Vibe coding might be extremely popular, but it comes with some serious security concerns, including exposed databases, leaked APIs, remotely orchestrated prompt injection attacks, and AI scraping. It's enough to raise the question: Is there a version of vibe coding that could actually hold up in a live environment? I spoke with Shiran Brodie, Head of Growth at Softr, for a face-to-face discussion on the challenges and solutions to vibe coding security hassles. Softr began as a no-code app builder designed specifically for professionals, small businesses, and enterprises to build apps or portals to support their internal workflows. That means handling a ton of proprietary data, where security is always a big concern. The original version has gone through several updates since launch, with vibe coding now one of the platform's core features. Brodie spoke about the challenges that the company faced expanding into this new space and the solutions that helped get through them. We also talked about how app development platforms like Softr now suggest a hybrid approach that layers vibe coding features on top of pre-built security infrastructure like built-in database management, access control, and developer visibility. But how does this hybrid security system work on a technical level? And more importantly, does it actually hold up in practice?
Vibe-Coded Apps Are a Security Nightmare, but They Don't Have to Be
Vibe-coded apps are susceptible to command injection, request forgery, API leaks, and worse. Taking a hybrid security approach with AI-generated code might be the best path forward.







