Vibe Code Penetration Test
A monthly penetration testing subscription for applications built with AI-assisted 'vibe coding' tools. Every test is performed by an ethical hacker and delivered as a clear, actionable report | so you can ship fast without shipping vulnerabilities.
The Challenge
Common problems businesses face:
The Risks of Getting It Wrong
Our Structured Approach
Commercial Outcomes
Frequently Asked Questions
What's included in the £199 monthly subscription?
A 12 month subscription includes one penetration test per month performed by an ethical hacker, one retest of previously flagged issues, and a written report for every test. The price is fixed at £199 per month for the duration of the term.
What if I need more than one test in a month?
Additional tests within the same month are available at £150 per test. There is no limit on how many additional tests you can request.
Who performs the tests?
All testing is carried out by an ethical hacker. You're not getting an automated scan | you're getting genuine manual testing combined with industry-standard tooling.
What does the report cover?
Each report sets out the scope of the test, the vulnerabilities identified, their severity, the potential business impact and clear remediation guidance your developers can act on.
What is a 'vibe-coded' application?
We use the term for applications built primarily using AI-assisted coding tools such as Lovable, Cursor, Bolt, v0 and similar platforms. These apps ship quickly, which makes ongoing security testing especially important.
Is there a minimum term?
Yes, the subscription runs for 12 months. This allows us to build up knowledge of your application over time and deliver more meaningful testing each month.
Vibe Coding Platforms We Test
Whichever AI builder or agentic IDE your team is shipping with, the same classes of vulnerability tend to slip through. We test apps built on all of the leading platforms | and new ones are coming out all the time.
Lovable
AI app builder with full-stack React + Supabase output.
Base44
All-in-one platform for building internal tools and apps with AI.
Bolt.new
StackBlitz-powered in-browser AI app builder.
v0 by Vercel
AI-generated React + Tailwind UI shipped to Vercel.
Cursor
AI-first IDE used to vibe-code production codebases.
Replit Agent
Cloud IDE with an autonomous agent that builds and deploys apps.
Platform names are trademarks of their respective owners | listed for reference only.
What We Test
Every monthly test is manual, benchmarked against the OWASP Top 10 and tailored to how vibe-coded apps actually fail in production.
Injection flaws
SQL, NoSQL and command injection across forms, APIs and query parameters.
Broken authentication
Login flows, session handling, password reset and multi-factor weaknesses.
Broken access control
Horizontal and vertical privilege escalation, IDOR and missing authorisation checks.
Sensitive data exposure
Unprotected endpoints, leaked tokens, misconfigured storage and verbose errors.
Misconfiguration
Headers, CORS, default credentials, exposed admin panels and cloud misconfig.
Cross-site scripting (XSS)
Reflected, stored and DOM-based XSS across user-facing surfaces.
Business logic abuse
Workflow bypasses, race conditions and abuse of legitimate features.
Vulnerable dependencies
Outdated libraries and known CVEs introduced by AI-generated code.
OWASP Top 10 coverage
Every test is benchmarked against current OWASP Top 10 guidance.
One-Off Pen Test vs Monthly Subscription
Traditional engagements give you a snapshot. A subscription gives you continuous assurance as your app evolves.
| Feature | Traditional One-Off Test | Vibe Code Pen Test Subscription |
|---|---|---|
| Up-front cost | £2,000 – £8,000+ | £199 / month |
| Test frequency | Once, then out of date | Every month |
| Retest of previous issues | Usually extra | Included monthly |
| Written report | Included | Included every month |
| Knowledge of your app | Starts from scratch | Builds over 12 months |
| Additional tests | Full new engagement | £150 per extra test |
| Evidence for clients / insurers | Single point in time | Ongoing audit trail |
How A Month Works
A predictable monthly rhythm so security keeps pace with delivery | not the other way around.
Test booked & scoped
We confirm scope, agree the testing window and review any changes since the last test.
Penetration test performed
Manual testing by an ethical hacker, supported by industry-standard tooling.
Report delivered
Clear written report with findings, severity, business impact and remediation guidance.
Retest scheduled
We re-verify previously flagged issues to confirm fixes are in place and effective.
What The Report Looks Like
Every monthly test ends with a professional written report your developers, clients and insurers can rely on.
Penetration Test Report
[Client Application]
Monthly Assessment | May 2026
Prepared by
Lucas & Co Consultants
Ethical Hacker
Executive Summary
Plain-English overview of scope, risk posture and headline findings for non-technical stakeholders.
Scope & Methodology
Targets tested, in-scope and out-of-scope items, tooling used and testing approach.
Findings
Each issue with severity (Critical / High / Medium / Low), affected component and reproduction steps.
Business Impact
What an attacker could realistically achieve and the consequences for your firm and clients.
Remediation Guidance
Specific, developer-ready recommendations | not generic advice.
Retest Results
Verification status of previously reported issues: Fixed, Partially Fixed, or Still Present.
Sample structure shown. Real reports are confidential and tailored to your application.
Ready to discuss your project?
Book a 30-minute strategy call with Stephen Lucas.
Book a Strategy Call