The VibeSecurity blog
Security for the way you build now.
Practical, source-backed writing for founders and builders shipping with AI tools: what breaks, how to test your own app, and what to fix first.
Fundamentals
Vibe Coding Security Risks, Ranked by Real-World Harm
The vibe coding security risks that most often hurt small apps, ranked by judgment, with a table of how each appears, how to test your own app and the fix.
Fundamentals
What Is Vibe Coding? A Security-First Explainer
What is vibe coding, where the term came from, how the workflow runs, and where security risk enters at each step. A plain guide for founders.
Fundamentals
Is Vibe Coding Safe? Decision Rules for Founders
Is vibe coding safe? An honest answer for founders: when it is fine, when it is not, and how data sensitivity should decide how much review you need.
Tools and workflow
Vibe Coding Security Checklist a Solo Founder Can Finish
A vibe coding security checklist with testable checks, how to verify each on your own app, and clear pass conditions. Finish it in an afternoon.
Incidents and lessons
CVE-2025-48757: What the Lovable RLS Flaw Teaches Supabase Apps
CVE-2025-48757 was about missing Row Level Security in Lovable-generated Supabase apps. Learn how the exposure works and how to test your own project.
Tools and workflow
Vibe Coding Security Tools: What Each Type Catches
A neutral guide to vibe coding security tools: what secret scanners, SAST, DAST and other types catch in AI-built apps, and how to combine them.
Incidents and lessons
Supabase RLS Mistakes AI Tools Make, With SQL Fixes
Six Supabase RLS mistakes that AI-built apps commonly ship, each with the wrong SQL, the right SQL and a way to test it. Fix them before launch.
Incidents and lessons
Exposed API Keys in Vibe-Coded Apps: Leaks and Rotation
How exposed API keys leak from AI-built apps, which keys are safe to ship, a step-by-step rotation runbook, and how to cap the damage.
Tools and workflow
How to Secure AI Generated Code: A Review Workflow
How to secure AI generated code with prompt habits, diff review, added tests and CI gates, plus what to do when you cannot read the code.
India
Vibe Coding India: DPDP Act Data Security for Founders
Vibe coding India guide: what founders shipping AI-built apps should know about the DPDP Act, 2023 and Rules, from consent to safeguards and breaches.
Tools and workflow
Vibe Coded App to Production: The Security Gap List
Taking a vibe coded app to production? See the security gaps between prototype and launch: secrets, auth, database rules, logging, backups and response.
Fundamentals
AI Generated Code Vulnerabilities Mapped to the OWASP Top 10
How each OWASP Top 10 (2021) category shows up in AI generated code vulnerabilities, with a mapping table and three worked examples with corrected code.
Tools and workflow
Prompt Injection in AI Coding Assistants: How to Defend
How prompt injection reaches an AI coding assistant through READMEs, issues, web pages and tool servers, and the controls that limit the damage.
Incidents and lessons
Slopsquatting: When AI Suggests Packages That Do Not Exist
Slopsquatting is when attackers register package names an AI made up. Learn how it works and the checks that keep hallucinated dependencies out.
Fundamentals
Vibe Coding Security for Beginners: A Plain-Language Guide
Vibe coding security for beginners who do not read code: four mental models, what to ask your AI, tests you can run with no coding, and when to hire a reviewer.
India
Startup Security Questionnaire India: Answer It Honestly
A startup security questionnaire India guide: build a one-page security note, answer data, access and backup questions honestly, and know CERT-In basics.
Want the scanner when it ships?
Join the waitlist. One email when it opens, nothing else.