/ WebThree Consulting · Free vibe-code audit
Before hackers test your app, we will.
WebThree Consulting tests apps built with Lovable, Bolt, Replit, Cursor or Claude Code. A person tries to break your live app from the outside, and the results are free. No code needed.
WebThree replies within 1 business day and signs an NDA before starting.
Trusted by 300+ companies
Live · bookly.app
Your app is ready.Found you.
Live. Waiting for your first visitorClick the attacks to block themYou blocked 0. 0 got through.
is all it takes bots to find a new site. Sometimes 12 seconds.1
You blocked 0 · 0 got throughYou ship bookly.app. The first visitor isn't a person.
/ The attacks we see most
They're not guessing. They have a playbook.
Every vibe-coded app is made from the same few parts. So every attacker tries the same few doors.
01 · The data grab
Ask the database for everything.
If the database rules are off, it hands over every customer's name, email and booking.
1 in 10 Lovable showcase apps exposed user data through missing database rules.3
02 · The key hunt
Search your code for secret keys.
AI tools paste keys wherever they work. Bots read every file your site sends.
In one research honeypot, 1 in 6 requests hunted for secret files.4
You can't see any of this from your dashboard.We can.
A person tries to break your live app from the outside, the way an attacker would.
Get my free audit- The data grabtested
- The key hunttested
- The promotiontested
- The free ridetested
- 01Send your link and emailAdd your app's link and your email. We ask for a test login when we reply.
- 02We try to break itData access, secrets, admin roles, payments, AI agents and more. By hand, from the outside, and in your code if you share it. We never change or delete real data.
- 03You get the resultsEvery result is free. If we find something critical, we show you what it is and offer to fix it for you.
Sources
- Kondracki, So and Nikiforakis, “Uninvited Guests: Analyzing the Identity and Behavior of Certificate Transparency Bots”, USENIX Security 2022
- Deng, Fan and Meng, “Understanding the (In)Security of Vibe-Coded Applications”, arXiv 2606.23130, September 2026. Audit of 200 live apps built with Lovable and Claude Code
- Matt Palmer, statement on CVE-2025-48757, March 2025. Scan of 1,645 Lovable showcase apps
- THOR Collective, “Vibe Coding The Holidays Away”. Honeypot data for January 1–16, 2026
- OWASP Top 10:2025, A01 Broken Access Control
- Tenzai, “Bad Vibes: comparing the secure coding capabilities of popular coding agents”. 15 apps built by 5 coding agents
/ Questions
What's the catch?
Is the audit really free?+
Yes. Testing, results and the explanation of every finding are free. If we find something critical, we also offer to fix it for you. That fix is a separate job, and we tell you what it involves before you decide.
What counts as critical?+
A hole that lets someone outside your team read other users' private data, act as another user or an admin, or change payments.
Won't you just call everything critical?+
No. Critical has a fixed meaning, set out above, and we show you what we found so you can check it yourself. Either way, the results are free.
Will you break my live app?+
We never delete or change real data, and we only use test accounts. If you prefer, send a staging link instead.
Do you need my code?+
No. With just the URL and a test login, we test the live app from the outside, the way an attacker would. Sharing your code gives us the fuller picture: database rules, server logic and keys an outside test can miss. We sign an NDA before you share anything.
Is my customers' data safe with you?+
What we see stays between us. We sign an NDA before we start and delete what we collected when the audit closes.
How fast will I hear back?+
We reply within 1 business day. We agree a time, run the audit, and send the result.
Is vibe coding safe?+
It can be. AI tools write code that works, but they often skip the checks that keep data private and payments honest. In a 2026 audit of 200 live vibe-coded apps, 91% had at least one exploitable hole. Finding them is the first step.
Is code from Claude Code secure?+
Claude Code writes code that works, but an app is only as safe as the checks the agent was asked to build in. The 2026 audit of 200 live apps covered apps built with Claude Code and Lovable, and 91% had at least one exploitable hole. We audit the running app, whichever agent wrote it.
Is this an AI code review?+
No. AI code review tools read your code and flag patterns. We are people testing your live app the way an attacker would: signing up, reading other users' data, changing roles and payments. It works alongside AI code review, not instead of it.
Do you check AI agents inside my app?+
Yes. If your app includes a chatbot or an AI agent that can take actions, we test it from the outside like the rest of the app: whose data it will hand over and what it will do on a user's behalf. That AI agent security check is part of the audit.
How is this different from a penetration test?+
A formal penetration test is a larger, scoped engagement, often needed for compliance. Ours is a focused, outside-in check of the holes vibe-coded and agent-built apps most often have, sized for startups. If you need a formal pentest, we will tell you and scope one.








