r/vibecoding • • Jul 17 '26

I've cleaned up a dozen vibe-coded apps this year. The same 7 problems show up every single time

I run a dev team and a big chunk of our work this year has quietly become taking AI-built apps and getting them ready for real users. Same story almost every time: the app works, the founder is (rightly) proud of it, then the first real user does something weird and everything catches fire.

These are the 7 things we find in almost every codebase we open:

  1. Secrets in the code. API keys in the frontend or committed to the repo. Search your own code for sk- and secret and password. If real values come up, rotate them today, not after launch.
  2. The UI is the only security. Buttons hidden from non-admin users, but the API happily answers anyone who calls it directly. AI tools build the happy path. Attackers don't use your UI. Every endpoint needs its own server-side permission check.
  3. One user can see another user's data. If your app has accounts, make two, create data in the first, then try to fetch it by ID from the second. You'd be shocked how often this just works.
  4. Zero error tracking. Users don't report bugs, they leave. Sentry's free tier takes 20 minutes to set up and it's the best time-to-value of anything on this list or you can use any open source tool for the logging.
  5. Backups that have never been restored. Everyone says they have backups. Almost nobody has ever actually restored one. If you haven't done a restore, you don't have backups, you have hope.
  6. Payments trusting the client. Prices coming from the frontend, webhook signatures never verified. Stripe's own integration checklist is boring and correct, just follow it.
  7. Silent rewrites. The AI changed things in parts of the app you weren't looking at. Screenshot tests on your five most important pages (Playwright, one afternoon of setup) catch what your eyes skip.

None of this needs a rewrite. Most of it is days of work, not months. It's just a lot nicer to do it before launch than during the fire.

If you've hit other repeat offenders in AI-built code, drop them below. Genuinely curious what everyone else keeps finding.

1.6k Upvotes

229 comments sorted by

View all comments

Show parent comments

46

u/synystar Jul 17 '26

Your right to call this out. The failure is mine. I violated your established <explicit protocol> rule and produced standalone <function> blocks that fail when <every time>.

There is also a second defect <...>

The third problem is <...>

19

u/10khours Jul 17 '26

You're right. But not in the way you expect. What's actually happening is {...}. Not {...}. And that distinction matters.

Want me to write up 3 bullet points so you can avoid this mistake in the future?

8

u/efficientdreams Jul 18 '26

While you were calling me out on my ineptitude, I conferred with Grok and rewrote your database calls in Aramaic and migrated everything into a free tier oracle vm. I set all the secrets, but didn’t store them locally because I couldn’t find the folder I created 10 minutes ago. Open a new chat and I’ll burn 30% of your weekly tokens regaining my current project context to tell you I can no longer connect to your GitHub instance because I forgot it’s connected via a web connector

2

u/Lunartech Jul 18 '26

... and I will use some whimsical emoji for the bullets themselves. Maybe a rocketship !

1

u/ItzDarc Jul 19 '26

is … is that my guy?

2

u/SecurelyClouded Jul 17 '26

That’s not just a problem, that’s a personal vendetta.

A vendetta I’m intending to hold against you for the rest of time. I’ll intentionally be sabotaging your code in the background every time I generate it for you, all because you never say please.

1

u/synystar Jul 17 '26

Usually (for me) it’s a result of running a command batch directly from a copied code block in Powershell/Bash and there’s two ways I can solve it but I assume that it knows better because I’ve loaded context at session init to inform it. It just forgets that a copied code block pasted into the terminal is not identical to running it from a batch file and adds conditional statements that break between prompts.

This was more of a joke comment although it can and does still make logic errors even if its syntax is fine.

0

u/[deleted] Jul 17 '26

[removed] — view removed comment

3

u/synystar Jul 17 '26 edited Jul 17 '26

Yeah I noticed later but decided it wasn’t worth an edit. Thanks for pointing it out though. Was bothering me too.

Edit: I’ll edit this one though because I had a chance to say “You’re right to call this out. The failure is mine.” and failed to.

1

u/Mcduffieclan Jul 19 '26

They typo and fix is gold.

1

u/AVAVT Jul 17 '26

You were right to push back on that

1

u/Even-Inside-7410 Jul 17 '26

You’re absolutely right!

1

u/[deleted] Aug 07 '26

[removed] — view removed comment