# What breaks in vibe-coded apps, and how to monitor them

An app built with Claude Code, Lovable, Bolt or v0 can reach real users in a day. The tools have solved that part. What happens to the app after launch is mostly left to you.

## Where vibe-coded apps fail

Comparisons of AI app builders in 2026 agree that the generated code is rarely production-grade by default, and that failures cluster in authentication, error handling and backend state rather than in the UI ([Valletta Software](https://vallettasoftware.com/blog/post/vibe-coding-tools)).

The security gaps are the easiest to see:

- CVE-2025-48757: 170 of 1,645 Lovable showcase apps had missing row-level security, so whole tables could be read with the public key ([LaunchReady](https://launchreadycode.com/blog/cve-2025-48757)).
- A scan of 380,000 vibe-coded assets in April 2026 found about 5,000 exposing sensitive data without authentication ([VibeEval](https://vibe-eval.com/updates/lovable-security-report-apr-2026/)).

## Why a publish-time scan is not enough

Builder platforms now scan an app when it is published, and some have started checking running apps too. A scan sees the code at one moment. It does not see the signup that fails for Safari users after Tuesday's deploy, the query that slows down once the table grows, or the token bill that doubles because a loop calls the model twice.

## What to monitor once the app is live

- **Errors** in the browser, the mobile app and the backend, tied to the release that introduced them.
- **Deploys**: whether each release made errors and response times better or worse than the one before.
- **Usage**: where people stop in a flow such as signup, and which pages are slow.
- **Security** at runtime: exposed tables, missing headers, keys in client bundles.
- **Cost**: hosting and model tokens next to the errors they come with.

Most small teams cover these with four or five separate tools, each with its own logs, and none of those tools talks to the agent that wrote the code.

## How OpsBeaver handles it

OpsBeaver watches all of these for each service, across every platform it runs on, and writes one brief Claude Code can act on: what broke, the evidence, the probable cause and a suggested change. After the fix ships, it checks the new release against the old one. You approve the work. [Read how it works](/).
