Skip to content

Vibe-coded apps present security risks but solutions exist

Recent discoveries have raised urgent security alarms within the vibe coding landscape, as thousands of applications built with these easy-to-use, AI-supported development platforms have been found to harbor significant risks. Despite the advantage of their intuitive, code-free approach, experts are sounding the alarm over insufficient protections—especially as these tools rapidly adopt more sophisticated AI coding functions.

These challenges were explored during an interview with Shiran Brodie, Head of Growth at Softr, who explained both the underlying dangers and the new methods available to improve security when building with vibe coding. Softr’s shift from a traditional no-code business platform to one embracing vibe coding has been accompanied by a renewed focus on building robust security into its foundation.

Critical weaknesses expose thousands of applications

Careful examination has uncovered extensive vulnerabilities in vibe-coded applications. In 2025, Escape DAST’s research revealed that of 5,600 apps analyzed on various AI code generation platforms—including Loveable, Replit, Base44, and Bolt—over 2,000 had critical security flaws. Among these, researchers catalogued 2,038 high-risk vulnerabilities in addition to 400+ leaked credentials. Brodie attributes this to the streamlined workflow that vibe coding platforms offer, commenting that while simplicity is their selling point, it can also introduce security blind spots by over-abstracting complex safeguards from inexperienced users.

Concerns are further validated by additional independent studies. The Vibe Security Radar from Georgia Tech, which went online in 2025, aggregates vulnerability data from over 40,000 security advisories related to AI-generated code. The platform identified 43 severe vulnerabilities impacting eight different vibe coding ecosystems, including incidents such as command injection and authentication bypass. Even in late 2026, major API credential leaks were traced back to insecure, AI-produced code on popular services like Meta’s Moltbook and the Hugging Face community, underscoring enduring risks tied to the exposure of sensitive data through weak platform safeguards.

Hybrid models blend AI innovation with core safeguards

To address these issues, a new hybrid methodology is emerging. Rather than allow unrestricted AI to write code across entire applications, Softr has moved to a partially pre-built infrastructure model—managing key functions like storage, hosting, and integration inside a controlled environment, while reserving AI vibe coding for customizable automation and front-end tasks. Brodie explains that “component blocks” restrict where AI-generated logic can operate, containing any potential risks within a preset security perimeter. This setup—referred to as visual scaffolding—allows users to benefit from the flexibility of AI tools without undermining the fundamental protections of the underlying platform.

This architectural shift is mirrored elsewhere. Framer’s Workshop extension features AI-driven development automation under strict controls, while platforms such as FlutterFlow blend AI-powered functions with stringent protective barriers. Brodie underscores that this approach ensures that AI-generated features “only exist within specific, secure modules inside our system.”

Shadow AI: Hidden risks of unsanctioned deployments

“Shadow AI” has started to replicate the well-known challenge of shadow IT—causing significant difficulties for organizations. Employees can independently use coding tools such as Claude Code or Gemini on personal accounts, sometimes building apps that draw data directly from company records without official oversight. A 2026 study from RedAccess tracked more than 380,000 vibe-coded applications in public circulation; over 5,000 were unprotected, with 2,000 confirmed as leaking sensitive customer financial and health information.

Brodie notes that encouraging compliance with company security protocols is essential, describing how a lack of effective monitoring and access controls leaves organizations exposed—both to inferior code and to unauthorized data access. She urges the adoption of enhanced admin capabilities and stricter control systems to help address these risks effectively.

Model Context Protocol: Connecting AI with caution

The Model Context Protocol (MCP), introduced by Anthropic as an open and standardized way for AIs to interact with external infrastructure, is rapidly being adopted. Nevertheless, MCP implementations often inherit wide-reaching permissions from their source databases—potentially giving AI agents dangerous scope over sensitive assets. In response, Softr employs a proprietary database management solution to constrain MCP data access, but Brodie cautions that such nuanced controls are absent from most platforms. Without them, prompt injection and uncontrolled data access become real possibilities.

To further support secure automation, Softr operates with more than 60 vetted third-party integrations and connects with workflow services such as Zapier and Make, reinforcing adherence to security best practices across all automations.

Security priorities: Small business and enterprise demand

Whereas smaller companies may be satisfied with essentials like encrypted storage and basic permission layers, large enterprises demand comprehensive measures: GDPR and SOC II compliance, advanced authentication, and regional data controls. Both Softr and Retool—which carries SOC II Type 1 certification—offer granular role permissions and enforce separation between AI coding and sensitive workflows. Likewise, WaveMaker provides features such as centralized permissions, LDAP, and SSO support for their enterprise users.

Brodie’s assessment is clear: whether for small businesses or large corporations, all need to rely on the inherent security mechanisms of AI coding platforms to innovate responsibly. With a continual stream of high-profile data breaches, it is now imperative for vibe coding providers to establish trusted security frameworks—making protection a universal industry expectation.