Hook

Their other posts in the index, biggest breakout first.
There's a wall of shame for vibe coded apps. It went viral on Hacker News recently and some of these are bad. Apps that expose every user's data. Apps where you can literally access someone else's account from the URL bar. Apps that store passwords in plain text. And the part that messes me up is that people who built these didn't know. They shipped thinking everything was fine because the AI told them that it was fine. And I keep thinking that could be you right now. So here's how you never end up on that list. Three checks, five minutes each. One, search your entire codebase for any API key or secret that's not in an ENV file. Two, try to access every page and every endpoint without being logged in. Three, put a single quote in every input field and see what happens. And that's it. That catches what 90% of that wall of shame didn't. Don't be on that list, please.