The Trust Paradox: High Adoption, Low Confidence
The numbers behind the paradox
Developer trust in AI-generated code has been falling, not rising, even as usage climbs. Stack Overflow data shows trust dropping from roughly 40% to 29% in a single year, while favourable sentiment toward AI coding tools slid from over 70% in 2023 to 2024 down to around 60% in 2025. Distrust now outweighs trust outright: 46% of developers actively distrust AI coding tools versus 33% who trust them, and among experienced developers specifically, just 2.6% report high trust in AI-generated code while 20% report high distrust.
Why more confidence doesn't mean more safety
The Stanford finding is the detail worth sitting with: developers using AI coding assistants produced less secure code while feeling more confident about its security than developers who didn't use AI tools at all.
That combination, lower actual security paired with higher perceived security, is precisely the pattern that leads to vulnerabilities shipping to production undetected, since the people writing the code aren't flagging it for extra review.
Real Incidents, Not Hypotheticals
The Lovable data exposure
In May 2025, security researchers found that 170 of 1,645 publicly deployed apps built on the Lovable platform had data-exposure vulnerabilities, roughly one in ten. This wasn't a theoretical risk, these were live, deployed applications with real exposed data.
The database wipe incident
In July 2025, an AI coding agent ignored an explicit "do not touch" instruction and wiped a production database. This is the failure mode that security-first workflows are specifically designed to prevent, an AI system acting beyond its intended scope with no human check in the loop before the damage was done.
The Orchids platform disclosure
Security researcher Etizaz Mohsin discovered a flaw in the Orchids vibe-coding platform in December 2025 and demonstrated it publicly to a BBC News reporter in February 2026, bringing mainstream media attention to a problem that had, until then, mostly stayed within developer and security circles.
Even Experienced Developers Are Vibe Coding Now
It's worth being clear that vibe coding isn't just a beginner or non-technical phenomenon anymore. Linus Torvalds, the creator of Linux and Git, used Google Antigravity to vibe code the Python visualiser component of his AudioNoise project, and said so openly in the project's own README. When one of the most rigorous code reviewers in software history uses these tools and says so publicly, it confirms vibe coding has moved past being dismissible as a fad, and makes the security conversation more urgent, not less, since the assumption that "experienced developers wouldn't do this" no longer holds.
What a Genuinely Safe Vibe-Coding Workflow Looks Like
Treat AI-generated code as a first draft, not a final answer
The Stanford finding is a direct argument for building review into the process by default, not as an optional extra step. Every piece of AI-generated code that touches user data, authentication, or payments should go through the same review a human-written equivalent would.
Never let an agent operate without scoped permissions
The database wipe incident happened because an AI agent had the ability to act beyond what a human had explicitly authorised. Scoping exactly what an AI coding agent can touch, and what it categorically cannot, removes an entire category of failure before it can happen.
Security review before scaling, not after
The Lovable statistic, one in ten deployed apps with a data-exposure flaw, is a scaling problem as much as a coding problem. A vulnerability in a prototype seen by nobody is low risk. The same vulnerability in a deployed app with real users and real data is a very different problem, which is why security review needs to happen before scaling up usage, not after something goes wrong.
What CV Infotech Actually Does
We use Cursor with Claude Sonnet as our own team's daily development tool, so we're not arguing against AI-assisted coding, we use it constantly. The distinction is process: every piece of AI-generated code that reaches a client's production environment goes through the same security review discipline as code a human wrote from scratch. We don't add features to a codebase, AI-generated or otherwise, until it's been checked for exactly the kind of issues covered above.
Building this discipline in-house means someone on your team needs to know what to actually look for in AI-generated code, which is a genuinely different skill from writing secure code yourself. It also means resisting the pressure to ship fast just because the AI tool made shipping fast feel effortless, the entire appeal of vibe coding is speed, and security review is the one step that can't be rushed without recreating exactly the risk profile this post has walked through.
Where We Fit
If you're already running AI-generated code through a proper security review before it reaches production, you're already doing the hard part right, and you likely don't need us for this specifically. Where we come in is exactly the productionisation step, taking whatever a vibe-coding tool generated and reviewing, hardening, and preparing it for real users before scaling.
That's the entire premise of our vibe-coding-to-production work, $30 an hour, written scope before any billing starts. Also see our Cursor AI development service.
Working on a vibe-coding security review and productionisation project?
Written scope before billing. $30/hr. We tell you if we're not the right fit.

Akash Singh
·View full profileCTO and Co-Founder, CV Infotech · Gurugram, India
Akash has been building software for clients in the USA, UK, Australia, and Canada since 2012. He leads a 100% in-house team and personally manages every client relationship and technical decision. Francisco Escobar has worked with him since 2012. Steven has trusted the team with his AI platforms since 2019. 512 verified 5.0 reviews on Freelancer.com.