<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: ZANISS SOFTWARES</title>
    <description>The latest articles on DEV Community by ZANISS SOFTWARES (@zanisssoftwares).</description>
    <link>https://dev.to/zanisssoftwares</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3969799%2F601ef5d7-1b9a-4e65-96bc-c2c8d836b7d3.png</url>
      <title>DEV Community: ZANISS SOFTWARES</title>
      <link>https://dev.to/zanisssoftwares</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zanisssoftwares"/>
    <language>en</language>
    <item>
      <title>I Reviewed a Dozen "Vibe-Coded" Apps This Year. Here's What Actually Breaks.</title>
      <dc:creator>ZANISS SOFTWARES</dc:creator>
      <pubDate>Mon, 28 Sep 2026 05:26:05 +0000</pubDate>
      <link>https://dev.to/zanisssoftwares/i-reviewed-a-dozen-vibe-coded-apps-this-year-heres-what-actually-breaks-220</link>
      <guid>https://dev.to/zanisssoftwares/i-reviewed-a-dozen-vibe-coded-apps-this-year-heres-what-actually-breaks-220</guid>
      <description>&lt;p&gt;Every developer has a version of this story now: a founder or PM hands you an app built entirely in Lovable, Bolt, or Replit Agent and asks you to "just clean it up before launch." Having done this a dozen-plus times in the last year, the failure patterns are remarkably consistent, and they're worth naming so you can check for them before you agree to a scope.&lt;/p&gt;

&lt;p&gt;The most common issue by far is API keys and secrets sitting in client-side code — not because the model doesn't know better, but because the fastest path to "it works" is often to skip environment variable setup entirely. Second is authorization logic that checks &lt;em&gt;authentication&lt;/em&gt; (are you logged in) but not &lt;em&gt;authorization&lt;/em&gt; (should you specifically have access to this record), which shows up as classic IDOR vulnerabilities the moment you change an ID in a URL. Third is database rules — Postgres row-level security, Firebase rules, Supabase policies — left wide open because the default during rapid prototyping is permissive access.&lt;/p&gt;

&lt;p&gt;The data backs up the anecdotes: independent testing has found that around 45% of AI-generated code fails basic OWASP Top-10 checks, and cross-site scripting shows up roughly 2.74x more often in AI-generated pull requests than in human-written ones. None of this is an argument against using AI coding tools — plenty of us reach for Cursor or Copilot daily, and adoption sits at roughly 84% of developers for good reason. It's an argument for treating AI-generated code the way you'd treat a contractor's first pull request: useful, often fast, but not something you merge to &lt;code&gt;main&lt;/code&gt; without a real review pass.&lt;/p&gt;

&lt;p&gt;If you're the developer being asked to "clean up" a vibe-coded app, the fastest useful first step is a targeted security pass — auth flows, secrets, and data access rules — before you touch architecture or performance. That triage alone tells you whether you're looking at a few days of hardening or a genuine rebuild. We put together a longer breakdown of the decision framework, the real numbers behind the productivity-vs-risk tradeoff, and 2026 India pricing for each remediation path in the &lt;a href="https://zanisssoftwares.com/blog/vibe-coding-vs-custom-software-development-india-2026" rel="noopener noreferrer"&gt;original article on vibe coding vs. custom software development&lt;/a&gt;, if you want the full picture to bring back to whoever's asking you to ship this by Friday.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>ai</category>
      <category>programming</category>
    </item>
  </channel>
</rss>
