Softr began as a no-code app builder designed specifically for professionals, small businesses, and enterprises to build apps or portals to support their internal workflows. That means handling a ton of proprietary data, where security is always a big concern. The original version has gone through several updates since launch, with vibe coding now one of the platform's core features.
In 2025, a security firm called Escape DAST analyzed 5,600 vibe-coded apps built using platforms like Loveable, Replit, Base44, and Bolt. More than 2,000 of these apps had security issues, totaling 2,038 critical vulnerabilities and over 400 exposed credentials.
Also in 2025, Georgia Tech researchers launched the Vibe Security Radar, a platform that pulls information directly from publicly accessible security advisories and traces them back to AI-generated coding platforms and LLMs. Researchers scanned more than 40,000 security advisories, and uncovered 43 critical vulnerabilities across eight vibe coding platforms that led to command injections, server-side request forgery, and authentication bypass. Even in the last few months of 2026, security analysts have discovered massive API leaks from Meta-owned Moltbook and the Hugging Face community. Most of these incidents stem from poorly generated code that didn’t take enough steps to secure private API keys from the open web.
Contain the AI instead of letting it run free
Instead of letting AI models generate every new app from scratch, Softr retains the same pre-coded backend infrastructure, hosting, integrations, and permission management. Vibe coding features add more design flexibility and smarter workflow automation, but the core systems remain the same.
In development terms, this is called visual scaffolding. Apart from Softr, several other no-code platforms have carried forward this same model, with varying levels of success. Framer, for instance, offers an AI-enabled Workshop extension in its app marketplace. The feature has expanded into Framer’s built-in prompt-based development tool and AI agents that can handle ongoing maintenance tasks. FlutterFlow, a no-code tool designed specifically for building smartphone apps for iOS and Android, also lets you generate pages and components with established security guardrails using AI.
Shadow AI is the AI-era version of a long-standing problem called "shadow IT." When employees put company data in a software platform without IT approval, it opens businesses to data governance and cybersecurity risks. The same goes for AI, except now, it’s no longer limited to a rogue Trello board, but an employee’s personal account running Claude Code or Gemini with full access to proprietary company databases. AI coding platforms offer generous limits even on personal accounts, making it convenient for employees to go off on their own and start building apps on company data without a centralized approval system.
Earlier this year, RedAccess scanned more than 380,000 vibe-coded applications built using platforms like Lovable, Replit, or Base44. They found over 5,000 of these apps publicly accessible on the open web and 2,000 of them actively leaking company data, including customers’ sensitive financial and medical information.
MCPs make things more complicated
Model Context Protocol—or MCP for short—is Anthropic’s open-source standard for securely connecting AI models to external applications and data sources. It’s quickly become an industry staple, more so because of convenience and the fact that it’s free to use. But the problem with MCP connectors is that they inherit the same permission structure as the database or application it’s connected to.
Vibe coding tools often get blanket access to your raw databases without a permission layer in between, making breaches more likely when attackers use prompt injection attacks. Data is further exposed for companies that need to give third-party vendors and clients access to their vibe-coded applications, where controlling access to company data is a minimum security requirement.
Making security accessible to SMBs, but also enterprises
There’s a marked difference in the security requirements of a small business or early-stage startup versus a large-scale enterprise operation spanning multiple locations. Small business startups are usually content with basic permission management and data encryption standards, whereas enterprise organizations need GDPR and SOC II compliance, control over data center locations, and stronger access control with multi-factor authentication and single sign-on facilities.
"No organization wants to hire or train more developers just to keep one internal tool secure," Brodie said. Larger companies expect these things to be handled by an AI coding platform’s native security systems. With multiple major public security incidents rattling the AI coding space, no-code platforms are looking for options to offer users more flexibility, without being plagued by the complexity that made them turn to vibe coding in the first place.
Hence then, the article about vibe coded apps are a security nightmare but they don t have to be was published today ( ) and is available on Live Hacker ( Middle East ) The editorial team at PressBee has edited and verified it, and it may have been modified, fully republished, or quoted. You can read and follow the updates of this news or article from its original source.
Read More Details
Finally We wish PressBee provided you with enough information of ( Vibe-Coded Apps Are a Security Nightmare, but They Don't Have to Be )
Also on site :
- Martha Stewart’s ‘Adorable’ Lemon Curtain Set Is Just $15 and Gives Kitchens a 'Cheerful' Pop of Color
- Walmart's $17 Raffia Knot Slides Are 'Incredibly Versatile and Comfortable' to Wear from Day to Night
- Iran-US war latest: Trump claims total control of Hormuz as he demands Iran pay for US soldiers’ deaths