Is my vibe coded app secure?
Probably not fully, and you cannot tell from using it. Vibe coded apps usually work well on the happy path and miss checks nobody asked for: whether one user can reach another's data, whether secret keys reach the browser, and whether database rules are on. Run the five checks below with two accounts. If any fail, or you cannot run them, get the app tested before it holds real data.
The five checks that matter most
- Two accounts. Log in as A and B in different browsers. From A, change every ID you can see in URLs and requests to B's. Nothing of B's should load or change.
- Database rules. If you use Supabase or Firebase, confirm row level security or security rules are on for everything. See the Supabase checklist.
- Secrets. Search your built front-end code for key prefixes like
sk_andservice_role. See exposed keys. - Admin routes. As a normal user, call the requests the admin screens make. They should be refused.
- Payments. Confirm access is granted by a verified server-side event, not by reaching a success page.
Why the app looks fine
The AI tool wrote what the prompt described and nothing else. "Show users their orders" produces a page that shows the logged-in user's orders and an endpoint that returns any order by ID. The page is correct. The endpoint is the hole, and no screen reveals it.
When it matters
| Your app | Urgency |
|---|---|
| A tool with no accounts or stored data | Low |
| Accounts and personal information | Before launch |
| Payments, health data or business customers | Before launch, with a report |
| An AI feature over customer data or with tools | Before launch, plus an AI assessment |
Signals your app needs attention now
- You have never opened the browser developer tools on your own app.
- Your Supabase or Firebase dashboard shows warnings you have not read.
- The app calls an AI, payment or email provider directly from the browser.
- Admin features are reachable by URL even if no button links to them.
- You added teams or organizations after the first version was built.
- Nobody other than you and the AI has looked at the code.
Each is common, and each is fixable. If several apply and real users are coming, use the risk score to see where to start, then fix the obvious items before paying for a test, so the tester's days go to what you could not find.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
- What security holes do AI-built apps have?
- Do I need a pentest before launch?
- Pre-launch security checklist
- Vibe coded app risk score
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Can I check this without knowing how to code?
The two-account test needs no code, only two browsers and patience. The key search needs the developer tools. Anything beyond that is what a tester does.
My AI tool says the app is secure. Is it?
The tool checks its own work with the same assumptions that produced it. Treat its answer as a first pass, not a verdict.