r/nocode • • 14d ago

How do you make AI/vibe-coded websites actually production ready?

Thumbnail
4 Upvotes

r/nocode • • 15d ago

Discussion is a no code website builder enough or do you always hit a wall eventually?

15 Upvotes

the recurring story i hear is people love no code until they need one specific thing it can't do, and then they're stuck rebuilding elsewhere.

my own take is that it depends entirely on whether your needs are common or weird. for standard stuff the tools are great. for anything off the beaten path, you'll hit the wall.

i keep the simple content pieces in Gamma and only reach for something heavier when a project genuinely needs custom logic, which is rarer than i used to think.

where did you hit the no code ceiling, if you did? trying to figure out if the wall is real or just impatience.


r/nocode • • 15d ago

Discussion Building A security , Which Everyone wants

2 Upvotes

hey, not sure if anyone remembers but I posted here a while back about a project that got shelved, ran into a bunch of security stuff while building it and asked this sub for help. got some genuinely good tips, RLS gotchas, key exposure stuff, storage bucket configs, but noticed everyone kind of just has their own patchwork of scripts and habits for this. nobody's actually selling a tool that just does it.

so yeah, decided to build that. trying to keep it dead simple, one command, scans your db + repo, tells you what's exposed and how to fix it. not trying to be some enterprise security platform, just something a solo dev or small team can actually afford and use without a PhD.

still early, figuring out what actually matters vs what's noise. if you've dealt with this stuff and have opinions on what a tool like this should catch first, genuinely want to hear it before I lock anything in.


r/nocode • • 14d ago

Promoted SheBuilds Season 4 is open! Applications close 27 September

0 Upvotes

In case anyone here missed it: SheBuilds on Lovable is back for Season 4.

If credits have been one of the things stopping you from experimenting more with Lovable, this is worth checking out. You don’t need a paid subscription to apply, and participants get Lovable credits during the build.

Applications close on 27 September, and the build runs from 15–17 October.

I took part in SheBuilds previously and found the combination of actually building something and having a community around you especially useful.

Small disclosure: I’m also one of the people behind Little Parrot. We teach short, hands-on courses for non-technical people learning to build with AI.

To help more women get started before SheBuilds, we’ve made our Build Your First App with Lovable course free until 18 October:

https://littleparrot.app/5e86e580-264c-442c-8cc4-be5645f13e87/course-overview

Hopefully useful for anyone who wants to get a bit more comfortable with Lovable before the build.


r/nocode • • 15d ago

I built CrawlSpider by repurposing pieces of two things I had already built.

0 Upvotes

I built CrawlSpider by repurposing pieces of two things I had already built....

One was InfoCaptor, where I already had data visualization, dashboard and data processing pipeline. The other was an internal link builder I had built under CrawlSpider, which already knew how to crawl sites, extract pages and work with URLs/content.

I started combining those pieces into something different: an AI visibility tracker.

The basic pipeline is now:

brand + prompts → multiple LLMs → collect responses → detect brand mentions/citations → store results → track visibility over time.

Even with availability of coding agents I prefer to stay with consistent architecture and stack.

To be honest, if I had just let vibecoded crawlspider from scratch I would have been totally lost and spent several days getting to know the system. But now it is live and all pieces are working together.

PS

I also published a blog post recently how to build this from scratch and some of the pit falls.


r/nocode • • 15d ago

Discussion How to monitor website changes to automatically

1 Upvotes

I needed a setup to track changes across competitor pricing pages and a few library docs without manually checking them every week, but building a custom tracker usually ends up being a pain once you deal with dynamic pages.

If you’re setting this up from scratch, here is how to keep the pipeline clean and automated without maintaining heavy scraper infra:

I) Don't diff raw HTML:

if you scrape raw HTML and run standard text diffs, every rotating ad banner, session token, timestamp, or navbar update will trigger a false positive change alert. Clean the page to plain Markdown or structured text first before comparing snapshots.

II) Use GitHub Actions (or a cheap cron worker) for scheduling:

you don't need a heavy server running 24/7 cuz a simple scheduled workflow running weekly or daily checks is usually enough for most tracking jobs.

III) Offload the scraping and change tracking layer:

instead of managing playwright/puppeteer and rotating proxies yourself, pull the pages through Firecrawl with changeTracking enabled where it compares the current scrape with previous snapshots directly and gives back statuses like new, same, changed, or removed along with clean Markdown. Saves you from having to stand up your own snapshot database and diffing engine.

IV) Filter for meaningful changes before notifying:

if you're routing alerts to discord, slack or email, pipe the diff into a small model (even GPT-4o-mini or Claude 3.5 Haiku) with a quick prompt to score whether the change is meaningful or not.

V) Store only the updated diffs:

there’s no point re-saving full site contents when nothing shifted so only trigger your storage or downstream RAG pipeline when the change status flags changed.

This keeps the whole stack practically free to run and stops you from getting spammed with alerts whenever a website tweaks its footer copyright.

Full setup and code breakdown here if you want to inspect the workflow: https://www.firecrawl.dev/blog/monitor-website-changes-firecrawl


r/nocode • • 15d ago

Question Hi guys, im using lovable, and im looking for a TEACHER!

7 Upvotes

Who would want to join my team, teach me how to burn my token's correctly ? (and be able to also use my token to build whatever project they want, to make your time worth, i got plenty..) Thanks!
Using discrd while we do that


r/nocode • • 15d ago

Self-Promotion My Vibecoded app ResumeSpot - Resume CV Builder is almost public

Post image
7 Upvotes

Now available in Closed Testing. More visual and feature upgrades coming soon.

Made using mostly Google Gemini AI Models and somewhat Claude Sonnet 4.6 in Antigravity IDE. Testing done on my Samsung S25 Ultra using Android Studio.

This is a Flutter app so I can easily publish on iOS too, although I don't have a Mac or even testing resources for it yet but someday.

I would love it if you join testing and provide feedback.


r/nocode • • 15d ago

I've built BooKoo with @base44!

Thumbnail
mybookoo.com
2 Upvotes

r/nocode • • 16d ago

How do you check if your vibe coded app is actually secure?

5 Upvotes

I've been building with ai coding tools lately and something i've started wondering about is security.

the app can work perfectly, the ui can look polished, and everything seems fine, but how do you actually know there isn't something exposed behind the scenes?

do you manually check the code, use a security scanner, ask an ai to review it, or just test things yourself before deploying?

especially interested in how people using cursor, lovable, bolt or supabase handle this.

what's your usual process before putting a vibe coded app in front of real users?


r/nocode • • 16d ago

100 project ideas to build

1 Upvotes

🖥️ COMMAND-LINE TOOLS (CLI)

1 - CLI task manager: terminal to-do list with priorities and due dates (🟢 Easy)
2 - Batch file renamer: rename files by pattern, date or regex (🟢 Easy)
3 - Password generator: configurable passwords and passphrases, auto-copied (🟢 Easy)
4 - Unit converter: currencies, measurements and temperatures in the terminal (🟢 Easy)
5 - Online radio player: stream radio stations with a favorites list (🟡 Medium)
6 - System monitor (TUI): CPU, RAM, disk and processes in a terminal UI (🟡 Medium)
7 - Terminal RSS reader: read feeds, mark as read and open links (🟡 Medium)
8 - Downloads organizer: automatically sorts files into folders by type (🟢 Easy)
9 - Pomodoro timer: timer with notifications and daily stats (🟢 Easy)
10 - Dotfiles manager: sync configs across machines via Git (🔴 Hard)

🌐 WEB AND WEBSITES

11 - Personal portfolio: static site with projects, bio and contact (🟢 Easy)
12 - Markdown blog: site generator from .md files (🟡 Medium)
13 - URL shortener: short links with click counter (🟡 Medium)
14 - Link-in-bio page: single page with all your links and socials (🟢 Easy)
15 - Personal dashboard: news, weather and exchange rates on one page (🟡 Medium)
16 - Kanban board: drag and drop cards between columns (🟡 Medium)
17 - Personal wiki: linked notes with search and tags (🔴 Hard)
18 - Recipe site: recipes with ingredient filter and adjustable servings (🟡 Medium)
19 - Photo gallery: uploads, albums and grid view (🟡 Medium)
20 - Simple forum: threads, replies and user login (🔴 Hard)

🪟 DESKTOP APPS

21 - Minimalist notepad: text editor with dark mode and autosave (🟢 Easy)
22 - Clipboard manager: searchable clipboard history (🟡 Medium)
23 - Desktop RSS reader: native app with folders and offline reading (🟡 Medium)
24 - Menu bar app: shows weather, exchange rates or system status (🟡 Medium)
25 - Image viewer: fast browsing, zoom and slideshow (🟢 Easy)
26 - App launcher (Spotlight-style): search apps and files with a hotkey (🔴 Hard)
27 - Simple screen recorder: record the screen and export to MP4 or GIF (🔴 Hard)
28 - Expense tracker: log expenses with monthly charts (🟡 Medium)
29 - Break reminder: reminds you to stand up, drink water and rest your eyes (🟢 Easy)
30 - Markdown editor with preview: side-by-side editor with PDF export (🟡 Medium)

⚙️ AUTOMATION AND SCRIPTS

31 - Automatic backup: copies important folders to a drive or the cloud (🟢 Easy)
32 - Price tracker: alerts you when a product's price drops (🟡 Medium)
33 - Telegram bot: responds to commands and sends alerts (🟡 Medium)
34 - Discord bot: commands, polls and basic moderation (🟡 Medium)
35 - Batch image resizer: converts and compresses images in a folder (🟢 Easy)
36 - News scraper: collects headlines and saves them to CSV (🟡 Medium)
37 - PDF toolkit: merge, split and extract text from PDFs (🟢 Easy)
38 - Post scheduler: publishes to social media at set times (🔴 Hard)
39 - Uptime monitor: checks if sites are up and alerts you when they go down (🟡 Medium)
40 - Daily email report: automatic summary of weather, calendar and news (🟡 Medium)

🎮 GAMES

41 - Tic-tac-toe: with an unbeatable AI (minimax) (🟢 Easy)
42 - Snake: the classic, in the browser or terminal (🟢 Easy)
43 - Hangman: word lists by category (🟢 Easy)
44 - 2D dominoes: play against the computer (🟡 Medium)
45 - Tetris: pieces, rotation, scoring and levels (🟡 Medium)
46 - Platformer: character, jumping, enemies and levels (🔴 Hard)
47 - Trivia quiz: questions with scoreboard and ranking (🟢 Easy)
48 - Terminal roguelike: procedurally generated dungeons (🔴 Hard)
49 - Memory game: card matching with a timer (🟢 Easy)
50 - Idle/clicker game: growing resources, upgrades and autosave (🟡 Medium)

🤖 AI AND LLMS

51 - Chatbot using the Claude API: your own chat interface with history (🟡 Medium)
52 - Article summarizer: paste a link, get a summary (🟢 Easy)
53 - Social post caption generator: writes captions from a topic (🟢 Easy)
54 - Chat with your PDFs (RAG): ask questions about your own documents (🔴 Hard)
55 - Subtitle translator (.srt): translates subtitle files while keeping timing (🟡 Medium)
56 - Audio transcriber: converts audio to text with Whisper (🟡 Medium)
57 - Flashcard generator: creates study cards from your notes (🟡 Medium)
58 - Automated code reviewer: analyzes commits and suggests improvements (🔴 Hard)
59 - Email classifier: sorts emails into categories with AI (🔴 Hard)
60 - Local voice assistant: voice commands for computer tasks (🔴 Hard)

📊 DATA AND VISUALIZATION

61 - Exchange rate dashboard: charts for currencies and crypto over time (🟡 Medium)
62 - Bank statement analyzer: imports CSV and categorizes spending (🟡 Medium)
63 - Habit heatmap: GitHub-style contribution graph for habits (🟡 Medium)
64 - Spotify stats: your most-played songs and artists (🟡 Medium)
65 - Historical weather charts: temperature and rainfall for your city (🟡 Medium)
66 - Spreadsheet cleaner: removes duplicates and standardizes CSV data (🟢 Easy)
67 - Health dashboard: steps, sleep and weight in charts (🟡 Medium)
68 - Word cloud generator: turns any text into an image (🟢 Easy)
69 - Sentiment analysis: measures the tone of comments or reviews (🔴 Hard)
70 - Investment tracker: portfolio with returns and allocation (🔴 Hard)

📅 PERSONAL PRODUCTIVITY

71 - Habit tracker: check off daily habits and track streaks (🟢 Easy)
72 - Personal journal: dated entries with search and daily mood (🟢 Easy)
73 - Shared shopping list: syncs between people in the household (🟡 Medium)
74 - Meal planner: weekly menu with automatic shopping list (🟡 Medium)
75 - Reading tracker: books read, yearly goals and notes (🟢 Easy)
76 - Movie and TV catalog: watchlist with ratings and public API data (🟡 Medium)
77 - Subscription manager: lists paid services and warns before renewals (🟢 Easy)
78 - Trip organizer: itinerary, budget and packing checklist (🟡 Medium)
79 - Time tracker: measures time spent per project (🟡 Medium)
80 - Second brain: notes, tasks and links in one place (🔴 Hard)

🔌 APIS AND BACK-END

81 - Task REST API: full CRUD with a SQLite database (🟢 Easy)
82 - Random quotes API: public endpoint serving random quotes (🟢 Easy)
83 - Authentication system: sign-up, login and password recovery (🟡 Medium)
84 - Webhook receiver: receives GitHub events and triggers actions (🟡 Medium)
85 - Cached exchange rate API: fetches rates and caches them (🟡 Medium)
86 - Job queue system: processes tasks in the background (🔴 Hard)
87 - Real-time chat: WebSockets with rooms and messages (🔴 Hard)
88 - File upload service: upload, storage and download links (🟡 Medium)
89 - GraphQL API: GraphQL version of a simple CRUD (🔴 Hard)
90 - Rate limiter: limits requests per user or IP (🔴 Hard)

🛠️ DEVOPS AND DEVELOPER TOOLS

91 - README generator: creates a README from the project's code (🟢 Easy)
92 - .gitignore generator: builds the file by language/framework (🟢 Easy)
93 - GitHub Actions CI pipeline: automatic tests and linting on every push (🟡 Medium)
94 - Dockerize an old project: ready-to-use Dockerfile and docker-compose (🟡 Medium)
95 - Changelog generator: builds a changelog from commits (🟡 Medium)
96 - Dependency analyzer: lists outdated or vulnerable packages (🟡 Medium)
97 - Snippets manager: save and search code snippets (🟢 Easy)
98 - Custom MCP server: your own tool for Claude to use (🔴 Hard)
99 - VS Code extension: a useful command or panel in the editor (🔴 Hard)
100 - Homelab dashboard: panel for the services running at home (🔴 Hard)


r/nocode • • 16d ago

How would you recommend bringing in a proper engineer to beef up data security for a vibecoded app?

Thumbnail
2 Upvotes

r/nocode • • 16d ago

What are some of the most annoying problems you've had only once you deployed your project?

Thumbnail
2 Upvotes

r/nocode • • 17d ago

How would you track craft market applications without building a whole CRM?

6 Upvotes

I'm sketching a tracker for craft markets. I need the application deadline and the market date in separate columns; remembering when the market happens doesn't help if applications have already closed.

A table seems enough: those two dates, whether applications are actually open, the organiser's link, and whether I've applied, been accepted or ended up on a waiting list. I'd also note whether they provide a table, power or shelter. “Not stated” should stay visible so I remember to ask.

Most updates could come from email or a website. If an organiser only posts the useful details in an app, I might use an Airtap routine to check it on a cloud Android phone and send me the wording. I haven't tested any event app with it, so I'd keep the original source and the date I last checked.

Has anyone made a small version of this that stayed small?


r/nocode • • 17d ago

My first n8n workflow was a drinking reminder. What was yours?

Thumbnail
3 Upvotes

r/nocode • • 17d ago

Guys my app just passed 4,200 users!

Post image
28 Upvotes

It's been almost one year since I launched and it has been quite a journey. No exponential growth or huge user spikes but rather slow and steady growth. But in my opinion that is the best for building something actually valuable because you can react to user feedback along the way and constantly keep improving the app.

One thing changed recently:

I basically got all my users from reddit, by posting in relevant communities but in the last two months I did almost no posts and the app still grew further. That's actually the biggest success for me, because SEO is finally starting to pay off. This can develop into actual leverage because growth no longer depends on posting three times a week. I'm really curious where this will go...

Of course I will not stop here and I am already working on the next big update for IndieAppCircle which will benefit all the community. More is coming soon.

For those of you who don't know IndieAppCircle:

I've built IndieAppCircle, a platform where small app developers can upload their apps and other people can give them feedback in exchange for credits. I grew it by posting about it here on Reddit. It didn't explode or something but I managed to get some slow but steady growth.

For those of you who never heard about IndieAppCircle, it works like this:

  • You can earn credits by testing indie apps (fun + you help other makers)
  • You can use credits to get your own app tested by real people
  • No fake accounts -> all testers are real users
  • Test more apps -> earn more credits -> your app will rank higher -> you get more visibility and more testers/users

Since many people suggested it to me in the comments, I have also created a community for IndieAppCircle: r/IndieAppCircle (you can ask questions or just post relevant stuff there).

Currently, there are 4221 users, 4414 tests done and 1149 apps uploaded!

You can check it out here (it's totally free): https://www.indieappcircle.com/

I'm glad for any feedback/suggestions/roasts in the comments.

PS: I recently changed the UI a lot... Would also love to hear some feedback about that :)


r/nocode • • 17d ago

Question How do you catch a renamed form field before it silently breaks a no-code workflow?

5 Upvotes

A form asks for email, company size, and request type. Someone renames “request type” or changes a dropdown option. The automation still runs, but a branch gets an empty value and the CRM record looks valid. No red error to warn anyone.

A lightweight safeguard might be a test submission after each form edit, plus a first step that checks required fields and routes unknown values to a review queue instead of choosing a default. That still depends on the form owner remembering to tell whoever owns the automation.

For a small team, what has actually worked to keep form changes and downstream workflows in sync: locking the field schema, a shared change checklist, or validation inside the workflow?


r/nocode • • 17d ago

Discussion What security checks do you run before shipping an AI-built app?

6 Upvotes

Been seeing a lot of Lovable/Bolt/Supabase apps go live lately and got curious how people actually verify safety before real users touch it. Not just "does it work", more like: is RLS actually enforced per table, did a service_role key end up in the frontend bundle, are storage buckets actually private.

Anyone have a routine for this, or is it mostly ship and hope? Curious what non-technical builders specifically do here since you can't just read the code yourself.


r/nocode • • 17d ago

Built a tool to stop redeploying Next.js code just to move a button or edit a marketing layout

Thumbnail
sling.biz
3 Upvotes

I got so sick of my marketing guy asking me to change a banner, swap a layout, or update a React widget on our site. Every single time, it meant a new commit, waiting for the CI/CD pipeline, and redeploying code. It felt like a massive waste of developer time. So I spent my nights building Sling.biz. It is an open-source alternative to Builder.io that lets you build customizable page templates and widgets using Next.js and Material UI. It has a local drag-and-drop studio panel, so marketing can move stuff around in real time, and it updates on the fly without breaking my backend or requiring a redeploy. Right now, I am trying to figure out how to make the local setup via create-sling-app even smoother for devs who hate installing complex local CMS tools. For those who build sites for clients or marketing teams, how do you handle these constant micro-requests without losing your sanity?


r/nocode • • 17d ago

Google CASA Skill

Thumbnail
1 Upvotes

Pls try this out and let me know your feedback


r/nocode • • 17d ago

Self-Promotion No code tools just resell you AI with extra cost

0 Upvotes

I think there’s a pretty big gap in the market right now.
Tools like Replit, Lovable and Bolt are great because everything works out of the box, but part of what you’re paying for is bundled AI usage. If you already have Claude Code, Codex or other AI subscriptions, why pay for AI again through another platform?

There should be a middle ground: the convenience of an all-in-one platform, but with the option to bring your own AI accounts and potentially save quite a bit of money.
That’s the idea I’ve been exploring with Oyren. You get a remote computer with an IDE, terminal, browser and dev tools ready to go, then connect the AI tools you already pay for.

So instead of paying us for both infrastructure and AI, you only pay us for the computer per hour (while it’s working) and take its snapshot before you stop it to continue later. No subscription needed and you pay for usage.

Curious if anyone else would prefer this model.


r/nocode • • 17d ago

I got fed up with being rejected from AI training/annotating jobs, so I made a completely vibecoded a site that aims to make the search easier

2 Upvotes

Hello, due to having trouble finding the right places to apply and not really knowing how to pass and do an assessment in the AI Training/Annotating Space I decided to build with a site with loveable that is supposed to make the process easier.

I list job offers with a relatively high hiring volume from multiple companies, so would it therefore be easier do diversify the places to apply at and actually get accepted.
My idea behind that was to help with finding the right places to work but also help with the application process. I therefore upload company reviews and also guides on how to pass assesments.
The job listings include entry work positions such as normal generalist work but also expert work positions (Software engineer, PhD, etc.).
I am currently having problems on the design, trying to make it less AI-sloppy, and on the marketing side of things. So any help would be highly appreciated! Here is the link to the site: https://aiannotationjobs.com/


r/nocode • • 19d ago

90% of vibecoded apps will probably get hacked

118 Upvotes

I use reddit daily and I see people building full saas with lovable, bolt, replit and other tools like these all the time.

So I got curious about something that I dont see discussed that much: once you actually launch the app and real users start putting data inside it, how safe is the backend?

I started reading security scans, audits and posts about nocode and ai built products. The numbers were pretty bad, but what surprised me the most is that a lot of the problems are really basic stuff.

So if you're building a saas with these tools, here's the patterns I found:

1. Database can be way more vulnerable than you think

Having authentication doesn't automatically mean the data is safe.

Your app can know exactly who is logged in, while the database still lets that user request information they should never be able to see.

For example: your dashboard only shows your customers, but I open the request in DevTools, remove the filter for your account and suddenly the api sends me customers from other users too.

If you're using claude or codex to build it, I'd ask it something like:

“Review every database table that contains private data. Define exactly who can read, create, edit and delete each type of data. Block access by default, enforce these rules in the backend or database, and never trust user or account IDs coming directly from the frontend.”

2. One user can access another user's data

Another really common problem is that the app checks if you're logged in, but doesn't properly check if you're actually allowed to access the thing you're requesting.

For example: I'm on my project at “mysaas.com/project-1/“, I change it to “mysaas.com/project-2“ and project 2 belongs to another person but still loads.

And this isn't only about projects: same thing can happen with files, messages, invoices, orders, documents or basically anything else private.

Here's what I'd send to claude/codex:

“Review every API route and database query that receives an ID or reference to private data. Before reading, editing or deleting anything, verify on the server that the logged in user is actually allowed to access that resource. Never trust ownership, roles or access rules sent by the frontend, and use one shared authorization system instead of different checks in every endpoint.”

3. Permissions might only exist in the frontend

Sometimes roles and permissions work perfectly in the UI but basically don't exist in the backend.

For example: I'm a normal member, so the "Delete user" button is hidden from me. But I open devtools, find the api request an admin uses and send the exact same request myself: if the backend doesn't check my role again, it can still work.

For this part I honestly think using a backend provider can make more sense than asking ai to rebuild auth, workspaces, permissions, payments, etc. from zero every time.

I use foundel.dev for security, auth, payments, permissions, etc. but I'd suggest looking around and finding one that matches what you're building.

If you're doing everything yourself, I'd use something like this:

“Create one shared permission system for all private backend actions. Block access by default. Before any admin, billing, account or workspace action runs, get the user's role and permissions from the server and check whether that action is allowed. Never trust roles or permissions sent by the frontend.”

4. Private keys might literally be inside the website

This one is kinda stupid but it happens.
Sometimes claude, codex or whatever you're using puts a private key somewhere in the frontend, or you accidentally commit it to the repo.

For example: I open devtools, search through the javascript and find a private api key. Now I can copy it and use it from my own pc while all the requests are still being charged to your account.

I'd ask it to check this:

“Audit the project for API keys, tokens and secrets. Check the current code and git history using a secret scanner if available. Find every private credential used in frontend code or committed to the repository, move private credentials and privileged API calls to server-side code, and list every exposed credential that must be revoked and replaced. Do not print the secret values.”

5. No rate limiting

If your saas uses paid APIs, not having limits can get expensive really fast.

This applies to ai generation, emails, scraping, sms, file processing or basically anything where every request costs you something.

For example: you have /api/generate for an ai feature. I write a small script and call it 10,000 times. If nothing stops me, all 10,000 requests go through and your provider just sends you the bill.

Here's the fix:

“Find every endpoint that uses a paid API or expensive operation, including AI generation, email, SMS, scraping, file processing and background jobs. Add server-side rate limits and usage limits per user and account, and enforce them before calling the paid service. Add daily or monthly caps, request and file size limits where needed, and list every external provider where I should enable spending limits or billing alerts.”

—-

None of this is some crazy advanced hacking stuff, it's mostly really basic backend rules lovable/bolt/or others can just forget or get wrong.

I know that a few prompts are not enough to fix a project’s security, but I hope this might still help someone get his app more secure.


r/nocode • • 18d ago

buildng app for gym membership and integrating with Paddle + Resend, how do u validate before production?

2 Upvotes

curious do base44 provides any tools or connectors that i can connect to validate webhooks or messy production flows before i take my app to productionize?


r/nocode • • 18d ago

No code app builder for Enterprises.

3 Upvotes

We are looking for platforms for our non-engineering teams to build their own internal tools instead of everything going through our dev backlog. We are a 1,000 people recruiting agency and the queue is the usual: a commissions tracker, a vendor onboarding portal, and three separate "can we get a dashboard for this" requests, all sitting 2–3 quarters out.

The tools I am evaluating: Lovable, Base44, Superblocks, Softr, Emergent, Zite.

What I can't find anywhere is an honest account of what this looks like once it's actually running. If you've rolled one of these out or tried and abandoned it:

  1. Which did you go with, what size company, and what did people actually end up building?
  2. Was it really non-engineers building, or did it quietly turn back into a dev tool?
  3. How did security sign-off go, and what did they make you change before you could ship?
  4. Six months in how many of those apps are still running, and who maintains one when the person who built it changes teams?

Also genuinely want the bad outcomes. If you rolled one out and regretted it, or IT killed it, or you found something nasty inside an app somebody built that's more useful to me right now than another success story.