From vibe-coded prototype to production: the 25-point checklist
Your AI-built prototype works in the demo. These 25 checks, grouped into ten areas, cover what usually needs attention before real users and real money arrive.
ReadPick your stack and tick off what a real launch needs, from backups and error tracking to legal pages.
Runs 100% locallyYour ticks are saved only in this browser's local storage; nothing is sent to TakeoverWork.
What is your app built with?
Your ticks are saved in this browser only, separately for each stack.
Next step
Describe what works, what's broken and what's left. Developers who finish and rescue projects will contact you.
Post your takeover freeA prototype that works on your screen is not the same as an app that can take real users, real money and real mistakes. This checklist lists what usually separates the two, adjusted for the stack you built on. Choose a stack, work through the items, and export the result to share with your developer or keep with your project notes. Ticks are saved in this browser only.
Each stack shares a common core and adds items specific to that platform.
Lovable / Supabase. Row level security must be on for every table in the public schema, and the service-role key must never appear in front-end code. Run your SQL through the Supabase RLS Checker and your code through the Secret Leak Scanner. Check which backups your Supabase plan includes rather than assuming.
Next.js. Any variable starting with NEXT_PUBLIC_ is bundled into the browser code. Confirm that server-only values do not carry that prefix, that API routes check who is calling, and that preview deployments do not use production data.
Bubble. Privacy rules control who can see each data type; without them, data can be searchable by anyone. Check that the live version, not only the development version, has the changes you expect, and that API workflows exposed to the public are meant to be.
WordPress. Remove unused plugins and themes, keep core and plugins updated, remove admin accounts nobody uses, and make sure off-site backups include both files and the database.
Shopify. Review installed apps and their permissions, remove staff accounts that are no longer needed, and duplicate your theme before editing so you can roll back.
Flutter. Store your Android signing key and its passwords somewhere safe and owned by you, because losing it complicates future updates. Check release builds, not debug builds, and prepare store listings, privacy details and test accounts for reviewers.
The progress bar shows how many items you have resolved, but not all items weigh the same. An unchecked item in authentication, environment variables or backups is a launch blocker. An unchecked SEO item is something to fix in the first weeks. If several blockers are open, launching to a small group first is safer than a public launch.
Use Export Markdown to download the checklist with your ticks and notes, or Print to save it as a PDF from your browser's print dialog. The export is a good attachment for a handover, or a starting point when you brief a developer.
The checklist is a structured reminder. It does not look at your code, your hosting or your store, so it cannot tell you whether an item is really done. Results are guidance, not a security audit.
For the reasoning behind each item, read the prototype to production checklist and why Lovable, Bolt and v0 apps break in production. For WordPress and Shopify, see what to check first in a takeover. For Bubble or FlutterFlow, fix or rebuild helps you decide how much work is reasonable.
If the list keeps growing, or a store keeps rejecting your build (app store rejection help), it may be time for another pair of hands. Post your takeover for free and attach your exported checklist, so developers can see exactly what is left.
In your browser's local storage on this device. It is not linked to an account, so clearing site data, using a private window or switching devices will show an empty checklist. Export to Markdown if you want a copy.
Pick the closest match. A React app on Vite with Supabase fits the Lovable/Supabase list, and most server-rendered web apps fit the Next.js list. The general sections on auth, backups, error tracking and legal pages apply to almost any app.
No. Some items will not apply to you, such as payments in a free app. Mark them as not applicable rather than skipping silently, so the export shows a decision was made.
No. The checklist helps you avoid common gaps, but it does not inspect your app. Results are guidance, not a security audit.
Yes. Export it as Markdown or print it, then share the file. Your developer can tick items off in their own browser, but progress does not sync between people.
Your AI-built prototype works in the demo. These 25 checks, grouped into ten areas, cover what usually needs attention before real users and real money arrive.
ReadThe checks to run before handing a WordPress site or Shopify store to a new developer, so you keep control of access, data, payments and search traffic.
ReadShould you keep improving your Bubble or FlutterFlow app, or start again in code? Work through seven questions to make the call on evidence, not frustration.
ReadAI app builders are excellent for prototypes. These are the gaps that usually appear when a prototype meets real users, real data and a real domain, and how to close them.
ReadMost Lovable apps that break do so for a short list of reasons: auth settings, database policies, keys, deploys, edge functions or payments. Here is how to narrow it down.
ReadMost App Store and Google Play rejections fall into a few familiar groups. Read the message carefully, fix the real cause, and reply clearly.
ReadAn unfinished WordPress site is usually recoverable. Start by securing access and backups, then map the theme, plugins and WooCommerce setup.
Read