Skip to content

How Much Does It Cost to Fix a Vibe-Coded App? Audit to Rewrite Prices (2026)

The cost to fix a vibe-coded app from Lovable, Bolt or Cursor, in EUR: price ranges for an audit, a security cleanup and a rewrite, and what drives them.

By

Freelance full-stack developer

Published
Reading time
12 min
In this post9

The cost to fix a vibe-coded app usually falls into four bands: €800-3,000 for a technical audit, €1,500-4,000 to close the urgent security holes, €4,000-12,000 for a full production-ready cleanup, and new-MVP money (roughly €10,000-40,000) if the app has to be rebuilt. Those figures assume a senior European developer at about €100 an hour, and they hold whether the app came out of Lovable, Bolt, v0, Replit or Cursor.

I sell this kind of work myself, so weigh my numbers with that in mind. It's also why I've included the cases where you shouldn't spend anything yet.

The short answer: four price bands

What it costs to take an AI-built app to production (rough estimates, excl. VAT)
AuditSecurity fixesProduction-ready cleanupRebuild
What you getCode and database review, security check, ranked findings and an estimateAccess rules, secret keys, auth and payments made safeSecurity fixes plus staging, tests, migrations, backups and monitoringA new codebase built from the prototype, including moving users and data
Hours8-3015-4040-120100-400
Cost at €100 an hour€800-3,000€1,500-4,000€4,000-12,000€10,000-40,000
Calendar time, one developer1-4 days1-2 weeks2-6 weeks1-4 months
Right for you whenYou want to know where you stand before spending moreReal users are coming soon and the app has few rolesThe app will take payments and hold personal data for the long haulThe data model is wrong, or the app must do far more a year from now

The hours are my rough estimates for an experienced developer working on a small to mid-sized app: up to about 20 database tables and two or three user roles. €100 an hour isn't my rate. It's a round number inside the €75-120 range that Lancebase reports for freelance full-stack developers in Western Europe, so you can scale it to whatever quote you get. Rates in Denmark tend to sit at the top of that range or above it, which I cover in my post on freelance developer rates in Denmark.

If you're budgeting for more than the fix, my overview of what software development costs puts these numbers in context.

What each band gets you

The bands stack. A production-ready cleanup includes the security fixes, and a rebuild almost always starts with an audit. I've covered the process itself in my step-by-step guide to taking a vibe-coded app to production. This section is about price: what you pay at each stage, and what you get back.

The audit: 8-30 hours

An audit is the cheapest place to start, and it's where most money gets saved. The developer reads through the code, the database and the hosting setup, then hands you a list of problems ranked by severity, with an estimate for fixing each one.

A useful audit answers three questions. Can users see data that isn't theirs? Are secret keys sitting somewhere they shouldn't be? And is the code worth saving, or does it need a rewrite? The answer to that last one moves your total more than anything else in this post.

Size drives the range. An app with one user type and no payments can be reviewed in a day. Add roles, payments and a few integrations, and it takes longer, because every access rule has to be tested as well as read.

Security fixes: 15-40 hours

This is where the holes that can cost you data and trust get closed. Typical work:

  • Access rules on every table so each user only sees their own records. In Supabase, which Lovable often uses as its database, this is called Row Level Security.
  • Secret keys moved out of the browser, and rotated if they were ever exposed.
  • Sign-up and login made ready for real users: email confirmation, password reset and correct redirect URLs.
  • Payment status checked on the server, so nobody can get a paid plan for free by tampering with the browser.

This isn't a problem with one particular tool. When Veracode tested code from more than 100 language models, 45% of the samples failed its security tests, and newer models did no better than older ones (Veracode 2025 GenAI Code Security Report). Assume there's security work to do, even if the app seems to run fine.

Production-ready cleanup: 40-120 hours

This is what it takes for the app to keep running for months and years after the demo. Here's where the hours usually go:

TaskHours
GitHub, a staging environment and a repeatable deploy process4-10
Access rules and secret keys8-20
Auth, roles and password flows4-12
Payments and payment provider webhooks0-15
Data model, migrations and data cleanup6-20
Automated tests for the critical flows8-20
Hosting, backups, monitoring and error logging6-15
Documentation and handover4-8
Total40-120

Payments start at zero because plenty of apps don't take money yet. Subscriptions with trials, cancellations and failed cards push you toward the top of the range.

The line item that tends to surprise founders is the data model. If the AI tool stored the same information in three places, or put several customers' records in one table with nothing to separate them, that has to be fixed before more data goes in. It only gets more expensive the longer you wait.

Rebuild: 100-400 hours

If the data model is wrong, or the app needs to do much more in a year than it does today, starting over on an established framework such as Laravel or Next.js can be the cheaper path. Expect new-MVP pricing, which I break down in my post on MVP development cost.

Rebuilding a vibe-coded prototype is still cheaper than a blank-page project, for two reasons. The prototype shows exactly what the app has to do, so discovery is faster. And the screens and flows have already been tried out, so less time goes into design. On the other hand, if the app has live users, migrating their accounts and data adds hours.

There's a middle path too: replace the app piece by piece, say authentication and billing first, while the rest keeps running. On price, it lands between a cleanup and a full rebuild.

What moves the price up or down

The number of screens rarely decides the bill. What decides it is how much is at stake if something breaks, and how messy the foundation is.

FactorCheaperMore expensive
User rolesOne user typeSeveral roles with different permissions
PaymentsNone, or a simple payment linkSubscriptions, trials and platform fees
DataNo personal dataPersonal, health or financial data
IntegrationsNoneAccounting, CRM or calls to AI models
Data modelA few tables with clear relationshipsDuplicated data, customers mixed together
BackendStays on SupabaseMoves to your own server, e.g. Laravel
Hosting regionAlready where your customers expect itData has to move to an EU region
Current usersNone, test data onlyPaying customers whose data must survive

Roles and the data model move the price most. Every role needs its own rules, and every rule has to be tested with a user who shouldn't get in, not only with one who should.

The tool you built with matters less than people expect. Lovable, Bolt and v0 typically produce a React front end with a hosted database behind it, so the problems look alike across them. Cursor is different: it's an editor, and the code could be in almost any stack. There, price depends more on which stack was picked and how consistently it was used.

If you sell to European businesses, expect them to ask where their data is stored. When the database was set up in a region outside the EU and customers want it inside, moving it is a migration job with its own estimate.

Your own involvement counts as well. If you can quickly answer who should see what, and what the app needs to do in six months, fewer hours go into back-and-forth.

The price of shipping it as is

Putting off the fix isn't always the cheap option. Launch without it, and three bills tend to arrive:

  • A data leak. If the app holds personal data about people in the EU, an exposed table can trigger GDPR's breach notification rules, and you'll have to explain to users what happened. That cost doesn't show up in an hourly estimate.
  • Prompt loops. When every fix breaks something else, you pay for credits and your own time without moving forward.
  • A cleanup with users on board. Fixing the data model is harder once real data lives in it, because everything has to be migrated without losing a record.

My rule of thumb: get an audit before you invite your first real users, and close the security holes before you take payments or personal data.

When you shouldn't pay for this yet

Not every AI-built app needs fixing right now. Hold on to your money if:

  • The app runs on test data and exists to show the idea to customers or investors.
  • You don't know yet whether anyone will use it. Spend the money finding out first.
  • It's an internal tool for a handful of colleagues with no personal data. Switch on access rules and leave the rest for later.

A solo freelancer like me isn't always the right hire either. If the app needs a full-time team from day one, or a new brand, copy and marketing at the same time, an agency or an in-house developer is a better fit.

Does it matter where your developer is based?

On the hourly rate, yes. On the total, less than you might think. A senior freelancer in Western Europe typically charges €75-120 an hour, and offshore rates are often much lower. But an audit and a security cleanup are mostly about understanding your app and asking the right questions, so the cheapest hour doesn't always buy the cheapest fix.

If your users are in Europe, two things are worth weighing:

  • Access to personal data. A developer working in your production database processes personal data on your behalf, and GDPR Article 28 requires a written agreement with them, usually called a data processing agreement. If they're based outside the EU, the rules on international data transfers typically apply on top.
  • Working hours. Fixes involve lots of short questions about who should see what. A developer on Central European Time overlaps with nearly all of the UK and EU working day, and with mornings on the US East Coast.

Running costs after launch

The cleanup is a one-off. After that come the recurring costs:

  • Hosting and database. Supabase's free plan has no backups and pauses projects after a week of inactivity, so an app with real users belongs on the Pro plan, which starts at $25 a month according to Supabase's pricing page. Add front-end hosting, transactional email and any AI usage on top.
  • The builder itself. If you keep building in Lovable or Bolt, the subscription keeps running.
  • Maintenance. Dependencies need updating and new vulnerabilities need patching. As a rough estimate, a small app needs 3-10 hours a month, more if you're also shipping features. A retainer makes that predictable, and I compare the common setups in my post on developer retainer agreements.

Next steps: how to get a quote you can trust

  1. Get the code into GitHub. Lovable can export and two-way sync your project with GitHub (Lovable's GitHub integration docs), which is the easiest way to give a developer access without sharing your login.
  2. Write half a page on who uses the app, what data it stores and whether it takes payments.
  3. Ask for a fixed-price audit before you agree to a cleanup. It works like a paid discovery phase, and I've explained why a scoped discovery phase pays for itself.
  4. Ask for the estimate broken down by task, as in the table above, so you can choose what gets done now and what waits.
  5. Close the security holes first, and phase the rest.

On my service page for taking AI-built apps to production you can see how I run audits and cleanups. You work directly with me, the developer who reads and writes the code, and you own the code from day one.

Frequently asked questions

Can I get a fixed price for the cleanup without an audit?

You can, but it rarely comes cheap. Without an audit, a developer can't know whether the data model holds up or how many access rules are missing, so a fixed quote has to carry a large buffer for the unknown. A fixed-price audit first gives you an estimate with far less padding, and you can use the report to get competing quotes.

Can I keep building in Lovable after a developer cleans it up?

Yes, in most cases. With GitHub sync, you and a developer can work in the same codebase. Agree on a clear split, though: changes to the database, access rules and payments go through the developer, while you're free to prompt copy, layout and new screens. Otherwise one prompt can quietly undo part of the security work.

Do I have to move off Supabase to go to production?

Not necessarily. Supabase is a managed Postgres database with built-in auth and file storage, and plenty of apps run on it in production once the access rules are right. Moving the backend makes sense when the business logic gets complex, when you need background jobs and integrations that don't belong in the browser, or when you want a conventional framework a new developer can pick up. Treat it as a separate decision with its own estimate.

What happens if the audit finds a data leak?

The hole gets closed first, and any keys that may have leaked are rotated. If personal data was actually exposed, GDPR Article 33 requires you to notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to put people at risk. This isn't legal advice, so check with a lawyer or your data protection officer.