The store looked finished. Clean product pages, a checkout that worked, a fast mobile layout. The owner was happy with it and had every reason to be. Then we ran our usual audit and found a handful of debug scripts sitting in the public web root. One of them exposed the live database password to anyone who knew its address.
The cause was a single character. The file that's meant to keep secrets out of version control had been saved as gitignore instead of .gitignore. Without the leading dot, the system ignored it completely, and nobody noticed because nothing looked broken.
We start with that story because it explains this whole post. AI website development is now the normal way websites get built, including ours. We use AI tools every working day. So this is not an anti-AI article. What follows is about who's holding the tool, and why a business owner can't see the difference by looking at the homepage.
The short answer: AI can write most of the code for a business website, and it writes it quickly. It doesn't reliably know whether that code is safe, compliant or wired up correctly to your payment gateway and email. A developer who built websites for years before AI arrived can check the output and fix it; someone who has never built one usually can't tell there's anything to fix.
What vibe coding actually is (and where it's genuinely good)
The term comes from AI researcher Andrej Karpathy, and it caught on fast enough that Collins Dictionary named it Word of the Year for 2025. Collins defines it as using AI, prompted in plain language, to write computer code. In practice it means you describe what you want, the AI builds it, and you keep asking for changes until it looks right. You don't read the code. You judge it by what appears on screen.
For some jobs that's a perfectly sensible way to work. We'd happily recommend it for:
- A prototype you want to show investors or your board before spending real money
- An internal tool that three people in your office use, with no customer data in it
- Testing whether an idea is worth building properly
- A personal project, a hobby site, a weekend experiment
Tools like Lovable, Bolt and Replit have made it possible for a non-developer to get a working screen in an afternoon. That's impressive, and we'd be lying if we said otherwise.
The trouble starts when the prototype quietly becomes the production website. It takes card payments, collects personal details on a quote form, sends invoices and stores customer records. The code was accepted because it looked right. Nobody asked whether it was right.
AI writes the code. Experience checks it.
Here's the part that's hard to see from outside. When an experienced developer uses AI, the AI does the typing and the developer does the thinking. They know what the correct answer looks like before the AI produces anything, so they spot a wrong answer in seconds. They also know which questions to ask in the first place, and that's the bigger advantage.
AI answers the question you asked. It rarely volunteers the question you didn't know to ask. Below are six we ask on every build, and none of them show up on a homepage.
Does the payment notification actually get verified?
When a customer pays through a payment processor such as Stripe or PayPal, the processor sends a background message to your site (a webhook, or payment notification) confirming the payment. Your site has to verify that message before it marks the order as paid. We took over a store where customers were paying successfully, the money was landing in the bank, and not a single order was being marked as paid. The verification code was stripping out the gateway's empty fields before checking the signature, so every check failed. The owner thought the problem was customers not completing checkout. It was one line of code.
The opposite failure is worse. If the verification is too loose, someone can send your site a fake "payment successful" message and receive goods they never paid for.
Is the payment gateway in live mode or sandbox mode?
Every payment gateway has a test mode. We've caught a store days before launch with the gateway still pointing at the sandbox. It would have accepted orders, sent confirmation emails and taken no money at all. An AI tool will happily set up sandbox mode for testing. Remembering to switch it over, and checking that the live merchant keys are in place, is a launch checklist item that comes from having launched before.
What's sitting in the web root?
This is the .gitignore story again, and it's the most common thing we find. Test files, database dumps, backup archives, .env files with API keys. AI tools create helper files as they go, and a beginner doesn't know which ones should never be publicly reachable. On one page-builder site we rebuilt, the old backup folder contained SSH keys and database credentials that anyone could download.
Who can reach the admin pages?
A generated admin panel often looks locked because it has a login screen. The question is whether each admin page checks the login itself, or whether typing the direct URL of /admin/orders.php skips the front door. Access control is the kind of thing AI gets right on the page you asked about and forgets on the next five.
Will your emails arrive?
A contact form that "sends" isn't the same as a contact form whose emails reach an inbox. Without correct SPF, DKIM and DMARC records on your domain, inquiries and order confirmations land in spam or vanish. The form works perfectly in testing, because the developer tested it by sending to themselves. Three months later you realize you've had no inquiries since launch.
Does the quote form comply with privacy law?
If a form collects names, phone numbers or other personal details, you're handling personal information, and US privacy laws such as the CCPA/CPRA set rules for the businesses they cover. In practice that means telling people why you're collecting it, getting consent where needed, storing it securely and not keeping it forever. And if that data leaks, state data breach notification laws can require you to tell the people affected. An AI tool won't raise any of this unless you ask, and most people don't know to ask.
There's a seventh we'd add for anyone running a plugin-based site: what happens when a dependency updates? A generated site built on ten packages that nobody has read can break, or open a hole, the day one of them changes. Someone has to know what's in there.
What the research says about unchecked AI code
Our experience is one thing. The independent research points the same way, and it's been consistent for two years now.
The code compiles, but fails security tests about half the time. Veracode has been testing AI coding models since 2025. Its Spring 2026 update found that over 95% of generated code was syntactically correct, yet only 55% passed security checks. On cross-site scripting, a classic website vulnerability, the pass rate was 15%. Veracode's July 2026 report, covering more than 100 models, put the average at 56%. The models are getting better at writing code that runs. They aren't getting much better at writing code that's safe.
Live vibe-coded apps leak secrets. Security firm Escape scanned 5,600 publicly deployed apps built on platforms such as Lovable, Base44 and Bolt.new. It found more than 2,000 vulnerabilities, over 400 exposed secrets like API keys, and 175 cases of exposed personal information, including medical records and bank details. These weren't lab experiments. They were real apps with real users.
Asking the AI to "improve" the code can make it worse. A study of 400 code samples put through repeated rounds of AI refinement found a 37.6% increase in critical vulnerabilities after just five iterations. That's exactly how vibe coding works: keep asking for changes until it looks right. Each round can quietly undo a safeguard from the round before.
The problem is reaching public vulnerability databases. Researchers at Georgia Tech's Systems Software & Security Lab traced 74 published security vulnerabilities directly to AI coding tools. Eighteen came in the second half of 2025. Thirty-five came in March 2026 alone.
None of this says AI is bad at code. It says AI code that nobody qualified has checked is a coin flip on security. That's a fine risk for a prototype. It's a poor one for the site that holds your customer list.
AI plus experience vs AI plus no experience
Both people in this table are using the same AI tools. The difference is what they bring to it.
| AI + 10 years of building websites | AI + no website experience | |
|---|---|---|
| Security | Reads generated code, knows the common holes, checks the web root before launch | Trusts that working means safe |
| Speed | Much faster than before AI, because checking is quicker than writing | Fast to a first version, slow once something breaks and the cause is unclear |
| SEO structure | Plans headings, page hierarchy, schema and internal links before building | Gets whatever structure the AI chose, often one long page of divs |
| Payments | Tests payment notification verification, failed payments, refunds and the live-mode switch | Tests one successful payment in sandbox |
| Privacy and forms | Consent wording, secure storage, spam protection, retention rules | A form that emails someone |
| Hosting and email | Server hardening, backups that restore, SPF/DKIM/DMARC set on the domain | Whatever the platform defaults to |
| When it breaks at 9pm | Reads the error log and knows where to look | Pastes the error into the AI and hopes |
| Who you call | A team with a support process | The person who built it, if they answer |
Honestly, the speed row surprises people most. The inexperienced builder is often faster for the first week. After that the lines cross, because every problem becomes a guessing game and every fix risks breaking something else.
How we use AI when we build websites
We'd be doing our clients a disservice if we didn't use AI. It makes our team faster, and that saves clients money. Here's where it earns its place in our workflow:
- First drafts of code, especially repetitive markup like product grids, form layouts and page templates
- Writing test cases we'd otherwise skip for time
- Debugging: pasting an obscure error and getting three likely causes in seconds
- First drafts of page content, which a human then rewrites for the client's voice and facts
- Research, like checking a payment provider's current documentation or a browser quirk
And here's where a human always signs off, no exceptions: anything touching security, anything touching payments, anything touching customer data, and the final design judgment. AI can suggest a layout. It can't tell you whether that layout will make an engineering firm's buyers trust them.
Two things let us stand behind AI-assisted work in a way a solo builder usually can't. First, our servers are managed by our own in-house Unix team, not outsourced, and they've kept uptime above 99% over the past five years. When something odd happens on a server, the people looking at it are the people who configured it. Second, every site comes with a lifelong functionality guarantee: if the site breaks because of our code or our build, we fix it free. We couldn't offer that if we were shipping code we hadn't read.
If you want to see what's included when we build, our website design packages list it plainly: on-page SEO, conversion tracking, speed optimization, security configuration and spam protection come as standard. For the numbers, see our packages and USD pricing. For online stores, the e-commerce website page covers payment processor integration and testing. We've written more about the day-to-day side in how we use AI to build websites.
Questions to ask any web designer about AI
You don't need to read code to find out whether someone knows what they're doing. Ask these in your first meeting. The answers tell you a lot, and a good designer won't mind the questions.
- Do you use AI, and who reviews what it writes? "No, never" is either untrue or a sign they're slower than they need to be. "Yes, and it's fine" is a worry. You want "yes, and here's who checks it and what they check".
- Whose name will the domain, hosting and ad accounts be in? The right answer is yours, every time. If a builder disappears, you shouldn't lose your website with them. We've covered this in detail in who actually owns your website.
- How do you test the payment flow before launch? Listen for sandbox testing, live-mode switchover, failed payments and notification verification. If they only mention "we do a test purchase", keep asking.
- How do our forms handle privacy? They should talk about consent, where the data is stored and who can see it.
- If the site breaks in eight months, what happens and what does it cost? A clear answer with a named process beats a vague "we'll take care of it".
- Who else knows how my site works? If the answer is one person, think about what happens when that person goes on vacation.
If you're comparing agencies more broadly, our guide on how to choose a web design company goes further.
So should you use an AI-built website?
For a prototype, an internal tool or a site that doesn't take payments or personal information, an AI-built site can be a sensible, cheap choice. We'd tell you that in a meeting.
For a business site that collects inquiries, takes money or stores customer data, assume AI was used somewhere. It almost certainly was. What you want to know is whether someone who knows what a safe, working site looks like read the code before it went live.
Picture the version where that happened. Orders mark themselves as paid. Inquiries land in the right inbox. The admin area stays private. No regulator ever has reason to write to you. Nothing about that is visible on the homepage, which is exactly the point.
If you'd like a second pair of eyes on your current site, whoever built it and however, send us the link. We'll tell you honestly what we'd change, and what we'd leave alone.
Frequently asked questions
Can AI build a business website on its own?
AI can generate most of the code and content for a business website in hours. What it can't do reliably is confirm that the site is secure, compliant with privacy laws and correctly connected to payments and email. Independent testing by Veracode in 2026 found AI-generated code passed security checks only about half the time, so a qualified person still needs to review it.
Is vibe coding safe for an e-commerce store?
Not without an experienced review. E-commerce involves payment notifications, customer records and order data, and those are exactly the areas where unchecked AI code tends to fail. Vibe coding is fine for a prototype of the store, but the version that takes real money should be checked line by line where payments and customer data are involved.
Will AI replace web developers?
It's taking over a lot of the typing. The judgment still sits with people. Experienced developers using AI are faster than they've ever been, because checking code is quicker than writing it from scratch. The skill that matters more now is knowing what correct, safe output looks like.
How can I tell if my website was built with unchecked AI code?
You usually can't from the front end, which is the problem. Signs worth checking include test or backup files reachable in the browser, forms without clear consent wording, order or inquiry emails landing in spam, and a builder who can't explain how payments are verified. A proper audit of the files and server configuration is the reliable way to know.
Does using AI make a website cheaper?
It can, because it cuts the hours spent on repetitive work. The saving is only real if someone experienced checks the output. Fixing a leaked database or a broken checkout after launch costs far more than the time AI saved.
Sources
- Veracode: Spring 2026 GenAI Code Security Update (March 2026)
- Veracode 2026 GenAI Code Security Report announcement, Business Wire (July 2026)
- Escape: Methodology, 2k+ vulnerabilities in vibe-coded apps (October 2025)
- Shukla et al.: Security Degradation in Iterative AI Code Generation (arXiv)
- Georgia Tech Research: Bad Vibes, AI-Generated Code Is Vulnerable (April 2026)
- Collins Dictionary: Word of the Year 2025 (November 2025)