Vibe coding security risks I keep finding in client code
AI agents optimize for code that runs, not code that is safe. Two failures I keep finding in agent-written WordPress code, hardcoded API keys and REST routes with no permission callback, plus the review habits that catch them.