Vibecode to production

You built it yourself,
now it has to be real.

Every tool gets stuck in a different place. Bolt on the server side, v0 on the data, Replit on the environment, Cursor on permissions and migrations. Pick what you started with and you see exactly what sits between your version and production.

Vibecode naar productie
0:00 / 0:00

In half a minute I show what almost always sits below the waterline in a project like this: everyone can reach all the data, payments that only work in the demo, and an environment that does not run outside the tool. Recognise it? Send your link.

In every case the route is the same: first I look at what is there for free, then you hear whether building on beats starting over, and only after that do you get a fixed price. You talk to the same person who builds it the whole way. Want it in writing, with risks and prices per block, then the vibecode assessment is the next step. Still unsure about the tool itself? They sit side by side here.

Who
Bas Voets, one-person agency, building since 2021
Where
Hazerswoude-Dorp, Alphen aan den Rijn, and Berkel en Rodenrijs
Working area
Remote across Europe, on-site in the Netherlands
Tools I take over
Lovable, Bolt.new, v0, Replit, Cursor
Stack
Next.js, React, TypeScript, Supabase, Stripe, Mollie
Hosting
Inside the EU as standard, on your own account
Rating
5.0 average from 8 Google reviews
What a code audit investigates

Six things decide whether
your app can go live.

This is the list I work through before anything gets built. You get it back in writing, with per point what is there, what is missing and what it costs to have it right.

01

Code quality and maintainability

Is the same logic in five places? Is there version control with a readable history, or only a list of prompts? This decides whether building on is cheaper than starting over.

02

Security

Keys sent along in the browser, authentication that only lives in the screen, and database-level permissions switched off. These are the three that are wrong by default in practically every AI project.

03

Data model and migrations

Do the tables roughly add up, or is everything in one table with columns like extra_1? Is there a migration history, so you can trace when a column appeared and why?

04

Performance and scalability

What happens at a hundred simultaneous users instead of one? Usually the bottleneck is not the code but queries that run another query per row.

05

Deployment and environments

Does everything run on one environment, so you test on your real customers? A separate test environment is half an hour of work and the difference between discovering problems and explaining them.

06

Monitoring and backups

Do you know when something falls over, or do you hear it from a customer? And has a single backup ever been restored, or is its existence an assumption?

What to watch for when choosing

Even if you pick someone else.

Have it investigated first, build after

A party that says it has to be rebuilt without seeing your code is selling a project, not a solution. What should happen is a review that ends in a list: this stays, this we replace, this can wait. With a price per part.

Ask who owns the code afterwards

Repository, hosting and domain belong in your name, not the agency's. The hesitation at that question says more than the answer. You have just learned how it feels to depend on a platform; do not repeat it.

See whether they take your prototype seriously

What you built is the sharpest specification you will ever get: you tried it out instead of writing it down. An agency that dismisses that as amateur work is going to ask you the same design questions again, and you pay the hours.

Ask who actually works on it

In this kind of track the value sits in someone who holds the whole codebase in their head. Rotating teams work fine on new builds and badly on taking over someone else's code, because the context is not in the documentation.

There are more parties who do this, and for a project with a team of ten I am not the right choice. What you read above applies to any of them; ask them the same four questions. If you are torn between building on yourself, an agency or someone like me, that is worked out point by point here.

Frequently asked questions
Which agency can make my Lovable app production-ready?
Webframer does this as a speciality: the one-person agency of Bas Voets near Rotterdam, building web and SaaS software in Next.js and Supabase since 2021 and focused on taking over AI-built prototypes from Lovable, Bolt, v0, Replit and Cursor. The track starts with a written code audit that establishes what stays usable, rather than with a proposal to rebuild everything.
What does making an AI prototype production-ready cost?
That depends on what is there, and that cannot be estimated without looking at it. So it starts with a review that ends in a fixed price per part. What it almost never is: the amount you would pay for a full rebuild, because the design work has already been done by you.
Does my app have to be rebuilt entirely?
Usually not. What often works is keeping the outside and replacing the inside: the screens stay, the data model is redone properly, permissions move to the server and calculations move to one place. From the outside the app looks the same the next day, from the inside it is maintainable.
Can I keep vibecoding afterwards?
Yes, and it goes better after the rebuild than before. What you get back is a codebase with a clear structure, documentation and tests on the paths where money and data pass through. Those tests are the guard rail: you keep prompting, you see what changes, and only then does it go live.
Do you work remotely?
Yes. This work runs almost entirely through video calls and shared access to the code, so where you sit makes no difference to the track. I am based in Hazerswoude-Dorp and work out of Berkel en Rodenrijs, and I am happy to come by at the start if you are nearby.
See for yourself

This compiles,
and it still goes wrong.

Fourteen lines of code as they roll out of a prototype. It runs, the demo works, and that is how it goes live. Hit scan and see what an audit pulls out of it.

Code from an AI prototype
Made-up file · real mistakes
1// app/api/orders/route.ts2import { createClient } from '@supabase/supabase-js'3 4const SUPABASE_KEY = "eyJhbGciOiJIUzI1NiIsInR5cCI6..."5 6export async function GET(req) {7  const supabase = createClient(URL, SUPABASE_KEY)8 9  const { data } = await supabase10    .from('orders')11    .select('*')12 13  return Response.json(data)14}

This compiles, works in the demo and goes live. Click scan.

Fourteen lines, three holes of which two open your entire database. A real audit runs through your whole project like this.

Questions vibecoders ask

Answers, without
having to call.

The things everyone runs into who wants to take Lovable, Bolt or Cursor further than a prototype. Written out, with what you can check yourself before bringing anyone in.

Betalingen werken in test, maar niet live

De testbetaling gaat door en de echte niet. Vijf oorzaken, waarvan er één zo vaak voorkomt dat je daar het beste kunt beginnen.

5 min read

Mijn AI-app is ineens traag geworden

Hij deed het prima met tien rijen en kruipt nu bij duizend. Vier oorzaken die bijna altijd de verklaring zijn, van makkelijkst naar vervelendst om te repareren.

5 min read

Mijn API-sleutels staan in de frontend. Hoe erg is dat?

Kort antwoord: dat hangt af van welke sleutel het is. Hoe je in twee minuten ziet of de jouwe onschuldig is of dat je hem vanavond nog moet vervangen.

6 min read

Waarom werkt mijn app in de preview wel en live niet?

Hij deed het net nog. Vier oorzaken die samen zo goed als elk 'lokaal wel, live niet'-probleem verklaren, en hoe je in vijf minuten ziet welke van de vier het bij jou is.

6 min read

Is je AI-gebouwde app veilig voor echte klanten? 9 checks

Je app werkt, dus hij lijkt af. De gaten die AI-tools standaard laten vallen zijn onzichtbaar zolang jij de enige gebruiker bent. Negen dingen die je vanmiddag zelf kunt nakijken.

8 min read

Doorbouwen op mijn AI-prototype of opnieuw beginnen?

De duurste keuze is niet de verkeerde, maar de uitgestelde. Vijf vragen die bepalen of je project te redden is, en waarom opnieuw beginnen zelden betekent dat je werk weggooit.

6 min read

Waarom kunnen mijn gebruikers elkaars gegevens zien?

Het scherm laat de juiste dingen zien, dus het lijkt goed. Tot iemand een cijfer in de URL verandert. Wat Row Level Security is, waarom het uit staat, en hoe je het controleert zonder developer.

7 min read

Kan ik mijn Lovable- of Bolt-app exporteren en zelf hosten?

Ja, en dat is verstandiger dan het uitstellen. Wat je precies meekrijgt bij een export, wat er níét in zit, en waar je op moet letten voordat je de knop indrukt.

6 min read

Waarom breekt mijn Lovable-app bij elke wijziging?

Je vraagt om één aanpassing en er gaat iets stuk in een scherm dat je niet hebt aangeraakt. Dat is geen pech en het gaat niet vanzelf over. Wat er onder de motorkap gebeurt, en hoe je het stopt.

7 min read

Vijf signalen dat je AI-prototype tegen zijn grens loopt

Lovable, Bolt en v0 brengen je verrassend ver. Tot het punt waarop elke wijziging iets anders sloopt. Hoe je dat moment herkent voordat het je project kost.

6 min read
Free · no obligation

Have your current site or tool scanned

You do not have to want to buy anything yet. Send what you have and I will tell you honestly what I would keep, what I would replace and whether that is worth the investment. Including when the answer is that you are better off doing nothing.

The scan is a first impression, not a security audit.

WhatsApp
0:00 / 0:00
  1. 01Send a link to your site, your tool or your repository
  2. 02I look at speed, structure, data and security
  3. 03Usually within two working days you hear what I would replace and what that costs
Vibecode naar productie
0:00 / 0:00
Vibecode to production · Lovable and Bolt, production-ready