Apps// Guide

How to Get Exposure for a Vibe-Coded App (Without Getting Hacked the Day It Works)

How to Get Exposure for a Vibe-Coded App — TechWhack
The short answer

Wiz Research and Escape found the same four security holes in vibe-coded apps again and again. Here's the audit to run before you submit anywhere, and where to list your app once it's ready.

Building the app is the cheap part now. Apple's App Store added nearly as many new apps in the first half of 2026 as in all of 2025, about 560,000 of them, and is on track for more than a million this year, past its 2016 record of 890,000. Both figures come from Sensor Tower data first reported by The New York Times, which put the surge down "in large part to vibecoding." What still costs something is getting anyone to find your app, and the day that finally happens is also the day every shortcut you took gets tested at once.

Run the Security Pass Before Anyone Finds You

Wiz Research studied apps built on vibe-coding platforms, working with Lovable, and published the results under the headline "One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications". The exposure came from the same four misconfigurations, over and over. Security firm Escape found the same pattern at scale: it scanned more than 5,600 publicly available vibe-coded apps and found more than 2,000 vulnerabilities, 400-plus exposed secrets and 175 instances of exposed personal data. None of the four problems is exotic.

Passwords checked in the browser. Wiz found apps whose entire login ran on the client side, comparing the password you type against a string sitting in the JavaScript, where anyone can read it in developer tools. Both of Wiz's examples then marked you as logged in with a simple flag in the browser's storage, which an attacker can set by hand without touching the login form at all.

API keys shipped to the browser. OpenAI keys and other third-party credentials hardcoded into client-side files instead of called through a backend. Lovable's own security best practices put it plainly: "Secrets stored in frontend code are visible to users and should be considered compromised."

Database tables open to anyone. Vibe-coding platforms make it easy to wire an app to a database like Supabase, and just as easy to leave Row-Level Security off or set it too loose. Supabase's documentation is blunt about what that means: "A table in an exposed schema without RLS is readable and writable by any role with a grant on it." In Wiz's writeup, a vibe-coded enterprise game leaked all of its users' personal details and IP addresses this way.

Internal tools left public. Admin dashboards, internal knowledge bases and chatbots trained on company data, deployed with no login at all. Wiz found them by searching for the platforms' own fingerprints, which means anyone else can too.

Wiz calls all four "easily preventable," and the rule under every fix fits in one line from Lovable's guide: "Frontend code should never make security decisions." Ask whatever you built with to audit exactly these four things, then check its answers against Lovable's checklist yourself rather than taking the AI's word for it.

The Vibe-Coding Directories: Free, Small, Worth an Afternoon

A handful of directories exist only for apps built this way. They're free or close to it, and each takes minutes, but they're small: most are run by one person and list dozens of projects, not thousands. Treat them as a permanent link and a small, genuinely interested audience, not a launch plan. Sizes below are what each showed when we checked on September 27, 2026.

DirectoryWhat it isSize when checkedHow to get listed
r/vibecodingThe main vibe-coding subredditAbout 356,000 weekly visitorsPost it yourself; read the subreddit's rules first
Vibe Coding ShowcaseGallery of vibe-coded projects90 projectsSubmission form on the site
YourAIProject Vibe App DirectoryProject pages, many imported from GitHubAbout 60 projectsFree, GitHub-based listings
awesome-vibecoded-appsA curated "awesome" list on GitHub50 entriesFree, by pull request
vibcod.devOne-person, hand-picked directoryAbout 30 projectsFree; needs a live URL, gives a followed link
Built With Vibe CodeHand-curated Lovable appsNot publishedNo form; contact the curator on X

Where to List It

Four places are worth your submission beyond the niche directories. Start with the one that keeps working after launch day, then take on the loud ones.

AlphaShot

AlphaShot's homepage, with the 'Discover your next favourite product' heading, a free submit button and product category filters

AlphaShot is a free Product Hunt alternative built the other way round: there's no launch day to win or lose. It's a directory, and by its own rules products stay listed, rankings change with recent votes, and upvotes come from signed-in members, one vote per member, enforced by the database. Paid promotion goes into labeled slots "so it never bumps a free listing out of a position it earned." Once you verify you own the domain, your product page carries a followed link back to your site, according to its FAQ; rows on the main board stay nofollow.

Product Hunt

Product Hunt's homepage, listing the top products launching today with comment and upvote counts

Product Hunt runs on a daily board. Its own launch guide explains that "the homepage runs on a 24-hour cycle based on Pacific Standard Time" and recommends posting at 12:01am PST to get the full day. That makes it a spike: the attention lands in one day and moves on when the board resets, so go in with the security pass done and a plan for the comments.

Peerlist Launchpad

Peerlist Launchpad showing the week's ranked product launches with upvote counts and a voting countdown

Peerlist Launchpad runs a weekly cycle instead of a daily one. Launches open every Monday, 12:00am to 11:59pm UTC, and voting on that week's launches stays open until the end of Sunday, so a smaller app has a week to be found instead of a day. You'll need a verified Peerlist profile first, per Peerlist's help center, and a project page that is 100% complete, or the launch fails.

Show HN

The Show HN page on Hacker News, listing community-submitted projects with points and comment counts

Show HN on Hacker News is for "something you've made that other people can play with," and its guidelines ask you to make it easy to try "without barriers such as signups or emails." They also include a line written for exactly this moment: "Don't post quickly-generated one-offs; anybody can do that now." Expect people to click around and try to break it, so save Show HN for an app you'd defend in the comments, after the security pass, not before.

Get Launch-Ready Before You Submit Anywhere

Most of what sinks a first launch is showing up half-ready. AlphaShot's eight free tools run without an account and cover the prep work: a startup idea validator that scores a concept 0 to 100 across six dimensions before you sink a weekend into it, an MVP cost calculator, a startup name and domain checker that tests .com, .io, .app, .dev and .ai as you type, a tagline checker that shows your one-liner in a real listing row, a logo checker that measures your logo against a 56px listing slot, a SaaS pricing calculator, an interactive product launch checklist, and a landing page analyzer that scores your page across eight conversion dimensions.

A Short Checklist Before You Hit Submit

Run through this once, in order:

Run the security pass. The four checks above: client-side passwords, exposed keys, open database tables, unauthenticated internal tools.

Make sure a stranger can actually use it. Every platform here turns away apps people can't get into. AlphaShot's FAQ says rejections are "usually a dead link, a product that is not actually available yet, or a duplicate of a listing that already exists"; vibcod.dev asks for "a live URL someone can visit"; Show HN's guidelines rule out landing pages and sign-up pages. Open your link logged out, in a private window, on your phone.

Fill it with real-looking data. An empty dashboard shows a stranger nothing. Seed it before you take screenshots.

Write the one-liner that names the problem, not the category. "AI-powered productivity platform" describes nothing. "Turns a meeting recording into a to-do list" tells a stranger exactly why to click.

Then list it: AlphaShot and the vibe directories first, because they're permanent and free; Peerlist on a Monday; Product Hunt and Show HN once the app can take a crowd.

Frequently asked

Do I need to disclose that my app was built with AI?
On the vibe-coding directories it's the point, since they exist only for apps built this way. Elsewhere, lead with what the app does. Hacker News is the one place to be careful: its Show HN guidelines ask people not to post "quickly-generated one-offs," so post there only once the app is more than a weekend prompt.
Is it safe to publicly list an app I built by vibe coding?
It is once you've fixed the four problems Wiz Research documented: passwords checked in the browser, API keys in client-side code, database tables without Row-Level Security, and internal tools with no login. Wiz calls all four easily preventable. Escape's scan of more than 5,600 public vibe-coded apps shows how often they get skipped, so check before you list, not after.
How much does it cost to get exposure for an indie app?
Nothing, to start. AlphaShot lists products for free and its eight prep tools need no account, most of the vibe-coding directories list free, and a Show HN post costs nothing. Paid promotion exists on some platforms for a bigger short-term push, but it's optional, not the price of entry.
Where should I submit a vibe-coded app first?
The permanent, free listings first: AlphaShot and the vibe-coding directories take an afternoon between them. Launch on Peerlist on a Monday, and save Product Hunt and Show HN until the app has been through the security pass and can handle a crowd.

More in Apps