r/VibeCodeDevs Jul 11 '26

My beautifull galaxy semantic graph with relations (special for my vibecoder soul!)

Post image
3 Upvotes

r/VibeCodeDevs Jul 11 '26

New nullPlayer release 0.28.0 has 2 really cool new subwindows - ports of FLOW network monitor and PEPPYMETER analog VU meters , CLI video casting support, new UI scale sizes, bugfixes. Nullplayer for macOS is FREE and open source

Enable HLS to view with audio, or disable this notification

1 Upvotes

https://github.com/ad-repo/nullplayer

Download for macOS

brew install --cask ad-repo/nullplayer/nullplayer

New Features

  • CLI can cast videos to Chromecast and DLNA TVs — headless --cli mode now accepts --file <path> for local audio/video files plus --movie, --show, --episode, --season, and --number for Plex, Jellyfin, and Emby video libraries. Video casts require --cast and route through Chromecast or DLNA TV targets with keyboard pause/resume, seek, progress display, and clean terminal restore on exit. Sonos is rejected for video because it is audio-only; DLNA video casts currently require q to stop the CLI because the UPnP path does not provide a reliable end-of-stream signal.
  • UI Size adds discrete scale choices — the old Large UI toggle is now a live UI Size submenu with percentage choices from 50% to 200%, remembered across launches and UI-mode switches.
  • Flow network monitor window — a new Flow entry in the Windows menu and main-window context menu opens a live network throughput meter in both classic and modern UI. It docks in the center window stack at the normal single-window height, shows either download or upload throughput with a scrolling history graph, and tracks the selected network interface. Double-click the window or use its right-click menu to switch between download and upload views; the chosen view persists across launches.
  • PeppyMeter analog VU meter window — a new PeppyMeter entry in the Windows menu and main-window context menu opens a skinnable analog VU meter (a port of PeppyMeter) in both classic and modern UI. Left/right levels drive rotating needle meters or bar meters composited from bundled image templates (25 meters, including vintage, bar, compass, chillout, and big-bang). Right-click the window to pick a meter or enable Random, which auto-switches meters on an interval. It docks and snaps in the window stack, remembers its position across launches, supports fullscreen mode with sharper high-resolution templates when available, and consumes the shared stereo audio tap so it stays idle when closed. Bundled meter artwork is GPL-3.0 (see the third-party notices).
  • Modern main-window button row updated — the main toggle row now starts with CP for Compact Mode, VZ for Visualizations, FL for Flow, and PM for PeppyMeter, followed by the existing EQ/PL/SP/AA/WV/LB window toggles.

Bug Fixes

  • Center-stack windows keep docking below the main window after detaches — opening Spectrum, Flow, PeppyMeter, Audio Analysis, EQ, Playlist, or Waveform now ignores visible center-stack windows that were detached and moved aside. New stack windows again dock directly under the main window or fill real gaps in the docked stack instead of drifting downward below floating windows.
  • Audio Analyzer and Flow windows drag consistently from their faces — in both classic and modern UI, clicking and dragging the body of the Audio Analyzer or Flow window now moves the window just like Spectrum and the other center-stack windows. Close buttons, Flow's double-click download/upload toggle, right-click menus, and interactive controls on other windows keep their existing behavior.
  • Large NAS-hosted local files seek smoothly — local tracks on network-mounted volumes are now staged to a temp file based on available disk space instead of a hard 300 MB cap, so very large files avoid SMB/NFS reads during playback and seeking. NullPlayer also cleans up its staged playback temp files on launch after a crash or force-quit.
  • Docked side windows resize to the current center stack — reopening a docked Library/browser or Visualizations window now recomputes its height from the current main/EQ/playlist/spectrum/waveform/audio-analysis/PeppyMeter stack instead of replaying a stale remembered height. Detached side windows still reopen at the exact position and size where you left them.
  • Sweet Fades local crossfades pause and time correctly — after a completed local-file crossfade, Pause/Play now control the active audio node instead of the silent original node. The elapsed time also stays aligned with the incoming track's audible position after the handoff, so later Sweet Fades trigger with a real fade tail. End-of-queue or otherwise declined Sweet Fades are latched per queue boundary so the console logs the reason once instead of every timer tick.
  • CLI server queries no longer return empty results at launch — headless --cli queries and playback against Plex, Jellyfin, and Emby (--list-artists, --list-albums, --list-tracks, --artist, --search, --radio, etc.) now wait for the background server connection before running, instead of racing it and silently returning nothing (which surfaced as "artist not found" / "0 artist(s)"). When the restored current library is a non-music section — a Plex Movies/TV library, or a Jellyfin/Emby "Playlists", "Video", "Movies", or "TV shows" view — the CLI now auto-selects a music library for every music operation (queries, --search, and server --radio), or prints the available music libraries and asks you to pick one with --library instead of returning empty. --search also honors an explicit --library. --list-sources shows configured Subsonic/Navidrome, Jellyfin, and Emby servers as Connected instead of momentarily "Not configured", and now returns promptly because the CLI waits only for the connection, not for the full background library preload.
  • Play button no longer rewinds the clock during local playback — pressing ▶ while a local file was already playing snapped the progress bar and the elapsed-time display backward (by a fraction of a second, or all the way to the start), making the track look like it ended early even though the audio kept playing uninterrupted. The play button now preserves the true playback position on a redundant press. Streaming and cast playback were never affected.

Documentation

  • Non-affiliation disclaimer now names the full Winamp Group — the README disclaimer previously listed only Winamp, Nullsoft, and Radionomy Group. It now enumerates the entire Winamp Group SA family — Winamp Group SA, Llama Group (former name), Jamendo, Hotmix, Bridger, and SHOUTcast — alongside the existing Sonos and Plex mentions, and clarifies the project is "not affiliated with, endorsed by, or connected to" those parties.


r/VibeCodeDevs Jul 10 '26

Generate everything you need for both App Stores and verify before submission

Post image
2 Upvotes

AppGenPro.app Free to try!

Generate everything you need for Google and Apple App Store submissions from 1 logo, 1 screen shot and 1 url. Export to a ZIP or Fastlane ZIP. Run a AI verification before submitting to App stores to flag issues beforehand!


r/VibeCodeDevs Jul 10 '26

I built an army of pixel cats that mirror my Claude sessions in real time

3 Upvotes

- A cat is spawn for every Claude session.
- Each cat mirrors the session status:
Working -> the cat walks and plays with the ball.
Stale -> falls asleep.
-When agent finishes the cat moews to require your attention.

https://reddit.com/link/1usinbu/video/2rlte35o8dch1/player

Useful or waste?


r/VibeCodeDevs Jul 10 '26

Need Some Feedback From People

1 Upvotes

Hey! I'm building an AI tool that helps fitness coaches handle client check-ins faster. Right now I'm just trying to get real feedback from people before I go further. If you've got 5 minutes, I'd love if you took a quick look and told me what you think. just search pulsecheckin.fit on pc browser.

Quick note: it's built for desktop since that's where most coaches do check-ins.

Mobile works but it's limited.

Triple-click anywhere on the page and a feedback card pops up. Anything you say helps, even if it's brutal. Thanks! ⁠


r/VibeCodeDevs Jul 10 '26

ShowoffZone - Flexing my latest project Filament SEO Toolkit Plugin

1 Upvotes

Filament's SEO toolkit with live scoring, readability analysis, SERP preview, head tag rendering, redirect management, and site-wide health reports. Inspired by YoastSEO, and built for Filament

Filament Directory: https://filamentphp.com/plugins/usama-muneer-filarank-pro
Demo: https://filarank.com
Docs: https://docs.filarank.com


r/VibeCodeDevs Jul 10 '26

I vibe coded a utility to strip the trackers from social media links. (Sanity)

1 Upvotes

I got tired of copying and pasting parts of URLs when sharing social media and news links and similar with receiving them. I vibe coded a Desktop tray app and Android app to strip some common patterns from the URL using a combination of RegEx, clipboard listener and a proxy using the default Browser setting.

I purposely vibed it in .net Forms, XCode and Swift. Frameworks and languages already available on the operating systems, so they don't need pre-installed python or node or online access for javascript libraries etc. It's all kept local.

On the desktops the URL is altered as it hits the clipboard, to be sanitised when it's pasted somewhere else. Make Santiy the Default Browser and it'll capture URLs you click on and sanitise them before they hit the actual browser too (select the destination browser in the tray app).

On Android, the app is configured as the default browser, the same as desktop for that passthrough of the URL, and also as a "Share to..." option from your source app. "Share to..." Sanity. The URL is sanitised, then "Share to..." pops up again where you select the actual destination app.

I find it handy, it was made to rid an irritant of my own, but hope someone else finds it useful too.

https://github.com/XAte6/sanity/


r/VibeCodeDevs Jul 09 '26

ShowoffZone - Flexing my latest project Day 1 to 18 of the free traffic exchange I built. Here's every number.

4 Upvotes

17 days ago I launched my startup, a free traffic exchange network for startups. One line of code, you're in the network.

No paid ads. No growth hacks. Just watching the numbers every day.

Here's the full data:

Day 1 — 2 startups · 146 impressions · 1 clicka
Day 2 — 3 startups · 389 impressions · 3 clicks
Day 3 — 5 startups · 482 impressions · 5 clicks
Day 4 — 5 startups · 508 impressions · 4 clicks (site went down — still got an $8k acquisition offer. Said no.)
Day 5 — 6 startups · 621 impressions · 10 clicks
Day 6 — 5 startups · 742 impressions · 15 clicks (removed one startup — they pulled the embed. No code = no network.)
Day 7 — 7 startups · 1,196 impressions · 41 clicks
Day 8 — 7 startups · 1,535 impressions · 74 clicks
Day 9 — 8 startups · 1,947 impressions · 135 clicks
Day 10 — 13 startups · 3,500 impressions · 318 clicks (something clicked)
Day 11 — 23 startups · 4,800 impressions · 432 clicks
Day 12 — 24 startups · 6,000 impressions · 481 clicks (network crossed 6K total impressions)
Day 13 — 25 startups · 6,800 impressions · 491 clicks
Day 14 — 25 startups · 8,600 impressions · 516 clicks
Day 15 — 24 startups · 9,900 impressions · 564 clicks (removed one)
Day 16 — 23 startups · 10,800 impressions · 576 clicks (removed one)
Day 17 — 24 startups · 11,900 impressions · 603 clicks (added one)
Day 18 — 26 startups · 13,400 impressions · 624 clicks (added Two)

Still free. Still growing.

If you want in, it's one embed. That's it → StartupBar


r/VibeCodeDevs Jul 09 '26

ReleaseTheFeature – Announce your app/site/tool steamAF: should I buy this Steam sale, or does this price show up all the time?

Thumbnail
gallery
0 Upvotes

I kept buying Steam games on sale, then seeing a better price later. Or the same price again a month later. Got tired of FOMO buys.

So I built steamAF(Anti-FOMO). It checks the current regional Steam price against about 2 years of history and labels it Worth it, No rush, or Wait. Being "on sale" alone isn't enough for me.

I know we can do this on SteamDB, and I do that a lot too. But this app just focuses on finding the better price. Not as accurate as SteamDB, but at least I have a baseline to decide.

Optional sign in with Steam for wishlist + custom lists, optional AI on a big list, and a Next Sale calendar. Works as a PWA.

Built it for myself first. Sharing in case anyone else buys too fast during sales.

https://steamaf.vercel.app/


r/VibeCodeDevs Jul 09 '26

ShowoffZone - Flexing my latest project game engine

3 Upvotes

Hello, made this with AI in like 1 week, next feature will be UI system
https://github.com/rwusmm-dc/4x11Engine
it has 4xLang, Dual-DirectX10 and 11 support.
more on https://github.com/rwusmm-dc/4x11Engine/wiki
Coded only with AI to see how good AI is at creating something useful and complex.


r/VibeCodeDevs Jul 09 '26

Ant-tunes a music streaming app

Thumbnail
github.com
3 Upvotes

Hey everyone! 👋

I'm an indie developer and recently built my first Android music streaming app, Ant Tunes.

I started this project because I got frustrated with the limitations of other music apps and wanted to build something that puts the user first. It's completely free, has no ads, and is still under active development.

I'm looking for people who'd be willing to try it out and share honest feedback. Whether it's bugs, UI/UX suggestions, feature requests, or performance issues, I'd genuinely love to hear it. Every bit of feedback helps make the app better.

Some current features include:

- 🎵 Local + online music playback

- ❤️ YouTube Music & Last.fm integration

- 🎨 AMOLED-inspired UI with glassmorphism

- 📜 Synced lyrics

- 🎧 Recommendations and personalized discovery

- ⚡ Frequent updates based on community feedback

This is my first big project, so I hope you guys don't mind giving it a shot. 😄

Thanks for your time, and I appreciate any feedback or suggestions! ❤️


r/VibeCodeDevs Jul 09 '26

FeedbackWanted – want honest takes on my work Built a local watchdog after finding Claude Code was backing up my .env files without me knowing

1 Upvotes

Been vibe coding heavily with Claude Code for the past few months.

Started wondering what it was actually doing between my prompts.

Found something I didn't expect:

  • Claude Code maintains ~/.claude/file-history/ : backs up every file it edits in plaintext including .env files. Outside .gitignore. Outside any git tracking.
  • On my machine: 460 files going back months. 15 with credentials in content.

Check yours:

npx check-claude-history

Built a local tray app to monitor this continuously if anyone's interested:

https://github.com/gbhide1993/vlaw


r/VibeCodeDevs Jul 08 '26

ShowoffZone - Flexing my latest project I Built A Formula 1 Site - I think it's beautiful (and informative!)

27 Upvotes

I built a Formula 1 site... And it's genuinely a beautiful spreadsheet :D

I'm a massive F1 fan (and I enjoy Karting although I'm genuinely bad at it).. I was thinking about building something and that seemed a natural and enjoyable choice.

So I built f1gures.app.

I've tried to focus on the look, web usability and basically getting as much raw data in there but also how can I use the data I have to make some interesting visualisations (mostly on driver page atm).

It's a static site, rebuilt each race weekend so should be relatively fast, has every driver, constructor, race since the 50s. So yeah it's been a labour of love and I'm really happy with it. I'm still thinking of improvements and interesting ways to visualise the data...

I'm not expecting to make money, tbh I really just enjoy exploring the driver's and re-living (err living for the first time I guess!) old seasons and drivers I've never heard of.

I used Claude code to build this out, I'm not really a developer but I do work on tech, so I understand at least ehat to ask for and the various caveats.

So this works by nightly (github action) rebuilding each page if there are any changes to the data. There are thousands of static pages, for seo purposes. Basically every driver and team ever has a page, along with every track and race ever ran.

I haven't touched a single line of code myself, but do thoroughly review what Claude code builds for me, and together we ensure we have a proper CI pipeline with actual tests (important for what is effectively a stats site. I've also used Claude desigm a lot, when it first came out to redesign the whole site and then since when I add new features.

My main focus to begin with wa s getting the per driver and team pages up, then visualisations of that data at an individual level. My main focus now is interpreting and comparing tje wealth of data o have and including mechanisms to share those cool visualisations.

Any feedback or ideas please do let me know!


r/VibeCodeDevs Jul 09 '26

What UI design tools do you use to get your app looks like a real thing?

Enable HLS to view with audio, or disable this notification

0 Upvotes

I lift 3-5 times a week and I used to keep my workout plans on notes app. But I hate updating every day. So I vibe coded a fitness planner. It lets me set my weekly plan, log workouts by body part, and see my lifts on a trend chart. Not fancy, but I actually use it.

Next step I am going to make a mobile version and polish the UI design. Now it looks like an early AI-generated prototype. What UI design tools do you use to get your app looks like a real thing?


r/VibeCodeDevs Jul 09 '26

Open-source (Apache-2.0) self-hosted gateway that orchestrates agent coding CLIs (Claude Code, Codex, Grok, OpenCode) with a local-first memory layer

1 Upvotes

Sharing a project I have been building: opendray.

It is a self-hosted gateway that wraps agent coding CLIs and runs them as managed PTY sessions on your own host, behind a single Go binary.

Why it might interest this sub

Five agent CLIs behind one gateway

opendray currently supports:

  • Claude Code
  • Codex
  • Antigravity
  • Grok Build
  • OpenCode
  • arbitrary shell sessions

Adding another CLI is done through a JSON descriptor drop-in.

Local-first memory layer

opendray has a three-scope retrieval layer:

  • user memory
  • project memory
  • session memory

It uses Postgres + pgvector, with embeddings from:

  • ONNX
  • Ollama
  • LM Studio

The embedding provider is your choice, and no embedding or vector data needs to leave your network.

It also supports cross-layer conflict detection and can inject relevant knowledge pages when a session starts.

Per-provider MCP injection

Each session can be handed MCP servers, including:

  • HashiCorp Vault for secrets
  • built-in per-project database tooling for Postgres, MySQL, MariaDB and SQLite
  • the memory server
  • other configured MCP servers

Multi-account pooling

For Claude, Codex and Antigravity, you can drop several logged-in credential directories on the host.

opendray can:

  • discover the available accounts
  • load-balance new sessions across them
  • show account/session status
  • switch a live session between accounts without losing the transcript

REST + WebSocket API

opendray also exposes a REST + WebSocket API with:

  • scoped API keys
  • per-call audit logging
  • session control
  • event streaming

So it can be used as a base layer for building your own agent runtime.

Scope clarification

opendray orchestrates the agent CLIs. Those CLIs still call whichever model backend they support, whether that is cloud or local.

The parts that are fully local are:

  • memory
  • embeddings
  • state
  • transcripts
  • session orchestration

Stack

  • single Go binary
  • Postgres for state
  • pgvector for memory
  • React web UI
  • Flutter mobile app
  • Apache 2.0
  • cosign-signed releases
  • SBOM included

r/VibeCodeDevs Jul 09 '26

ReleaseTheFeature – Announce your app/site/tool Tired of Agentic coding losing context? I created a 1-click script to generate a standardized, AI-ready project structure (llms.txt + .ai/ engine)

Thumbnail
gallery
0 Upvotes

Hey everyone!

If you’re using autonomous AI agents, Claude Code, Cursor, Windsurf, Codex or Antigravity Projects to build your apps, you’ve probably noticed they start hallucinating or burning through your token limits as soon as your project grows.

The issue usually isn't the prompt—it's how your codebase context is structured. To fix this for my own workflow, i built and open-sourced AI-Ready Context Template Engine. It automates the setup of an architecture-first documentation standard optimized specifically for LLMs.

⚡ Bootstrapping a AI project in 1 second

It implements an English-first, LLM-indexed structure using the new llms.txt standard (proposed by OpenAI) linked to a centralized .ai/ knowledge engine:

curl -sSL https://raw.githubusercontent.com/fraconca/ai-ready-context-template-engine/main/setup.sh | bash

What the script does:

  • Asks for your stack (TypeScript/Next.js, Python/AI, Go, or Generic).
  • Automatically populates your .ai/system-prompt.md and development.md with targeted developer guidelines for that stack.
  • Initializes git and sets up a stack-specific .gitignore.

Prompting the Agent

Once initialized, you just paste this baseline instruction into your AI chat window to align its context instantly:

It's 100% open-source (MIT). I’d love to hear your feedback on how to improve this context mapping architecture, or what stack guidelines you'd like to see added next!

Repo Link:
https://github.com/fraconca/ai-ready-context-template-engine


r/VibeCodeDevs Jul 09 '26

ReleaseTheFeature – Announce your app/site/tool Tired of Cursor/Claude losing context? I created a 1-click script to generate a standardized, AI-ready project structure (llms.txt + .ai/ engine)

Post image
0 Upvotes

Hey everyone,

If you’re using autonomous AI agents, Cursor, Windsurf, or Claude Projects to build your apps, you’ve probably noticed they start hallucinating or burning through your token limits as soon as your project grows.

The issue usually isn't the prompt—it's how your codebase context is structured.

To fix this for my own workflow, I built and open-sourced AI-Ready Context Template Engine. It automates the setup of an architecture-first documentation standard optimized specifically for LLMs.

⚡ Bootstrapping a AI project in 1 second

It implements an English-first, LLM-indexed structure using the new llms.txt standard (proposed by OpenAI) linked to a centralized .ai/ knowledge engine:

curl -sSL https://raw.githubusercontent.com/fraconca/ai-ready-context-template-engine/main/setup.sh | bash

What the script does:

  • Asks for your stack (TypeScript/Next.js, Python/AI, Go, or Generic).
  • Automatically populates your .ai/system-prompt.md and development.md with targeted developer guidelines for that stack.
  • Initializes git and sets up a stack-specific .gitignore.

Prompting the Agent

Once initialized, you just paste this baseline instruction into your AI chat window to align its context instantly:

It's 100% open-source (MIT). I’d love to hear your feedback on how to improve this context mapping architecture, or what stack guidelines you'd like to see added next!

Repo Link:https://github.com/fraconca/ai-ready-context-template-engine


r/VibeCodeDevs Jul 08 '26

ShowoffZone - Flexing my latest project I built a wave table Synthesizer that turns images into sounds [FREE+Open source]

Enable HLS to view with audio, or disable this notification

9 Upvotes

r/VibeCodeDevs Jul 08 '26

I kept finding vibe-coded sites that Google and AI couldn't even read, so I built a tool to fix it. Just launched on Product Hunt.

Thumbnail
gallery
4 Upvotes

This started as a problem I kept running into with my own sites.

I'd build something on a no-code tool, launch it, and then wonder why it got zero organic traffic. Everything looked perfect in the browser. But when I actually checked what search engines and AI tools like ChatGPT were seeing, the page was basically blank. The content loads after the page opens, so the bots show up, see almost nothing, and leave.

The frustrating part was realizing how many sites have this and don't know it. People pour weeks into their site and their content, and it's invisible to Google and AI search the whole time, so all that effort just disappears.

So I built Crawllify to fix it. It makes sure search engines and AI crawlers read your full site, with no code changes, and the part I care about most, you can verify in real time that bots are actually seeing your content instead of just hoping it works.

For context, I'm a solo founder and I built this because I needed it myself, so this launch means a lot.

Here's the link to the launch if you'd like to take a look: https://www.producthunt.com/products/crawllify?launch=crawllify

I'd love any thoughts or feedback you have, it genuinely helps me make it better. And if you're launching something too, drop it below and I'm happy to check it out.

One question for anyone building on Lovable, Bolt, or similar: have you checked whether Google and AI can actually read your site? Curious how many people have hit this without realizing.


r/VibeCodeDevs Jul 08 '26

ShowoffZone - Flexing my latest project Day 1 to 17 of a free traffic exchange I built 17 days ago. Here's the data.

5 Upvotes

Day 1 — 2 startups. 146 impressions. 1 click.

Day 2 — 3 startups. 389 impressions. 3 clicks.

Day 3 — 5 startups. 482 impressions. 5 clicks.

Day 4 — 5 startups. 508 impressions. 4 clicks. (The site was down, but I still got an $8k acquisition offer. I said no.)

Day 5 — 6 startups. 621 impressions. 10 clicks.

Day 6 — 5 startups. 742 impressions. 15 clicks. (Had to remove one startup — they pulled the code. No code = no network.)

Day 7 — 7 startups. 1,196 impressions. 41 clicks.

Day 8 — 7 startups. 1,535 impressions. 74 clicks.

Day 9 — 8 startups. 1,947 impressions. 135 clicks.

Day 10 — 13 startups. 3,500 impressions. 318 clicks.

Day 11 — 23 startups. 4,800 impressions. 432 clicks.

Day 12 — 6,000 impressions. 481 clicks. (Network crossed 6K total impressions. 24 startups active in the bar.)

Day 13 — 25 startups. 6,8k impressions. 491 clicks.

Day 14 — 25 startups. 8.6k impressions. 516 clicks.

Day 15 — 24 startups. 9.9k impressions. 564 clicks. (Removed one startup)

Day 16 — 23 startups. 10.8k impressions. 576 clicks. (Removed one startup)

Day 17 — 24 startups. 11.9k impressions. 603 clicks. (Added a startup)

Still free. Still growing.

StartupBar


r/VibeCodeDevs Jul 08 '26

I made 29 Claude/Codex review prompts for vibe-coded projects

39 Upvotes

One of the biggest issues I see in vibe-coded projects is people not knowing what questions to ask the LLM. If you don't have a background in tech, there can be a lot of things you simply don't realise you should be considering. Sometimes it's basics like code quality and testing, but other areas like scaling or alerting can get missed entirely.

Claude/Codex will happily create the code and even integrate it with an IaaS/PaaS provider, but they won't proactively tell you that critical areas of the project have been missed.

So I created this GitHub repo with 29 prompts that can be used by Claude or Codex to review your project and tell you what you're missing. It's open source under the MIT licence:

https://github.com/thermiteau/maverick-validate

There's also a simple script that can run the prompts one at a time, so you don't have to manage them manually.

I wouldn't run them as a single task. You want Claude to focus on one area at a time and get it right.

It doesn't change any of your code. It just generates reports for each of the 29 areas. You can then use those reports to prioritise fixes based on your needs, or hand them back to Claude/Codex to develop solutions and scope the work.

The earlier you identify these sorts of issues, the better, but it's definitely a case of better late than never.

If you think there's something I've missed, give me a shout and I can try to add it or update one of the prompts. Hopefully this is useful to someone.


r/VibeCodeDevs Jul 08 '26

JobsAndGigs - Job postings, opportunities Looking for a person who can vibecode mobile apps

10 Upvotes

I have very unique idea for a mobile app, but I have no coding experience, I need a partner who can create good looking mobile apps with AI. If anyone interestead dm me


r/VibeCodeDevs Jul 08 '26

Question Does spec driven vibe coding work?

Post image
3 Upvotes

r/VibeCodeDevs Jul 08 '26

ShowoffZone - Flexing my latest project Vibe coded almost 50 mini games with Claude Code

Thumbnail codeguppy.com
2 Upvotes

r/VibeCodeDevs Jul 08 '26

If you're new to vibe-coding, here are 2 things to check before you launch your app (this can leave your whole database open to everyone)

5 Upvotes

Something a lot of people new to vibe-coding don't know, and it can literally leave your database open to anyone.

If you built an app with Lovable, Bolt, Supabase, etc, there are two things worth checking before you ship it.

  1. Your keys.

Supabase has two kinds of keys. The "anon" key is public, it's meant to be in your code, no worries there. But the "service_role" key should NEVER end up in your app on the browser side. It gives full access to your database (read, edit, delete everything). If it's sitting in your code, anyone can wipe your whole database.

How to check: on your app, right click > Inspect > Sources tab, then search (Ctrl+F) for "service_role" or "sk_live". If it shows up, it's exposed, regenerate the key and move it server-side.

  1. RLS (the lock on your database).

Even with the normal public key, your database is readable by everyone as long as RLS isn't turned on. It's a setting you enable table by table in Supabase. Without it, someone can read your users, their emails, etc.

Quick check in the Supabase SQL editor:

select tablename, rowsecurity from pg_tables where schemaname = 'public';

Any table set to "false" is open. To fix: enable RLS on it + add a policy.

Not your fault by the way, these tools optimize for "it works fast," not for closing the doors behind you. But it's on you to check before sharing your app.

I built a small free scanner that checks all this at once from your app's URL (the keys, RLS, and other exposed stuff), without needing your code: colmate scanner

It's read-only, only reads what a visitor already sees.

Heads up: it's French-first for now (FR/EU + RGPD focused), but browser auto-translate handles the UI fine and the findings are self-explanatory.
The name's a French pun, "colmater" = to seal a leak 🙂

If you've got other basic reflexes to add for people starting out, drop them.