Vibe-Coded App Security Checklist: 12 Checks Before You Launch
A practical security checklist for apps built with Lovable, Bolt, Replit, Cursor or Claude Code: secrets, auth, database access, inputs, backups and monitoring — before real users arrive.
AI coding tools like Lovable, Bolt, Replit, Cursor and Claude Code make it possible to build a working app in a weekend. They also make it easy to ship one with security holes nobody noticed, because the code works — it just isn’t safe yet.
Use this checklist before your vibe-coded app handles real customers, real data or real money. Each check says what to look for and what “fixed” looks like. You don’t need to be a developer to run most of it; you do need to be honest about the answers.
1. Secrets and API keys
Check: search your code and repository history for API keys, database passwords and tokens — especially in front-end code, .env files committed to Git, and config files.
Fixed looks like: secrets live only in server-side environment variables or a secrets manager, are never sent to the browser, and any key that was ever committed has been rotated, not just deleted.
2. Authentication
Check: can someone reach logged-in pages or API routes without logging in? Do sessions ever expire? Is password reset safe?
Fixed looks like: a proven auth provider (not hand-rolled logic), sessions that expire, and every protected API route checks the user on the server — not just the page in the browser.
3. Authorization: can users see each other’s data?
Check: log in as user A, then change an ID in the URL or API request to user B’s record. If you see B’s data, you have the most common serious bug in AI-built apps.
Fixed looks like: every query is scoped to the signed-in user or account on the server. If you use Supabase or Firebase, row-level security or security rules are switched on and tested.
4. Database queries
Check: look for queries built by gluing strings together with user input.
Fixed looks like: parameterised queries or a query builder everywhere, so user input can never change the query itself.
5. Input validation
Check: what happens if a form field gets a 5 MB string, a script tag, a negative number or a file that isn’t an image?
Fixed looks like: validation on the server for type, length and format; output escaped when shown; file uploads checked for type and size.
6. File uploads and storage
Check: are uploaded files public by default? Can anyone guess the URL of another user’s document?
Fixed looks like: private storage buckets, signed time-limited URLs, and size and type limits on every upload.
7. Dependencies
Check: run your package manager’s audit command and look at how many packages the AI added that you don’t use.
Fixed looks like: known vulnerabilities patched, unused packages removed, and a lockfile committed.
8. Error handling and logging
Check: do errors show stack traces or database details to users? When something breaks in production, would you know?
Fixed looks like: friendly error messages for users, detailed logs and alerts for you, and no sensitive data written to logs.
9. Rate limiting and abuse
Check: can someone hammer your sign-up, login or AI endpoints thousands of times? If you call a paid AI API, can a stranger run up your bill?
Fixed looks like: rate limits on auth and expensive endpoints, bot protection on public forms, and spending caps on paid APIs.
10. Backups and recovery
Check: if your database were deleted right now, how much would you lose?
Fixed looks like: automatic backups, a tested restore, and separate development and production databases so experiments never touch real data.
11. Deploys and environments
Check: are you editing production directly from the AI tool?
Fixed looks like: a separate staging environment, changes reviewed as pull requests, and the ability to roll back a bad deploy in minutes.
12. Documentation for humans and AI
Check: could a new developer — or your AI tool in a fresh session — understand how the app is structured and what must never change?
Fixed looks like: a short README and a CLAUDE.md or AGENTS.md that explains the architecture, conventions and security rules, so future AI-assisted changes don’t quietly undo your fixes.
Quick triage: where to start
If you only have an afternoon, do these three first — they cause most real-world incidents:
- Rotate and move any exposed secrets (check 1).
- Test whether one user can see another user’s data (check 3).
- Turn on backups (check 10).
Keep building with AI — safely
Vibe coding isn’t the problem; shipping without a review is. Once the foundations are right, you can keep using AI tools to move fast without reopening the same holes.
If you’d rather have someone do the audit and fixes with you, that’s exactly what our vibe-code tune-up covers: a code and security review, fixes delivered as pull requests you approve, and documentation so your AI tools stay on track. Your repo, your code.