How to Get Exposure for a Vibe-Coded App (Without Getting Hacked the Day It Works)
Wiz Research and Escape found the same four security holes in vibe-coded apps again and again. Here's the audit to run before you submit anywhere, and where to list your app once it's ready.
Building the app is the cheap part now. Apple's App Store added nearly as many new apps in the first half of 2026 as in all of 2025, about 560,000 of them, and is on track for more than a million this year, past its 2016 record of 890,000. Both figures come from Sensor Tower data first reported by The New York Times, which put the surge down "in large part to vibecoding." What still costs something is getting anyone to find your app, and the day that finally happens is also the day every shortcut you took gets tested at once.
Run the Security Pass Before Anyone Finds You
Wiz Research studied apps built on vibe-coding platforms, working with Lovable, and published the results under the headline "One in Five Organizations Exposed to Systemic Risks in Vibe-Coded Applications". The exposure came from the same four misconfigurations, over and over. Security firm Escape found the same pattern at scale: it scanned more than 5,600 publicly available vibe-coded apps and found more than 2,000 vulnerabilities, 400-plus exposed secrets and 175 instances of exposed personal data. None of the four problems is exotic.
Passwords checked in the browser. Wiz found apps whose entire login ran on the client side, comparing the password you type against a string sitting in the JavaScript, where anyone can read it in developer tools. Both of Wiz's examples then marked you as logged in with a simple flag in the browser's storage, which an attacker can set by hand without touching the login form at all.
API keys shipped to the browser. OpenAI keys and other third-party credentials hardcoded into client-side files instead of called through a backend. Lovable's own security best practices put it plainly: "Secrets stored in frontend code are visible to users and should be considered compromised."
Database tables open to anyone. Vibe-coding platforms make it easy to wire an app to a database like Supabase, and just as easy to leave Row-Level Security off or set it too loose. Supabase's documentation is blunt about what that means: "A table in an exposed schema without RLS is readable and writable by any role with a grant on it." In Wiz's writeup, a vibe-coded enterprise game leaked all of its users' personal details and IP addresses this way.
Internal tools left public. Admin dashboards, internal knowledge bases and chatbots trained on company data, deployed with no login at all. Wiz found them by searching for the platforms' own fingerprints, which means anyone else can too.
Wiz calls all four "easily preventable," and the rule under every fix fits in one line from Lovable's guide: "Frontend code should never make security decisions." Ask whatever you built with to audit exactly these four things, then check its answers against Lovable's checklist yourself rather than taking the AI's word for it.
The Vibe-Coding Directories: Free, Small, Worth an Afternoon
A handful of directories exist only for apps built this way. They're free or close to it, and each takes minutes, but they're small: most are run by one person and list dozens of projects, not thousands. Treat them as a permanent link and a small, genuinely interested audience, not a launch plan. Sizes below are what each showed when we checked on September 27, 2026.
| Directory | What it is | Size when checked | How to get listed |
|---|---|---|---|
| r/vibecoding | The main vibe-coding subreddit | About 356,000 weekly visitors | Post it yourself; read the subreddit's rules first |
| Vibe Coding Showcase | Gallery of vibe-coded projects | 90 projects | Submission form on the site |
| YourAIProject Vibe App Directory | Project pages, many imported from GitHub | About 60 projects | Free, GitHub-based listings |
| awesome-vibecoded-apps | A curated "awesome" list on GitHub | 50 entries | Free, by pull request |
| vibcod.dev | One-person, hand-picked directory | About 30 projects | Free; needs a live URL, gives a followed link |
| Built With Vibe Code | Hand-curated Lovable apps | Not published | No form; contact the curator on X |
Where to List It
Four places are worth your submission beyond the niche directories. Start with the one that keeps working after launch day, then take on the loud ones.
AlphaShot
AlphaShot is a free Product Hunt alternative built the other way round: there's no launch day to win or lose. It's a directory, and by its own rules products stay listed, rankings change with recent votes, and upvotes come from signed-in members, one vote per member, enforced by the database. Paid promotion goes into labeled slots "so it never bumps a free listing out of a position it earned." Once you verify you own the domain, your product page carries a followed link back to your site, according to its FAQ; rows on the main board stay nofollow.
Product Hunt
Product Hunt runs on a daily board. Its own launch guide explains that "the homepage runs on a 24-hour cycle based on Pacific Standard Time" and recommends posting at 12:01am PST to get the full day. That makes it a spike: the attention lands in one day and moves on when the board resets, so go in with the security pass done and a plan for the comments.
Peerlist Launchpad
Peerlist Launchpad runs a weekly cycle instead of a daily one. Launches open every Monday, 12:00am to 11:59pm UTC, and voting on that week's launches stays open until the end of Sunday, so a smaller app has a week to be found instead of a day. You'll need a verified Peerlist profile first, per Peerlist's help center, and a project page that is 100% complete, or the launch fails.
Show HN
Show HN on Hacker News is for "something you've made that other people can play with," and its guidelines ask you to make it easy to try "without barriers such as signups or emails." They also include a line written for exactly this moment: "Don't post quickly-generated one-offs; anybody can do that now." Expect people to click around and try to break it, so save Show HN for an app you'd defend in the comments, after the security pass, not before.
Get Launch-Ready Before You Submit Anywhere
Most of what sinks a first launch is showing up half-ready. AlphaShot's eight free tools run without an account and cover the prep work: a startup idea validator that scores a concept 0 to 100 across six dimensions before you sink a weekend into it, an MVP cost calculator, a startup name and domain checker that tests .com, .io, .app, .dev and .ai as you type, a tagline checker that shows your one-liner in a real listing row, a logo checker that measures your logo against a 56px listing slot, a SaaS pricing calculator, an interactive product launch checklist, and a landing page analyzer that scores your page across eight conversion dimensions.
A Short Checklist Before You Hit Submit
Run through this once, in order:
Run the security pass. The four checks above: client-side passwords, exposed keys, open database tables, unauthenticated internal tools.
Make sure a stranger can actually use it. Every platform here turns away apps people can't get into. AlphaShot's FAQ says rejections are "usually a dead link, a product that is not actually available yet, or a duplicate of a listing that already exists"; vibcod.dev asks for "a live URL someone can visit"; Show HN's guidelines rule out landing pages and sign-up pages. Open your link logged out, in a private window, on your phone.
Fill it with real-looking data. An empty dashboard shows a stranger nothing. Seed it before you take screenshots.
Write the one-liner that names the problem, not the category. "AI-powered productivity platform" describes nothing. "Turns a meeting recording into a to-do list" tells a stranger exactly why to click.
Then list it: AlphaShot and the vibe directories first, because they're permanent and free; Peerlist on a Monday; Product Hunt and Show HN once the app can take a crowd.


