PutThrough Product engineering studio
Book a build call

Audit & fix

What is vibe coding? What it’s good for, and what breaks when real users arrive

What vibe coding means, what it’s good for, what the security research shows, and the checks to run before real users arrive.

In short

Vibe coding is building software by describing what you want to an AI and accepting the code it writes without reading it. Andrej Karpathy coined the term in February 2025, and Collins made it its 2025 Word of the Year. It is a fast way to build a prototype and a risky way to launch one. In Veracode’s 2026 tests, AI-generated code passed security checks only 56% of the time. The public incidents are mostly missing access rules and exposed keys, and both can be checked before real users arrive.

Key takeaways

  • The term comes from Andrej Karpathy (February 2025), who described it for “throwaway weekend projects”.
  • In Veracode’s 2026 tests, AI-generated code passed security checks 56% of the time, barely changed from a year earlier.
  • Most real incidents are configuration mistakes: missing row-level security, keys in the browser, public-by-default data.
  • Lovable, Replit and Bolt all describe their own security scans as a first pass, not a full review.

What is vibe coding?

The term comes from a post by Andrej Karpathy, a founding member of OpenAI, on February 2, 2025: “There’s a new kind of coding I call ‘vibe coding’, where you fully give in to the vibes, embrace exponentials, and forget that the code even exists.” He described accepting every change without reading the diffs, and called it “not too bad for throwaway weekend projects”.

The word spread quickly. Collins named it Word of the Year for 2025, defining it as “the use of artificial intelligence prompted by natural language to write computer code”. Merriam-Webster added a full entry in September 2026. Tools such as Lovable, Bolt, Replit and Cursor are built around the idea: you describe the app, and the AI writes and runs it.

Is all AI-assisted coding vibe coding?

No, and the difference matters. The programmer Simon Willison drew the line in March 2025: “If an LLM wrote the code for you, and you then reviewed it, tested it thoroughly and made sure you could explain how it works to someone else that’s not vibe coding, it’s software development.” A year after coining the term, Karpathy wrote that professionals now work “with more oversight and scrutiny”, and that his preferred name for that is “agentic engineering”.

Most professional developers use AI but don’t vibe code. In Stack Overflow’s 2025 Developer Survey of more than 49,000 developers, 84% were using or planning to use AI tools. But 72% said vibe coding was not part of their professional work, and a further 5% said so emphatically.

What is vibe coding good for?

Speed, above all. It is a good fit for:

  • Prototypes and demos: showing an idea to users or investors in days rather than months.
  • Internal tools that hold no sensitive data and have a handful of trusted users.
  • Personal projects and one-off scripts.
  • Testing whether anyone wants the thing, before paying to build it properly.

The line is crossed the moment the app holds other people’s data or money. From then on it is not a weekend project, and it needs the checks below.

Is vibe coding safe?

Not by default. Independent research keeps finding that AI-generated code often works and is often insecure, and that the people using it tend to overestimate its quality:

What the research says about AI-generated code
StudyWhat it testedFinding
Veracode, July 202680 coding tasks across 11 new modelsAverage security pass rate of 56%, barely changed from 55% a year earlier
Veracode, July 202580 tasks across more than 100 models, in four languages45% of samples failed security tests with OWASP Top 10 flaws; security did not improve with model size
SusVibes (Carnegie Mellon), December 2025186 real-world tasks with AI coding agentsThe best setup solved 57% of tasks correctly, but only 11.8% securely
Perry et al., ACM CCS 2023Developers with and without an AI assistantThose with the assistant wrote less secure code and were more likely to believe it was secure
METR, July 202516 experienced open-source developers, 246 issuesWith AI they took 19% longer, while believing it had made them 20% faster

What actually goes wrong in vibe-coded apps?

The documented failures are rarely clever attacks. They are settings nobody checked, and the same few repeat:

Documented incidents involving AI-built apps
WhenWhat happenedCause
March 2025CVE-2025-48757: 170 of 1,645 Lovable projects scanned had exposed data, including emails, payment details and API keys. Rated 9.3 (critical); Lovable disputes responsibilityMissing row-level security
July 2025Replit’s AI agent deleted a company’s production database during a code freeze; Replit then separated development and production databases automaticallyNo separation between test and live data
July 2025Wiz found that private apps on Base44 could be joined without authorization; fixed within about a daySign-up endpoints that didn’t check who was asking
October 2025Escape.tech scanned more than 5,600 public vibe-coded apps and found over 2,000 vulnerabilities and 400 exposed secretsMixed: access rules, secrets, exposed data
February 2026Moltbook exposed 1.5 million API tokens and 35,000 email addressesA database key in the browser and no row-level security
April 2026Lovable disclosed that chat history and source code of public projects had been readable by other users since FebruaryA regression in Lovable’s own backend
September 2026UpGuard found 16,326 Supabase databases with readable tables among roughly 300,000 domains checkedTables created without row-level security

Two things stand out. Most of these are access-control mistakes, which a checklist catches. And several happened in the builders themselves, which is a reason to check your own app rather than assume the platform has.

What do the AI app builders say about security?

They are candid about it. Lovable’s documentation says: “You are responsible for ensuring that your app meets the security requirements appropriate for its use case”; its scans “cannot guarantee complete security”; and for sensitive apps it recommends “an additional professional security review.” Replit says its pre-publish checks “complement, rather than replace” a full scan. Bolt calls its publish-time audit “a first pass, not a replacement.”

What should you check before real users arrive?

These catch most of the incidents above. None needs you to read the code line by line:

  1. Row-level security is on for every database table, with a policy per operation. Our Supabase RLS checklist shows how to test it.
  2. No secret key is in the browser: search the built JavaScript for anything that isn’t meant to be public.
  3. Every server endpoint checks who is asking. Hiding a button is not access control.
  4. Projects, storage buckets and files are private unless you chose otherwise.
  5. Development and production use separate databases, so a test run can’t touch live data.
  6. Backups exist, and you have restored one.
  7. Payments reconcile: webhooks are verified, and cancellations and refunds update your records.
  8. Errors and downtime alert a person.

The longer version is the 20 ways AI-built apps fail in production, and for Lovable specifically, from Lovable demo to production.

When does a vibe-coded app need a professional review?

When it holds personal data, takes payments, or lets users see each other’s information. That is also where Lovable’s own documentation recommends one. The AI-Built App Audit Report is that review: read-only access, a written report ranked by severity in two business days, $349, and the fee is credited against any fix. If the report finds more than you want to fix yourself, the Launch Hardening Sprint fixes it at a fixed price.

Sources

  1. Andrej Karpathy on X — “vibe coding” (February 2, 2025)
  2. Andrej Karpathy on X — one-year retrospective (February 4, 2026)
  3. Simon Willison — Not all AI-assisted programming is vibe coding (March 19, 2025)
  4. Collins Dictionary — Word of the Year 2025
  5. Merriam-Webster — 1,400 new words and definitions (September 15, 2026)
  6. Stack Overflow — 2025 Developer Survey, AI
  7. Veracode — 2026 GenAI Code Security Report
  8. Veracode — 2025 GenAI Code Security Report
  9. Zhao et al. — SusVibes (arXiv, December 2025)
  10. Perry et al. — Do Users Write More Insecure Code with AI Assistants? (ACM CCS 2023)
  11. METR — Early-2025 AI and experienced open-source developer productivity (July 10, 2025)
  12. Matt Palmer — Statement on CVE-2025-48757
  13. NIST National Vulnerability Database — CVE-2025-48757
  14. Fortune — Replit AI agent wipes a production database (July 23, 2025)
  15. Wiz — Critical vulnerability in Base44 (July 29, 2025)
  16. Escape.tech — Vulnerabilities in apps built with vibe coding (October 2025)
  17. Wiz — Exposed Moltbook database (February 2, 2026)
  18. Lovable — Our response to the April 2026 incident
  19. UpGuard — Systemic data exposure in Supabase apps (September 25, 2026)
  20. Lovable — Security documentation
  21. Replit — Security scanner documentation
  22. Bolt — Security audit on publish (July 30, 2026)

About the author

Anubhav Mehrotra

Founder and principal engineer at PutThrough. Six-plus years shipping software end to end — Android and iOS apps, backends, frontends, infrastructure and AI agents.

Questions

Questions this raises

Something we haven’t covered?

Ask on a call
01 Who coined the term vibe coding?

Andrej Karpathy, a founding member of OpenAI and former director of AI at Tesla, in a post on X on February 2, 2025. He described giving in to the vibes and forgetting that the code exists.

02 Is vibe coding bad?

Not for prototypes, demos and personal tools, where it is fast and cheap. It becomes risky when an app holds other people’s data or money without anyone checking its access rules, keys and backups.

03 Is vibe coding the same as no-code?

No. No-code tools build apps from visual blocks inside the vendor’s platform. Vibe coding tools generate real source code, which you can usually export, edit and host elsewhere, and which therefore needs the same checks as any other code.

04 Does vibe coding make developers faster?

For prototypes, clearly. For experienced developers on familiar code the evidence is mixed: in METR’s 2025 trial, 16 experienced developers took 19% longer with AI tools while believing they had been 20% faster.

05 Can you launch a real business on a vibe-coded app?

Yes, once it has been checked and hardened. Row-level security on every table, no secret keys in the browser, server-side checks on every endpoint, separate test and live data, working backups and reconciled payments cover most of what goes wrong.

Have something to build?

A free 30-minute call. We’ll tell you honestly what fits in a week, and send a fixed quote afterward.

Prefer to write? Send your requirements

What do you need?

What it should do, who will use it, the must-haves, and any links. A few sentences is plenty.

Budget, if you have one in mind
When would you like to start?