@checkvibe.dev: We ran CheckVibe across 100 real apps built with Claude Code, Cursor, Lovable, and Bolt. The results are worse than you think. 83% had API keys exposed in the frontend. 67% had at least one Supabase table with RLS turned off, meaning anyone with the public anon key could read, edit, or delete every row. 41% were leaking user emails through unprotected endpoints. 29% had admin routes reachable without any auth check. And 100%, every single app we scanned, had at least one High severity finding. If you vibe-coded your SaaS and haven’t scanned it, you’re in this 100%. Not a maybe. The only question is which of the 37 issues your app has. Scan yours free in 2 minutes at checkvibe.dev. #vibecoding #cursor #claudecode #lovable #indiehacker
CheckVibe
Region: CH
Saturday 18 April 2026 07:57:07 GMT
Music
Download
Comments
6foot4bp :
And 100% not true statistics
2026-04-20 11:01:18
12
Examripper :
is there a list of these vibe coded websites? because what if it’s just like 100 sites that were just abandoned that people dont use and aren’t actively maintained
2026-04-21 06:19:56
2
yves :
67
2026-04-18 08:52:43
7
🇱🇹 therealbudanov 🇺🇦 :
I tried out your tool on my website, first free vulnerability came in that hackers can brute force passwords because there is no rate limiting, the thing is we don't even have a system set for logging in with username and password, we only have Google auth, which makes me wonder how real is this tool
2026-04-20 21:16:40
1
Ueaodo13 :
It’s just of matter of time, lovable already included safety features. In 6 months, it won’t happen anymore
2026-04-20 11:31:34
1
To see more videos from user @checkvibe.dev, please go to the Tikwm
homepage.