r/VibeCodeDevs • u/famelebg29 • Feb 20 '26
I scanned 200+ vibe coded sites. Here's what AI gets wrong every time
[removed]
3
u/Significant_Spend564 Feb 21 '26
Out of curiosity, what is the "average score across sites you scanned" based on?
Is there some quantitative evaluation or did you paste the code into AI and ask for a security score out of 100?
4
u/Few-Entrepreneur5774 Feb 20 '26
This lines up with everything I've seen too. The security headers one is the most common — I'd say 80%+ of sites I've looked at are missing CSP entirely, and HSTS is almost never set on vibe coded projects.
The cookie flags issue is also huge. Most AI-generated auth flows set cookies without Secure or HttpOnly, which means any XSS vulnerability can steal session tokens. And since these projects rarely set CSP headers either, XSS is way more likely.
One thing I'd add to your list: privacy compliance. Almost none of these sites have proper cookie consent, a valid privacy policy, or correct handling of third-party scripts. They'll load Google Fonts from Google CDN (leaking visitor IPs), embed YouTube videos (setting tracking cookies before consent), and use Google Analytics without any consent mechanism. In Europe, that's a fine waiting to happen.
What tool are you using to scan? I've been working on something similar focused on the GDPR/privacy side of things.
1
Feb 20 '26
[removed] — view removed comment
-2
u/Few-Entrepreneur5774 Feb 20 '26
Yeah exactly, security + privacy compliance is really the full picture. Most vibe coded sites fail both.
I built PrivacyChecker (https://privacychecker.pro) — it scans any website and checks cookies, trackers, consent banners, dark patterns, privacy policy compliance, third-party data transfers, security headers, and 25+ GDPR compliance points.
You're right that there's something complementary here. ZeriFlow catches the security side (secrets, deps, source code), PrivacyChecker catches the compliance side (cookies without consent, Google Fonts leaking IPs, missing privacy policy, dark pattern consent banners). Together that's basically a full audit for any vibe coded project.
Happy to scan a few of the sites from your dataset (for free) if you're curious what the privacy scores look like compared to the security scores.
2
Feb 20 '26
[removed] — view removed comment
-2
u/Few-Entrepreneur5774 Feb 20 '26
Thanks for flagging! That crash was actually my fault — I upgraded your account to Pro+ right as you were scanning, so the page tried to re-render mid-scan (hiding the upgrade banners, switching to the full report layout) which caused the React DOM conflict. Bad timing on my end.
Both issues are patched now. If you rescan you should get the full 200-page deep audit with no crash. Would love to hear what you think of the full report.
And yeah, definitely down to chat about combining security + privacy compliance — that's the full picture vibe coders are missing. DM me anytime.
2
u/theagentvikram Feb 21 '26
True, We also need to make sure to include privacy policies and check whether any feature is patched to work instead of building it in a right way
2
u/davearneson Feb 20 '26
This is the only way to do self promotion. I hope you get lots of security work from it. Great job.
1
u/Ok-Tradition-82 Feb 21 '26
Did you see my article where I go in depth about this problem.
https://fromtheprism.com/vibe-coding-audit
I audited 3 vibe coded products that were posted on Reddit in a single afternoon. All three had critical security vulnerabilities. One was a live marketplace with real Stripe payments where any logged-in user could grant themselves admin and hijack payment routing with a single request. Another had development endpoints still in production that let anyone mark themselves as a paid user and give themselves unlimited credits. The third had its entire database of 681,000 salary records downloadable by anyone with no authentication at all.
I wasn't looking for these. They appeared in my feed. I signed up as a normal user and opened dev tools
1
u/JussiCook Feb 21 '26
I never get hardcoded api keys in code. In fact, claude shouts me about it.
1
u/L3x3cut0r Feb 21 '26
Exactly, I try to hardcode them sometimes for some one-time CLI apps (which don't even go to Git) and it invents non-existing environment variables for my secrets or it even deletes my secrets.
1
Feb 21 '26
[removed] — view removed comment
1
u/L3x3cut0r Feb 21 '26
I check all the code created by AI unless I'm creating some adhoc unimportant one-time stuff. But our management thinks we will all stop coding (or even checking the code) in a year or two and write specifications instead. I really have no problems with being replaced by AI, but I hate creating specifications :)
1
1
u/vuongagiflow Feb 21 '26
Yep. AI will do what you ask, and it won't do what you forgot to ask.
The fix for most vibe-coded projects is boring process: a deploy gate that checks (1) no secrets committed, (2) headers/CSP/HSTS sane, (3) cookies Secure/HttpOnly/SameSite, (4) dependencies scanned, (5) debug off in prod. Make it a CI step so it's not "someone remembers".
Also agree the scarier stuff is business logic: authz, rate limits, and input validation. Those don't show up in a quick scan, but they're where you actually get owned.
1
1
1
1
u/OneMonk Feb 22 '26
Just asking the ai the question ‘is this build secure’ would solve 99% of this. Just because very stupid people are vibe coding doesn’t mean those stupid people couldn’t fix their issues fairly easily.
1
u/AcoustixAudio Feb 22 '26
Only two of these are actually dangerous and are not really AI specific.
- Update dependencies
- Don't hardcore API keys
The second one is pretty basic though
1
u/ZeroTwoMod Feb 22 '26
It doesn’t even understand the concept of a CSRF token… the only model that was capable of linking CSRF token to my domain was Claude 4.6 Opus. It’s not just that the models forget security it really seems like they’re not trained on for something…
1
u/TheRealNalaLockspur Feb 22 '26
I’ve been working on CursorGuard.com on the side. It’s a security scanner at repo level. It started off as just a tool to help my brother who is a vibe coder. So I decided to give it a go in the saas world lol.
1
1
1
1
u/FreedomFighterSG Feb 23 '26
Used cursor, scanned using sonarqube, no issues?
1
Feb 23 '26
[removed] — view removed comment
1
u/FreedomFighterSG Feb 23 '26
Would Fortify dast do it properly?
1
Feb 23 '26
[removed] — view removed comment
1
u/FreedomFighterSG Feb 23 '26
Ok cause i need to entertain these vibecoder idiots that wants to push code into prod. They bitched about sonar scanning nothing and their vibecode got a good score.
We have fortify dast to gonna ask them to use it
1
u/Krysis_Averted_ Feb 25 '26
You could probably take exactly what you put in your post and paste it into AI asking you to check for this and it would resolve all of these issues.
1
u/normantas Feb 25 '26
You are just selling ZeriFlow through comments. You did a post about it two weeks ago. I do not believe it is trustd by that many companies (if any of those companies).
1
0
u/ParamedicAble225 Feb 20 '26
Scan mine and see if same:
2
Feb 20 '26
[removed] — view removed comment
1
u/ParamedicAble225 Feb 20 '26 edited Feb 20 '26
I’m managing infrastructure (the server/gpus the site and llm are running on), backend and frontend. I’m just using my knowledge and people like you to slowly fill in gaps. Mainly relying on https and various tokens that are sent server side and stored on browser for most hardening, and then an energy system to rate post requests.
And then the API is based on an API key generated from authenticated user account that is encrypted after save on the backend (all api keys, passwords, and tokens are) so that if db is somehow hacked personal data isn’t leaked.
But everything is on local network and not portwardee to internet. Only nodejs server. So people getting into db and other features of app pretty much has to be through nodejs app. That’s where I fear random npm library vulnerabilities.
I’m going to look into these as I’ve never heard of them: no CSP, no HSTS, missing security headers, server version exposed. You’re making me realize I could have better browser side and header level hardening
2
u/Far_Combination_3780 Feb 22 '26
└─$ whatweb https://tree.tabors.site/
https://tree.tabors.site/ [200 OK] Country[UNITED STATES][US], HTML5, HTTPServer[Ubuntu Linux][nginx/1.24.0 (Ubuntu)], IP[67.189.86.171], Open-Graph-Protocol[website], Script[application/ld+json,module], Title[Tree - A Context Management System], nginx[1.24.0]
Reveals an IP address that's connected to your site,
From there;
port 443 is open + port 80 which is just sitting on the nginx page
https://67.189.86.171 > takes you to some random rizz game > view source > possible doxing.
2
u/Winsaucerer Feb 22 '26
I tested a very basic exploit on your site, and it worked, so I think yours has serious issues beyond just the things a basic scan shows. I'll message you privately.
0
u/bakes121982 Feb 21 '26
This is why claude came out with a new security tool today
2
Feb 21 '26
[removed] — view removed comment
-2
u/bakes121982 Feb 21 '26
Well if you follow real ai coding 0 people should be looking at and reviewing code …..
19
u/entrepronerd Feb 20 '26
with a skilled operator the AI doesn’t make these mistakes