Vibe-Coded Tools Need Grown-Up Engineering: A New Service Line for Software Companies

45% of AI-generated code carries security flaws. As non-coders ship real tools, software firms can sell security testing, maintenance and architecture.

10/7/20264 min read

In Veracode's 2025 study of more than 100 language models, 45% of AI-generated code introduced a security vulnerability [1]. Meanwhile, the platforms that let non-coders build software from a prompt are growing at extraordinary speed: Replit's annualised revenue was estimated at around $525m by April 2026 [2], and Lovable reported $200m of annual recurring revenue by December 2025 [3].

Put those two facts together and you get a new market. Thousands of operations managers, finance leads and founders are now producing working software. Very few of them can secure it, structure it or keep it running. That is exactly what traditional software companies are good at.

The prototype is the easy part

Vibe coding has genuinely lowered the cost of a first version. A business user can have a working internal tool in a day. But a working demo and a dependable product are different things, and the difference only shows up later: when the tool holds real customer data, when a second person needs to change it, when the platform that generated it changes, or when something breaks at 7am on a Monday.

Three problems recur, and each is a service a software company can sell.

Service one: security testing

The evidence on security is consistent. Veracode found models failed to defend against cross-site scripting in 86% of relevant test cases [1], and its CTO noted that "GenAI models make the wrong choices nearly half the time, and it's not improving" [1]. The consequences are not theoretical. A critical flaw (CVE-2025-48757, scored 9.3 out of 10) described how insufficient database row-level security in apps generated on one leading platform "allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites" [4].

The pattern is clear: non-coders rarely know to ask whether access controls, secrets handling and data exposure are correct, and the AI will not volunteer it. A structured security assessment for a vibe-coded tool covers access control and authentication, exposed keys and credentials, input validation, dependency risks and data-protection obligations such as UK GDPR. It is a well-defined, fixed-scope offer that software firms can productise.

Service two: bringing the tool to the right architecture

AI tends to generate whatever works right now. Independent analysis of 470 open-source pull requests found AI-written code produced roughly 1.7 times more issues than human-written code [5], and GitClear's analysis of code changes found an eightfold rise during 2024 in duplicated code blocks, a sign of copy-and-paste rather than reusable design [6].

For a business tool, that shows up as hard-coded logic, one giant file, no separation between data and interface, no tests, and no way to integrate with the systems the business already runs. The service here is a re-platforming engagement: assess what exists, keep the business logic and user experience that work, and rebuild the foundations. That means a sensible data model, proper authentication, an environment strategy, automated tests, and clean integration points. The vibe-coded prototype becomes the specification, which is often a faster and cheaper starting point than a blank page.

Service three: ongoing maintenance and support

Software that nobody owns decays. Dependencies go out of date, platform changes break features, and the one person who understood the prompt history moves on. GitClear's CEO has warned that "AI-driven maintainability decay will proliferate" if teams only measure how much code gets produced [6]. As one software chief executive put it, "AI can generate a solution. It cannot carry responsibility for one" [7].

A managed maintenance retainer answers that: monitoring, patching, backups, access reviews, small enhancements and a named person to call. For the customer it replaces an unfunded risk with a predictable monthly cost. For the software firm it is recurring revenue built on skills it already has.

How to package it

The most effective offers are simple. A fixed-price health check (security and architecture review with a prioritised fix list) is the entry point. A hardening sprint fixes the critical issues. A rebuild or migrate engagement moves the tool onto a proper architecture when it has outgrown the prototype. A care plan retainer keeps it secure and supported afterwards. Each step is a natural next step from the last, and each is far easier to sell than a blank-sheet development project because the customer already knows the tool is valuable.

Two cautions. First, be honest about when rebuilding is not worth it: some vibe-coded tools should stay as disposable prototypes. Second, protect your own delivery quality by applying review and testing discipline to AI-assisted work in your own team.

What to do next

If you run a software business, start by listing the skills you already have that this market lacks: security testing, architecture, DevOps, support. Then pilot a health check with two or three existing customers who have built something themselves.

#VibeCoding #AppSec #SoftwareDevelopment #DigitalTransformation #AI

InfinityX Digital helps UK businesses turn AI-built prototypes into dependable tools. We would love to partner with software companies that can provide these services for our clients. Get in touch at [https://infinityxd.uk](https://infinityxd.uk).

Sources & quotes

[1] Veracode, "AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks" (30 July 2025).** [veracode.com](https://www.veracode.com/?p=22337)

[2] Sacra, "Replit passes $500M/year" (2026).** [sacra.com](https://sacra.com/research/replit-passes-500m-year/)

[3] VKTR, "Lovable raises $400 million at $13.3 billion valuation" (12 August 2026).** [vktr.com](https://www.vktr.com/ai-platforms/lovable-raises-400-million-at-133-billion-valuation/)

[4] CVE-2025-48757 (published 30 May 2025; CVSS 9.3 Critical), via Intruder CVEmon.** [cvemon.intruder.io](https://cvemon.intruder.io/cves/CVE-2025-48757)

[5] CodeRabbit, "State of AI vs Human Code Generation Report" (17 December 2025).** [coderabbit.ai](https://www.coderabbit.ai/newsroom/state-of-ai-vs-human-code-generation-report)

[6] LeadDev, "How AI-generated code accelerates technical debt" (19 February 2025), reporting GitClear analysis.** [leaddev.com](https://leaddev.com/software-quality/how-ai-generated-code-accelerates-technical-debt)

[7] Andrej Hájek (CEO, FLO), "Vibe coding won't kill SaaS… but it will kill weak SaaS", Techfinitive (28 April 2026).** [techfinitive.com](https://www.techfinitive.com/opinions/vibe-coding-wont-kill-saas-but-it-will-kill-weak-saas/)

---