Back to browse
Howbadis.it – Paste your vibe-coded app, see what'll break

Howbadis.it – Paste your vibe-coded app, see what'll break

by emarboeuf·May 8, 2026·3 points·0 comments

AI Analysis

●●●BangerSolve My ProblemDark Horse

Exposes exposed API keys and public databases in vibe-coded apps before clients do.

Strengths
  • Targets specific pain point of no-code apps with zero security monitoring or error tracking.
  • Combines automated URL scanning with stack questions to catch issues scanners miss.
  • Median score of 38/100 across 4,271 apps proves real demand for this audit tool.
Weaknesses
  • Limited to no-code platforms like Lovable and Bolt, not custom-built applications.
  • Surface-level scanning may miss deeper architectural or business logic vulnerabilities.
Category
Target Audience

Non-technical founders and no-code developers launching apps

Similar To

SecurityHeaders.com · Mozilla Observatory · SSL Labs

Post Description

Ten years as a CTO. Owned Engineering, security, compliance at very different stages.

Your non-technical friend built something in Lovable last weekend. It works. They want to charge for it. They don't know their API keys are in the client bundle, their database is public, and they have zero error monitoring.

howbadis.it: they paste the URL, get a score. A few stack questions cover what the URL scan can't see.

What checks should I add?

Similar Projects