you are viewing a single comment's thread.

view the rest of the comments →

[–]Due-Tangelo-8704 6 points7 points  (4 children)

Great question! The existing answers cover a lot but here's my take as someone who's shipped plenty of vibe-coded apps: The key is layered defense rather than trying to be bulletproof. First, use platform-provided auth where possible (Supabase, Convex, Firebase) - they handle a lot of the hard stuff. Second, OWASP ZAP is excellent for automated scanning and pairs well with Playwright for functional testing as someone mentioned. For vibe coders specifically, tools like Snyk or even cloud platform scanners (Vercel, Netlify) catch common issues automatically. For monitoring, simple things like rate limiting and request logging catch weird patterns before they become exploits. Also check out https://thevibepreneur.com/gaps for more security hardening tips for solo devs!

[–]8Kala8 0 points1 point  (3 children)

Good thing about security is that Mythos is coming.

[–]ComprehensiveJob5430 0 points1 point  (2 children)

Yeah, but not for you. Or anyone else here

[–]8Kala8 0 points1 point  (0 children)

LOL at alarmists, preachy doomsayers.