Dev.to VibeCoding
A team audited 1,764 apps built with AI coding tools like Lovable and Bolt. The numbers are bad.
7% had publicly accessible Supabase databases. Anyone with the URL could read the data.
15% of Bolt-generated apps shipped with hardcoded API keys in source.
Source: r/netsec post summarizing the a