A shop the day before opening, with open boxes, filled shelves and a handwritten list on the counter beneath a brass lamp

· 6 min read

Check your application before launch: the 23 vulnerabilities an audit found

The final week goes into announcements, screenshots and first-customer notices. Two pre-launch security reviews, described by a commissioner and a provider, show what else the week should contain and why the list fits into five ordinary working days.

The owner of a no-code marketplace reports on Reddit (r/nocode, August 2026) that its pre-launch audit produced 23 findings across four severity levels, including one letting buyers set product prices themselves. Checking an application before launch takes a week and a list.

23 findingsacross four severity levels in a pre-launch marketplace review (r/nocode, August 2026)
5 access rulesmore permissive than intended in another pre-launch review (r/vibecoding, July 2026)
level 1 freeamong Replit's three security-test levels announced August 17, 2026

What two reviews found

The marketplace's first three findings concerned buyers setting checkout prices, missing access checks and unauthenticated data changes. A second review described by a provider on r/vibecoding (July 2026) found something else: every demo visitor silently created a permanent company, workspace and profile in the production database, while five security rules granted excessive access. Its commissioner expected thousands of fake accounts in the hours after opening. None of these defects is visible on screen or prevented operation. Both reviews were commissioned before public opening; uncommissioned reviews let an application ship on schedule with the same defects and no list naming them.

The happy path and everything else

Another account (r/vibecoding, August 2026) voices most commissioners' doubt: its author did not know whether endpoints checked permissions server-side or whether a user could retrieve another's data by guessing an identifier. Their prototype launched in a weekend for work previously estimated in months. AI builds the briefed path, where a customer does what is expected. Everything outside remains to be decided, and that is what these reviews billed. A security provider sells the list of unrequested cases: cross-account access, editable amounts, error states and deletions.

Reading code is not enough

On August 17, 2026, Replit added black-box penetration tests attacking an application via its public address without reading code, complementing source analysis (replit.com, August 2026). It divides checks into three levels, the first free, and says their findings overlap little: an unprotected administration dashboard was found externally but missed by code review. The announcement chiefly serves as a useful admission for software commissioners: request both, whichever tool built your application.

What Félix does and does not do

At Maestro, verification lives within work: Constance reviews requirements before construction, Félix writes each stage's tests before building, and failed verification sends a stage back for repair. This catches forgotten rules and regressions and forces explicit statements of who may read what, as explained in the two-minute customer-data test. Nobody here attacks your application externally once live. We also have our own defects, as the visible key in our code reminded us in August. A specialist security review remains an expense for your launch budget.

The preceding week's list

Four passes fit into five days. Monday, permissions: for every screen and data item, write who reads and changes it, then test with two accounts. Tuesday, money: repeat a purchase changing what you can, quantity, discount code, shipping address, and check that the final amount remains the catalogue amount. Wednesday, separation: ensure demo visitors and test data write nothing into the database serving real customers. Thursday, unhappy states: deleted account, declined payment, requested export, lost password. Friday, have an outsider review and keep the report: from September 11, 2026, your software also has obligations to account for.

Read the complete guide: build an application without coding

Back to the journal

Take the baton.

Leave your email to try Maestro in the first waves.

The beta is open by invitation on macOS 13 and later. Leave your email for an upcoming wave of access. Windows is in development.

The beta is currently available on macOS 13 or later. Your answer helps us plan other versions.

Your email is only used to let you know when access opens. Nothing else, we promise.