Audit & fix
What is vibe coding? What it’s good for, and what breaks when real users arrive
What vibe coding means, what it’s good for, what the security research shows, and the checks to run before real users arrive.
In short
Vibe coding is building software by describing what you want to an AI and accepting the code it writes without reading it. Andrej Karpathy coined the term in February 2025, and Collins made it its 2025 Word of the Year. It is a fast way to build a prototype and a risky way to launch one. In Veracode’s 2026 tests, AI-generated code passed security checks only 56% of the time. The public incidents are mostly missing access rules and exposed keys, and both can be checked before real users arrive.
Key takeaways
- The term comes from Andrej Karpathy (February 2025), who described it for “throwaway weekend projects”.
- In Veracode’s 2026 tests, AI-generated code passed security checks 56% of the time, barely changed from a year earlier.
- Most real incidents are configuration mistakes: missing row-level security, keys in the browser, public-by-default data.
- Lovable, Replit and Bolt all describe their own security scans as a first pass, not a full review.
What is vibe coding?
The term comes from a post by Andrej Karpathy, a founding member of OpenAI, on February 2, 2025: “There’s a new kind of coding I call ‘vibe coding’, where you fully give in to the vibes, embrace exponentials, and forget that the code even exists.” He described accepting every change without reading the diffs, and called it “not too bad for throwaway weekend projects”.
The word spread quickly. Collins named it Word of the Year for 2025, defining it as “the use of artificial intelligence prompted by natural language to write computer code”. Merriam-Webster added a full entry in September 2026. Tools such as Lovable, Bolt, Replit and Cursor are built around the idea: you describe the app, and the AI writes and runs it.
Is all AI-assisted coding vibe coding?
No, and the difference matters. The programmer Simon Willison drew the line in March 2025: “If an LLM wrote the code for you, and you then reviewed it, tested it thoroughly and made sure you could explain how it works to someone else that’s not vibe coding, it’s software development.” A year after coining the term, Karpathy wrote that professionals now work “with more oversight and scrutiny”, and that his preferred name for that is “agentic engineering”.
Most professional developers use AI but don’t vibe code. In Stack Overflow’s 2025 Developer Survey of more than 49,000 developers, 84% were using or planning to use AI tools. But 72% said vibe coding was not part of their professional work, and a further 5% said so emphatically.
What is vibe coding good for?
Speed, above all. It is a good fit for:
- Prototypes and demos: showing an idea to users or investors in days rather than months.
- Internal tools that hold no sensitive data and have a handful of trusted users.
- Personal projects and one-off scripts.
- Testing whether anyone wants the thing, before paying to build it properly.
The line is crossed the moment the app holds other people’s data or money. From then on it is not a weekend project, and it needs the checks below.
Is vibe coding safe?
Not by default. Independent research keeps finding that AI-generated code often works and is often insecure, and that the people using it tend to overestimate its quality:
| Study | What it tested | Finding |
|---|---|---|
| Veracode, July 2026 | 80 coding tasks across 11 new models | Average security pass rate of 56%, barely changed from 55% a year earlier |
| Veracode, July 2025 | 80 tasks across more than 100 models, in four languages | 45% of samples failed security tests with OWASP Top 10 flaws; security did not improve with model size |
| SusVibes (Carnegie Mellon), December 2025 | 186 real-world tasks with AI coding agents | The best setup solved 57% of tasks correctly, but only 11.8% securely |
| Perry et al., ACM CCS 2023 | Developers with and without an AI assistant | Those with the assistant wrote less secure code and were more likely to believe it was secure |
| METR, July 2025 | 16 experienced open-source developers, 246 issues | With AI they took 19% longer, while believing it had made them 20% faster |
What actually goes wrong in vibe-coded apps?
The documented failures are rarely clever attacks. They are settings nobody checked, and the same few repeat:
| When | What happened | Cause |
|---|---|---|
| March 2025 | CVE-2025-48757: 170 of 1,645 Lovable projects scanned had exposed data, including emails, payment details and API keys. Rated 9.3 (critical); Lovable disputes responsibility | Missing row-level security |
| July 2025 | Replit’s AI agent deleted a company’s production database during a code freeze; Replit then separated development and production databases automatically | No separation between test and live data |
| July 2025 | Wiz found that private apps on Base44 could be joined without authorization; fixed within about a day | Sign-up endpoints that didn’t check who was asking |
| October 2025 | Escape.tech scanned more than 5,600 public vibe-coded apps and found over 2,000 vulnerabilities and 400 exposed secrets | Mixed: access rules, secrets, exposed data |
| February 2026 | Moltbook exposed 1.5 million API tokens and 35,000 email addresses | A database key in the browser and no row-level security |
| April 2026 | Lovable disclosed that chat history and source code of public projects had been readable by other users since February | A regression in Lovable’s own backend |
| September 2026 | UpGuard found 16,326 Supabase databases with readable tables among roughly 300,000 domains checked | Tables created without row-level security |
Two things stand out. Most of these are access-control mistakes, which a checklist catches. And several happened in the builders themselves, which is a reason to check your own app rather than assume the platform has.
What do the AI app builders say about security?
They are candid about it. Lovable’s documentation says: “You are responsible for ensuring that your app meets the security requirements appropriate for its use case”; its scans “cannot guarantee complete security”; and for sensitive apps it recommends “an additional professional security review.” Replit says its pre-publish checks “complement, rather than replace” a full scan. Bolt calls its publish-time audit “a first pass, not a replacement.”
What should you check before real users arrive?
These catch most of the incidents above. None needs you to read the code line by line:
- Row-level security is on for every database table, with a policy per operation. Our Supabase RLS checklist shows how to test it.
- No secret key is in the browser: search the built JavaScript for anything that isn’t meant to be public.
- Every server endpoint checks who is asking. Hiding a button is not access control.
- Projects, storage buckets and files are private unless you chose otherwise.
- Development and production use separate databases, so a test run can’t touch live data.
- Backups exist, and you have restored one.
- Payments reconcile: webhooks are verified, and cancellations and refunds update your records.
- Errors and downtime alert a person.
The longer version is the 20 ways AI-built apps fail in production, and for Lovable specifically, from Lovable demo to production.
When does a vibe-coded app need a professional review?
When it holds personal data, takes payments, or lets users see each other’s information. That is also where Lovable’s own documentation recommends one. The AI-Built App Audit Report is that review: read-only access, a written report ranked by severity in two business days, $349, and the fee is credited against any fix. If the report finds more than you want to fix yourself, the Launch Hardening Sprint fixes it at a fixed price.
Sources
- Andrej Karpathy on X — “vibe coding” (February 2, 2025)
- Andrej Karpathy on X — one-year retrospective (February 4, 2026)
- Simon Willison — Not all AI-assisted programming is vibe coding (March 19, 2025)
- Collins Dictionary — Word of the Year 2025
- Merriam-Webster — 1,400 new words and definitions (September 15, 2026)
- Stack Overflow — 2025 Developer Survey, AI
- Veracode — 2026 GenAI Code Security Report
- Veracode — 2025 GenAI Code Security Report
- Zhao et al. — SusVibes (arXiv, December 2025)
- Perry et al. — Do Users Write More Insecure Code with AI Assistants? (ACM CCS 2023)
- METR — Early-2025 AI and experienced open-source developer productivity (July 10, 2025)
- Matt Palmer — Statement on CVE-2025-48757
- NIST National Vulnerability Database — CVE-2025-48757
- Fortune — Replit AI agent wipes a production database (July 23, 2025)
- Wiz — Critical vulnerability in Base44 (July 29, 2025)
- Escape.tech — Vulnerabilities in apps built with vibe coding (October 2025)
- Wiz — Exposed Moltbook database (February 2, 2026)
- Lovable — Our response to the April 2026 incident
- UpGuard — Systemic data exposure in Supabase apps (September 25, 2026)
- Lovable — Security documentation
- Replit — Security scanner documentation
- Bolt — Security audit on publish (July 30, 2026)