@itsthatlady.dev: There's a Wall of Shame for vibe-coded apps and it just went viral on Hacker News. Exposed user data. Passwords stored in plain text. URL bar account takeovers. The scary part? Every single one of those devs thought their app was secure. The Coding Agent said it was fine. So they shipped. Here's how you make sure that's never you: 🔍 Search your entire codebase for any API key or secret that isn't in an environment variable. 🔓 Try to access every page and endpoint without being logged in. ⚡ Drop a single quote into every input field and watch what happens. That's it. That catches 90% of what's on that list. Don't be on it. #vibecoding #ai #saas
Unless you used ChatGPT 4.1 coz Claude won’t allow this mistake 😂😂
2026-04-25 16:42:57
39
♦️♠️ إلياس ♣️🎴 :
Laterally this is basic stuff
2026-04-25 00:38:15
30
Axtiran Group :
The mechanism behind nearly all of these is identical: the client talks to the database directly using a public key, and row-level security was never switched on. So the key sitting in every user's bundle can read every row. Quick self-check - open your own app, watch the network tab, and see whether requests go to your API or straight to the database host.
2026-09-05 18:18:31
0
Brynn :
Great tips! I feel like it's always worth it to spend some tokens on Fable or a frontier model to do a final high effort code check before launching
2026-08-08 02:16:02
0
Contessa Gardner :
Great info. Thanks.
2026-08-23 21:18:55
0
lmaooooooooooooooooooooooooooo :
There’s no way Claude or Codex would allow this tho. What kind of LLMs are they using 😭😭
2026-04-27 04:23:17
9
OBI :
we check ai with ai?
2026-05-01 10:21:59
0
Noel :
I am probably on it 😔
2026-04-27 20:43:08
4
lefthandedq :
More saves than comments
2026-05-31 20:34:27
1
Sulayman Loop :
I always pentest after production and patch every loophole that comes up. I have found Kimi and Claude to be good at pentesting and patching.
2026-04-25 00:20:11
8
Lodestar :
Thank you
2026-04-24 16:56:17
0
The Kraft :
are these tools free thou?
2026-06-08 17:57:04
0
Godwin Nkanta | Web Developer :
Omg thank you so much for this, I literally want to ship an app rn 😅
2026-04-24 19:57:29
0
GM :
you are gold. thank you🥰
2026-04-25 10:20:13
0
Silent Noisemaker :
Do you train people?
2026-04-25 03:22:30
1
Delmond :
I just launched a product I built the other day and 2 days later, I thought of this and tried out accessing the subscription features without actually paying the fee and I was shocked it took me straight to pro features 😊
2026-04-24 19:05:56
5
MBULO :
Try mine. I'm a vibe coder but security wise, am equal to a professional.
2026-05-08 20:12:02
0
Orakzay81 :
scanvibe.vercel.app helps me somehow find bugs in vibe code and then fix it.
2026-04-25 00:23:19
0
happyalpaca1.0 :
Easy: Learn to use your brain instead of fully trusting AI. I did the same. Built an app, used AI to learn what I didn't know. No leaks, no vulnerability, I know the system inside out.
2026-06-13 22:48:47
0
CollinBeatz_dev🇿🇦 :
Anthropic, the company behind Claude, has generally maintained a reputation for being "safety-first," but they have not been entirely immune to incidents involving data security and external exploitation. Look up: The September 2025 Anthropic Incident or most recently, Claude "Mythos" Control-Flow Hijack which occurred in April.
2026-05-10 16:34:17
0
bibbles2 :
"We don't need developers anymore"... Why is your app exposing my password to the internet?
2026-04-26 13:04:46
0
YanaOnChain :
SE basics...I love it...glad someone is sharing this info
2026-04-25 20:28:34
0
moyocornil265 :
You need to know what you're doing even when vibe coding. Otherwise we'll see thousands of vulnerabilities in different apps everyday.
2026-06-02 20:34:52
0
Lil Elles🫀💜📉📈 :
Common, what happened to authentication, are these prople okay at all
2026-04-25 10:55:49
0
Gideon Valor | Behavioralist :
just shipping shit
2026-07-12 21:49:37
0
To see more videos from user @itsthatlady.dev, please go to the Tikwm
homepage.