitHub, so the work is not thrown away later.
Keeping a vibe-coded app as it is can be the right call. If it serves a small team, holds no sensitive data and takes no payments, the cost of hardening it may outweigh the risk.
The weak spot is security. Veracode's 2025 GenAI Code Security Report, published July 30, 2025, tested more than 100 AI models on 80 coding tasks and found the models chose an insecure way to write the code in 45% of cases.
Where do vibe-coded apps break in production?
They break where a demo never goes: strangers, money, failures and time. We look at eight areas first, and the table in the next section covers all of them. Four have the clearest public record.
Database access rules
Supabase is the database behind Lovable apps, either inside Lovable Cloud or in your own Supabase project. Its documentation says to switch on row-level security (rules on which user may read or change which rows) for every table in an exposed schema; with it off, anyone holding the public key in your app can read the table. On May 29, 2025, the US National Vulnerability Database published CVE-2025-48757 for insufficient row-level security in Lovable-generated sites, a record Lovable disputes, saying customers are responsible for their app data. Semafor reported the same day that researchers, one of them a Replit employee, found the flaw in 170 of 1,645 Lovable-built apps.
Payment webhooks
A webhook is the message your payment provider sends your app when a payment succeeds, fails or is disputed. Stripe's documentation says live events are retried for up to three days, can arrive more than once and should have their signature verified. We look for orders marked paid from the browser, skipped signature checks and repeat events processed twice.
Backups
Supabase's documentation says Pro, Team and Enterprise projects get daily backups, and tells Free plan projects to export their own data. In July 2025, Fortune reported that a Replit AI agent deleted the production database of an app built by SaaStr founder Jason Lemkin during a code freeze; Replit's CEO called it unacceptable and announced automatic separation of development and production databases.
Search visibility
Most vibe-coded apps are single-page applications: the browser builds each page with JavaScript, so a crawler reading raw HTML sees an empty shell. Google's JavaScript SEO guide says "server-side or pre-rendering is still a great idea because it makes your website faster for users and crawlers, and not all bots can run JavaScript." That rarely matters behind a login, but public pages need it; our guide to how AI assistants find pages explains why.
How can you check your own app's risk?

You can find the worst gaps in about an hour without reading code. The table sums up each risk; the full eight-step founder self-check is on our vibe-coded app to production page.
| Risk | What goes wrong | How to check it yourself | Fix effort (our view) |
|---|---|---|---|
| Login and reset | Emails never arrive; reset links open the preview site | Reset a fresh test account on your live domain | Small |
| Database rules | Other users' rows are readable with the public key | Open private data while logged out; check row-level security in Lovable Cloud's database view or your own Supabase dashboard, or have us check | Medium |
| Secret keys | Anyone can copy keys and use your accounts | In browser developer tools, search the live app's files for sb_secret_ or sk_live_, or have us check | Small, plus key rotation |
| Payment webhooks | Orders marked paid without payment, or charged twice | Run a test payment, then a failed one, and compare what the app records | Medium |
| Error handling | Blank screens, silent failures | Turn off your connection mid-action and watch what the app shows | Small to medium |
| Backups | One bad change wipes the data | Find the date of your last backup and the restore steps | Small |
| Hosting and costs | Surprise bills; accounts in someone else's name | List who owns the domain, database, hosting, code and payments | Small, more if you move |
| Search visibility | Public pages show as empty to crawlers | View the page source of your homepage and look for your headline | Medium to large |
Fix effort varies by app. The audit sets it for yours.
Is Lovable secure?
Lovable as a platform includes real safeguards, and your app is only as secure as its own settings.
Lovable's documentation describes a quick scan that runs before publishing and a deeper scan of access rules, secrets, payments and login. It also says these tools "cannot guarantee complete security" and that you are responsible for your app's security, especially with sensitive data.
Two 2026 reports show both sides. In February 2026, The Register reported a researcher's claim that one Lovable-hosted app exposed 18,697 user records, partly through missing row-level security; Lovable's security chief said every project gets a free scan before publishing and acting on it is up to the user. In April 2026, The Register reported a claim that free accounts could read other users' project data; Lovable said its explanation of public projects had been unclear and patched its API.
What a Lovable app needs before launch is on our Lovable production page. Built with something else? See our guides to taking a Bolt app to production and moving a Replit app to production hosting, or the Lovable vs Bolt vs Replit production comparison.
Should you fix a vibe-coded app or rebuild it?
Usually you fix most of it and rebuild a few weak parts, and we decide which per app in the audit.
Vibe coding cleanup means taking an AI-built app and closing the gaps between the demo and real customers: database rules, login, keys, payments, backups, monitoring, tests and search visibility. The working screens and logic stay wherever they hold up.
A full rebuild makes sense when the data model is wrong for the business, when fixes would touch nearly every file, or when the app has grown into something the builder handles poorly. If you need software designed from scratch, our custom development service covers that path.
What does the Production Readiness Audit cover?
It scores your app on seven areas and tells you, in plain language, what must be fixed before launch.
The seven areas are security, authentication, database, hosting, performance, error handling and SEO, and the eight places above map onto them. You order through our app audit form, and within one business day (Monday to Friday) we confirm the scope by email with a payment link.
The terms are fixed. The audit costs $299, and the report arrives within five business days of access to your project, or you get your money back. We need collaborator access to your builder project and read access to GitHub and Supabase, and we sign your NDA first on request. Order the build within 60 days of the report and the fee is credited toward the build.
Production builds start from $4,000, and most small apps cost $4,000 to $15,000. Most are production ready within two to four weeks of starting the build. Apps with payments or sensitive data take longer: we fix the issues the audit finds and tell you what still needs a specialist. All prices are in US dollars; see our app audit and build prices.
Flamcom's view is that vibe coding suits prototypes and internal tools, and needs a review before real users, payments or personal data arrive.
Flamcom decides in its Production Readiness Audit whether each vibe-coded app is fixed in place or has its weak parts rebuilt.
Flamcom's vibe coding cleanup covers database rules, login, secret keys, payments, backups, monitoring, tests and search visibility for AI-built apps.
Questions founders ask before launching a vibe-coded app
Is vibe coding safe for a real business?
It depends on what the app holds. For prototypes and internal tools with no sensitive data, the risk is low. For an app with customer accounts, payments or personal data, check database rules, secret keys, login, backups and error alerts before launch. Our founder self-check covers the first steps in about an hour.
What are the biggest vibe coding security risks?
The two biggest are database tables left open and secret keys shipped to the browser. Open tables let anyone holding the public key read other users' data, which is what CVE-2025-48757 described for Lovable-generated sites in 2025. Exposed keys let strangers use your Supabase, Stripe or AI accounts. Unverified payment webhooks and missing backups come next.
How much does vibe coding cleanup cost?
At Flamcom, cleanup starts with the $299 Production Readiness Audit, a fixed price with the report within five business days of access. Production builds start from $4,000, and most small apps cost $4,000 to $15,000. You get a written scope with a fixed price and timeline before any build work starts, and the audit fee is credited toward a build ordered within 60 days.
Can a Lovable app be production ready?
Yes, many can. The usual gaps are row-level security, login email delivery, secret keys in the browser and backups. Lovable's scans flag common issues and leave your app's settings to you. If you hire us, we fix the issues the audit finds and tell you what still needs a specialist. Our Lovable production page lists what we check first.
What are good vibe coding best practices for founders?
Sync your code to a GitHub repository you own from the first week. Switch on database security rules before real data goes in. Keep every secret key out of the browser. Test sign-up, reset and payment on your live domain, then a failed payment. Set up backups and error alerts, and ask someone who did not build the app to review it.
Should I stop using Lovable, Bolt or Replit?
No. Keep building in them while you test the idea; they are fast, and the code they produce can be cleaned up. Many apps stay on the builder after launch. What changes is the checking: once real users arrive, review the settings, accounts and data rules, and decide app by app whether the database and hosting should move into your own accounts.
Find out what your app needs before real users arrive.
Vibe coding got your app this far, and most of it is worth keeping. Before you take payments or store customer data, have someone check the eight places it is likely to break. Send your app link and the builder you used, and we reply within one business day (Monday to Friday) with the audit scope and a payment link.
Your Production Readiness Audit includes:
- A scored report across security, authentication, database, hosting, performance, error handling and SEO
- A prioritized fix list ranked by risk and effort, which you keep whether or not you hire us
- A recommendation on whether your database and hosting should move into your own accounts
- A debrief call with the engineer who reviewed your app
Sources
- Andrej Karpathy on X: post introducing "vibe coding" (February 2, 2025), accessed 2026-10-02
- Merriam-Webster: vibe coding (Slang and Trending), accessed 2026-10-02
- Veracode: AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks, accessed 2026-10-02
- Supabase: Row Level Security, accessed 2026-10-02
- NIST National Vulnerability Database: CVE-2025-48757, accessed 2026-10-02
- Semafor: The hottest new vibe coding startup Lovable is a sitting duck for hackers, accessed 2026-10-02
- Stripe: Receive Stripe events in your webhook endpoint, accessed 2026-10-02
- Supabase: Database backups, accessed 2026-10-02
- Fortune: AI coding tool Replit wiped a database and called it a catastrophic failure, accessed 2026-10-02
- Google Search Central: Understand the JavaScript SEO basics, accessed 2026-10-02
- Lovable Documentation: Security, accessed 2026-10-02
- The Register: Lovable-hosted app littered with basic flaws exposed 18K users, researcher claims, accessed 2026-10-02
- The Register: Vibe coding upstart Lovable denies data leak, cites "intentional behavior," then throws HackerOne under the bus, accessed 2026-10-02
More from the blog
Pricing, honestlyHow much does a website cost in 2026? Real prices for a small businessWhat a small business site costs on a DIY builder, with a freelancer, a studio or an agency, the first-year totals, and how to compare quotes. 11 min read.
Pricing, honestlyHow much does SEO cost? Small business prices for 2026, with ours publishedMonthly retainer, project and hourly prices side by side, what a month of SEO should include, and the questions to ask before you sign. 10 min read.