Field notes

Vibe coding your business website: The three bills that come due

Web Design

what we found when we opened it

, Mohali, India · · 5 min read
8+ years building websites, 40+ sites launched. We do the work on every project ourselves, from the first call to launch.

Vibe coding is the name that stuck for describing what you want in plain language and shipping whatever the model produces, without reading it. As a way to find out whether an idea is worth building, it is genuinely good. As a way to build the website your business runs on, it moves cost rather than removing it — and it moves the cost forward, into a year when you have customers depending on the thing.

Is vibe coding safe for a business website?

For a prototype, yes. For the site that takes your bookings and payments, no — not without somebody reading the output. Veracode’s 2026 GenAI Code Security Report found that roughly 44% of AI code generation tasks introduced a risky security vulnerability, and that the rate has not improved year over year.

The first bill: security you cannot see

Insecure code looks exactly like secure code from the front end. The page loads, the form submits, the confirmation appears. Nothing tells the owner that the contact form will hand a visitor’s browser to whoever asks, because the failure only shows when somebody goes looking for it.

Veracode tested more than a hundred models across a standard set of coding tasks and published the pass rate per vulnerability class. The spread is the part worth reading twice: models passed SQL injection tasks 83% of the time and cryptographic algorithm tasks 87% of the time, but cross-site scripting only 15% of the time and log injection only 12%. Their best performer, at 68% overall, still failed roughly one security task in three.

Cross-site scripting is not an exotic threat. It is the flaw that lives in exactly the places a small business site has: a contact form, a search box, a review field, anywhere a visitor types something that is later displayed. It is the single most likely defect in a generated site and the one the models are worst at.

Veracode’s own summary of the trend is the sentence to keep: syntax is effectively solved, at close to a hundred per cent, while secure coding is not following the same curve. The code will run. That was never the question.

The second bill: a codebase nobody can change

A website is not finished when it launches. You will want a new service page, a price change, a booking integration. What decides whether those cost hundreds or thousands is not the original build — it is whether the code underneath can be altered without breaking something else.

GitClear analysed 623 million code changes between 2023 and 2026 and published what happened to maintainability over that window. Duplicated lines rose 81% to the highest level in their record. Refactored or moved code — the work of tidying something rather than re-typing it — fell from 21% of changed lines in 2022 to 3.8% in 2026. Copy-paste went the other way, from 9.4% to 15.7%.

In a small-business site that arithmetic has a physical meaning. If your phone number is written into nine places instead of one, changing it is nine edits and one of them gets missed. If your booking button is nine slightly different buttons, the fix you pay for on Tuesday reappears on Thursday somewhere else.

GitClear also measured a 47% rise in error-masking constructs — code that catches a failure and quietly carries on. That is the mechanism by which a site keeps looking fine while the enquiries stop arriving.

The third bill: the confidence gap

The most uncomfortable finding is not about the code. Researchers at Stanford ran the first large-scale user study on this and published it at ACM CCS: participants with access to an AI assistant wrote significantly less secure code than those without — and were more likely to believe their code was secure.

That is the part that makes vibe coding a business risk rather than a technical one. A bad outcome you know about gets budgeted for. This one arrives with confidence attached, which means it does not get budgeted for at all, and the first time anybody looks closely is after something has gone wrong.

The same study found the counter-move, and it is not “stop using AI”. Participants who trusted the assistant less and worked harder at their prompts produced fewer vulnerabilities. Scepticism was the variable that mattered.

What this means if you are buying, not building

Most owners reading this are not writing prompts themselves. They are choosing between a builder that advertises a site in minutes, an agency that quotes unusually low, and a studio that quotes normally. The evidence above does not tell you to avoid AI. It tells you exactly one thing: ask who read the code.

What you are told What to ask instead
“Built with AI, so it is faster and cheaper” Who reviewed the output, and what did they change?
“It passes all the tests” Were any of those tests security tests?
“You can edit it yourself” Show me the same change made in two places at once.
“It scores well on speed” Show me the score on a phone, on real data.

A studio that reads its own output will answer all four in a sentence each. One that does not will change the subject to how modern the stack is.

How to check the site you already have

You do not need a developer for the first answer. Open your contact form, type a quotation mark followed by a word into the name field, submit it, and read the confirmation page. If your input comes back onto the screen unchanged, that is the handling behind the cross-site scripting class Veracode’s models passed only 15% of the time.

Then check the boring things: does every image have alternative text, does every form field have a label, does the site still work with images blocked. Our free nine-point audit runs those and reports in public, and you can run it on any site including ours.

If the site came out of Lovable, check one more thing: 18 of the 36 Lovable sites we fetched sent crawlers an empty page, and fixing SEO on a Lovable site is a job we take on by itself.

The honest version of the trade

AI writes a great deal of the code in the world now, including in serious engineering teams, and pretending otherwise would be silly. The difference between those teams and a vibe-coded business site is not the tool. It is that somebody whose job is to be suspicious reads every line before it reaches a customer.

If nobody in the chain between the prompt and your homepage had that job, you did not save money. You deferred it, at interest, to a version of yourself who will be busier.

What a rebuild costs when that bill lands is set out in what it costs to fix a website AI built, and our own brackets are on the price list, in public, starting at $999.

Vibe coding your business website: The three bills that come due

Shelf
Web Design
Read
5 min
Written
21 Sep 2026
The signs your website is costing you work Small-business website examples: Three rebuilds, and what actually changed What each price bracket actually buys What is actually in a web design package (and what to watch for) How much does a website cost in Canada? (2026 real numbers)
( End of entry )

Want this run on your site?

The same audit these notes come out of, on your pages, with what we would change and what it would cost. After a refundable booking, real work inside 48 hours. Wrong direction? Full refund.

Start a project
One business day to a reply. Live date in writing inside 48 hours.