Is that vibe coded app safe? 5 checks before you download

Imported from official source

Cybersecurity Classified by Officially

AI platforms are transforming many industries. But perhaps none more so than software development. “Vibe coding” was only coined as a term in February 2025. Yet just a few months later, one report suggested 84% of developers were using or planning to use AI tools for work.

On paper, it’s obvious why they are doing so. AI does the heavy lifting, allowing the developer to let their creativity flourish. But in so doing, vibe coding tools also lower the barriers to entry for novices unable to spot bugs and mistakes. For some time-poor developers, the technology may also provide a false sense of security. These oversights aren’t necessarily going to be flagged by the platforms on which the software is distributed.

All of which puts the onus on users to vet their apps more carefully than perhaps they did in the past. But what are the risks to look out for, and what are the right questions to ask?

Vibe coding tools are designed to prioritize functionality, and look and feel, over quality. That can lead to some concerning oversights creeping in. These might include:

  • Hardcoded secrets such as API keys left in the app’s code, which malicious actors can extract, sometimes automatically. It could let them into the developer’s backend and the user data stored there, including yours.
  • No input validation or access controls, which could expose an app to accepting malicious input (data), or enabling users to access or change data belonging to other users.
  • Public-by-default settings which could allow users to view the profiles or private information of other users of an app.
  • Weak or missing encryption, which makes data stolen from an app, or intercepted on its way to and from it, easier to read and exploit.
  • No rate limiting, which means hackers could carry out “brute-force” attacks, using automated software to guess your password a huge number of times.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-questions-ask-first/

    Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    ESET — imported from official source
    Official source
    https://www.welivesecurity.com/en/rss/feed/ RSS
    Imported
    September 26, 2026 10:00
    Versions
    1 recorded
    Identity
    https://www.welivesecurity.com/en/mobile-security/is-new-vibe-coded-app-safe-5-question...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.