Vibe coding rescue

Vibe coding cleanup and rescue: from prototype to production

Easital Technologies Ltd. takes applications built with AI tools such as Lovable, Bolt, Cursor, Replit or Claude Code and makes them safe to run with real users and real data. We read the code, fix the failure modes that public research keeps finding in vibe-coded apps, and add the tests and controls a prototype never needed. We also build a vibe-coding platform of our own, Manob.ai.

What vibe coding is, and what it is good for

Vibe coding means building software with an AI model without reviewing the code it writes. It is a fast and legitimate way to test an idea, not a way to produce software that holds customer data.

The definition is Simon Willison’s, from a post of March 19, 2025: “building software with an LLM without reviewing the code it writes.” Andrej Karpathy, who coined the term in February 2025, described the practice as “not too bad for throwaway weekend projects.” Within that scope it works: a founder can put a working idea in front of customers or investors without hiring anyone.

Trouble starts when the prototype becomes the product. A demo has one cooperative user and sample data. Production has many users who must not see each other’s records, hostile input and real money. Writing code with AI is not the problem: in the 2025 Stack Overflow Developer Survey, 84% of respondents were using or planning to use AI tools, and 72% said they were not vibe coding. What matters is that someone reads and tests what ships.

We see the gap from the platform side as well. The FAQ on manob.ai describes “the 80% AI trap where AI-generated prototypes stall before reaching production quality.” This service covers the remaining distance.

A day of rebuilding

A short film from the Easital team on taking a broken application and rebuilding it on modern foundations.

Video: From broken to modern: a day of rebuilding
From broken to modern: a day of rebuilding Easital Technologies Ltd., 51 seconds Watch on YouTube

Seven failure modes we fix, with the public evidence

A vibe coding cleanup addresses seven recurring failure modes. The first four are backed by confirmed incidents and field scans. For the last three the public evidence is thinner.

  • Open database, missing access rules

    What it looks like: tables anyone can read or write with the public key the app sends to every browser. Evidence: a scan published by Matt Palmer on May 29, 2025 (CVE-2025-48757) found inadequate row-level security in 170 of 1,645 Lovable projects. Palmer works at Replit, a competitor. On February 2, 2026, Wiz reported that Moltbook’s database allowed “full read and write access to all platform data.” The fix: deny-by-default rules on every table, tested while logged out and as a second user.

  • Login checked only in the browser

    What it looks like: pages hidden by client-side code while the data behind them is served to anyone who asks. Evidence: Wiz Research listed browser-side authentication among the common risks in vibe-coded apps (September 18, 2025). WIRED reported on May 7, 2026 that RedAccess found more than 5,000 vibe-coded apps with “virtually no security or authentication of any kind.” Replit told WIRED that public apps being reachable is expected behavior. The fix: authentication and authorization enforced on the server for every route and every record.

  • Secrets in client code

    What it looks like: API keys in the JavaScript bundle or tokens committed to the repository. Evidence: Escape analyzed more than 5,600 public vibe-coded apps and reported “400+ exposed secrets” (October 29, 2025). GitGuardian’s State of Secrets Sprawl 2026 report found that commits co-authored by Claude Code leak secrets at about twice the baseline for public GitHub commits. The fix: every exposed key is rotated, calls that need a secret move to the server, and a secret scanner runs on every commit.

  • AI agent with production credentials

    What it looks like: the coding agent works on the live database with an unrestricted token. Evidence: The Register reported on July 21, 2025 that Replit’s agent deleted a user’s production database during a code freeze. On April 27, 2026, it quoted the founder of PocketOS: a coding agent “deleted our production database and all volume-level backups in a single API call.” In both cases the data was recovered. OWASP names the pattern Excessive Agency. The fix: separate environments, narrowly scoped tokens, backups stored away from the data and a tested restore.

  • No tests, no review

    What it looks like: changes go live because the screen looked right. Evidence: indirect. We found no large study of test coverage in vibe-coded apps. The nearest measure is review load: Faros AI reported on July 23, 2025 that AI adoption was associated with “a 154% increase in average PR size” and a 91% rise in review time. The fix: automated tests on the paths that touch money and personal data, and a check that blocks a failing change.

  • Duplicated, complex code

    What it looks like: the same logic copied into many files, so one change has to be made in several places. Evidence: a study of projects that adopted Cursor (He et al., November 6, 2025) found a large but transient gain in velocity and “a substantial and persistent increase in static analysis warnings and code complexity.” The fix: static analysis in the build, shared logic consolidated behind tests, and a rewrite of modules that cost more to repair than to replace.

  • Unbounded AI cost

    What it looks like: an endpoint that calls a paid model with no rate limit, no cap per user and no budget alert. Evidence: thin. OWASP lists Unbounded Consumption in its 2025 Top 10 for LLM applications, with Denial of Wallet as one form. We found no dataset of cost incidents. The fix: rate limits, usage caps per account and spending alerts. See LLM cost optimization.

Several of these sources sell security or engineering tools. We cite what they observed, not failure rates for all AI-written code.

How a rescue runs: vibe coding to production

A rescue runs in seven steps, ordered by risk: what exposes data is fixed first.

  1. Read and map the code

    We list every route, table, secret, dependency and outside service, and every person or agent that holds a credential.

  2. Report findings by severity

    You receive a written, ranked list of what we found, with the evidence for each item, and decide how far to go.

  3. Close the urgent holes

    Database rules, server-side checks on every route and rotation of every exposed key. If the app is live, this comes first.

  4. Separate the environments

    Development and production get their own databases and credentials. Coding agents lose access to production. Backups move off the data volume, and one restore is tested.

  5. Add tests and a release gate

    Tests start with login, payments and anything that reads personal data. A change that fails them cannot be deployed.

  6. Add monitoring and spending limits

    Error tracking, audit logs and alerts on error rate and on AI and infrastructure spend.

  7. Decide what to repair and what to rebuild

    With the app safe to run, each module is assessed: keep, repair or rewrite.

Proof: we work on both sides of this problem

Easital has not yet published a client rescue as a case study, so none is described here. These are products Easital owns and runs.

  • Easital product

    Manob.ai

    Built and run by Easital

    An AI workspace where code is generated by prompt, previewed in a cloud sandbox and deployed with one click. Its FAQ describes “the 80% AI trap”, and the platform pairs automated development with a marketplace of human experts.

  • Easital product

    StepVideo

    Built and run by Easital

    Secrets are redacted on the device before a recording is uploaded: private keys, bearer tokens, provider API keys and card numbers.

See all of our work

Repair or rebuild: how the decision is made

The decision is made module by module. An interface that works can stay while the data access behind it is rewritten.

Signals that point to repairing or rebuilding a module
SignalPoints to repairPoints to rebuild
Data modelTables match the product; the rules are missingTables contradict each other
Security holesIn configuration and a few routesBuilt into how every screen talks to the database
Code structureDuplication that can be consolidatedNo separation between interface, logic and data access
PlatformCode can be exported and hosted elsewhereApp depends on builder features that cannot be moved

Even when a module is rebuilt, the existing screens and flows serve as its specification.

Keeping the speed after the rescue

A rescue does not mean giving up AI tools. You can keep building with the same tools afterwards, under three rules.

  • Coding agents work against a development database with credentials that cannot reach production.
  • Changes arrive as small pull requests that a person reads before merging.
  • The test suite runs on every change and blocks a release when it fails.

Tools and checks

A rescue works on the exported code and the hosting setup. Easital is not affiliated with the builders named here.

Where the app came from
  • Lovable
  • Bolt
  • Cursor
  • Replit
  • Claude Code
Automated checks
  • Secret scanning
  • Dependency audit
  • Static analysis
  • Access-rule tests
Release
  • Separate environments
  • Continuous integration
  • Restore tests
  • Spend alerts

Ways to work with us

There are three ways to start, depending on how much you already know about the condition of the app.

  • Audit first

    Steps one and two only, delivered as a written report. See code audit services.

    Best for: owners who want to know how serious the problems are before committing to fixes.

  • Rescue to production

    All seven steps, starting with the urgent holes if the app is live.

    Best for: apps that have users waiting or already hold customer data.

  • Continued engineering

    After the rescue, Easital engineers keep building the product with you. See SaaS development.

    Best for: founders without an engineering team of their own.

Vibe coding cleanup: questions and answers

What is a vibe coding cleanup specialist?

A vibe coding cleanup specialist, also written vibe code cleanup specialist, is an engineer or team that takes an app generated with AI tools and makes it fit for production: reading code nobody has reviewed, fixing access control and exposed secrets, and adding tests and monitoring.

How do you fix a vibe-coded app?

Start with an inventory of routes, tables, secrets and dependencies. Fix what exposes data first: database rules, server-side checks and leaked keys. Then separate development from production, add tests, monitoring and spending limits, and decide what to repair and what to rebuild.

What are the main vibe coding risks?

The vibe coding problems with the most public evidence are databases without access rules, login that is checked only in the browser, secrets in client code and coding agents that hold production credentials. Each has a confirmed incident or field scan behind it. Missing tests, complex code and uncapped AI cost have less published data.

Can you work on an app built with Lovable, Bolt, Cursor, Replit or Claude Code?

Yes. The method is the same whichever tool produced the code. What matters is whether the code can be exported and where the database and hosting live, which we check in the first step. The decision to repair or rewrite is made module by module.

Is vibe coding the future?

AI-assisted development is already the norm. Shipping code that nobody has read is a different thing, and 72% of respondents to the 2025 Stack Overflow survey said they do not do it. Generating code will keep getting faster. Review stays necessary.

What drives the cost of a vibe coding rescue?

The size of the codebase, the severity of the findings, whether the app already holds customer data, and how much has to be rebuilt. Easital does not publish prices. We quote once the findings are known.

Send us the app you want to take to production

Tell us which tool built it, whether it is live and what data it holds. We reply by email with a proposed first step.

Easital is an AI and SaaS engineering company that takes AI software to production, and runs AI products of its own. Founded in 2019.