Honest reviews, security audits, and shipping advice for apps built with Lovable, Cursor, Claude Code, and Bolt.
Is your AI code secure? Is your Lovable app safe to launch? A 10-item founder-language checklist for Lovable, Cursor, and Claude Code apps. Each item: what, how to test, when to fix.
AI slop code is the new technical debt. Here are 8 specific patterns I find in audits, the r/cscareerquestions thread that named the problem, and what to do if your codebase has it.
A founder-grade vibe audit catches the 6 judgment-bound issues auto-scanners structurally cannot: RLS leaks, tenant boundary violations, auth state on refresh, SSR data leak, prompt injection in stored content, and secret rotation.