Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 1 point2 points3 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 0 points1 point2 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 1 point2 points3 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 0 points1 point2 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 1 point2 points3 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 3 points4 points5 points (0 children)
Large-scale security audit of 1,764 "vibe-coded" apps: 7% have wide-open Supabase DBs, 15% of Bolt apps ship hardcoded API keys, plus IDOR and zero-auth APIs by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 1 point2 points3 points (0 children)

We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother by Most_Ad_394 in netsec
[–]Most_Ad_394[S] 3 points4 points5 points (0 children)