# Michael Bires — Vibe-Code Rescue & Emergency Web Repair > Senior full-stack engineer. I audit, fix, harden, and deploy broken AI-built apps and hacked WordPress sites. Fixed prices, audit-first. I am a senior full-stack engineer specializing in rescuing AI-generated (vibe-coded) apps and cleaning up hacked WordPress sites. I diagnose before I touch a line of code, work at fixed prices, and harden every project so it doesn't break again. ## Services - [Vibe-Code Rescue](https://michaelbir.es/services/vibe-code-rescue): Your AI-built app works in the demo but breaks in production. - Triage / Audit ($299 — 48 hours): Know exactly what's wrong before spending more. - Priority Fixes ($799 — 3–5 days): The audit plus the fixes that unblock you. - Hardening & Deploy ($1,799 — 1–2 weeks): From fragile prototype to production-ready. - [Web Ambulance](https://michaelbir.es/services/hacked-wordpress-cleanup): Site hacked or down? Get a senior engineer on it now. - Emergency Cleanup ($349 — typically < 24 hours): Full cleanup with the root cause actually closed. - Care Plan (from $79/mo): So this never happens again. ## Fix-it guides - [Works in the Demo, Breaks in Production: The 6 Vibe-Code Failures](https://michaelbir.es/fix/ai-app-breaks-in-production): The six most common reasons AI-built apps (Lovable, Bolt, v0, Replit, Cursor) fail in production — and how to triage them without going in circles. - [How to Deploy a Lovable App to Production (Without It Breaking)](https://michaelbir.es/fix/deploy-lovable-app-production): A production deployment checklist for Lovable apps: custom domains, environment variables, Supabase configuration, and the failures that only appear after going live. - [Lovable App Broke After an Update? How to Recover Without Burning Credits](https://michaelbir.es/fix/lovable-app-broke-after-update): Your Lovable app worked yesterday. After a platform update, a deploy, or a 'security fix' prompt, everything broke. Here's how to triage regressions and when to stop prompting. - [Lovable Emails Not Sending? Fix Signup & Password Reset](https://michaelbir.es/fix/lovable-email-not-sending): Users sign up but never get a confirmation email? Password reset links go nowhere? Supabase's built-in email is rate-limited and lands in spam — here's how to fix it. - [Lovable Google Login Not Working? Fix the localhost Redirect](https://michaelbir.es/fix/lovable-google-login-not-working): Sign in with Google works on localhost but redirects to localhost:3000 on your Lovable preview or custom domain? It's almost always Supabase URL configuration — here's the fix. - [Stripe Webhooks Not Firing After Deploy? Here's How to Fix It](https://michaelbir.es/fix/stripe-webhook-not-firing): Payments succeed but orders never complete? The 5 reasons Stripe webhooks stop firing after you deploy — and how to fix each one. - [Supabase RLS Not Working (or Disabled)? Fix It Before Someone Finds It](https://michaelbir.es/fix/supabase-rls-not-working): Why ~70% of Lovable apps ship with row-level security disabled, what CVE-2025-48757 means for your app, and how to enable RLS without breaking everything. - [Why Google Can't See Your Vibe-Coded Site (And How to Fix It)](https://michaelbir.es/fix/vibe-coded-site-not-indexed-google): AI-built sites are client-side rendered — Google may index an empty shell and AI crawlers see nothing at all. Here's how to check and how SSR fixes it. ## Case studies - [Compromised WooCommerce Store Cleaned & Hardened in Under 24 Hours](https://michaelbir.es/case-studies/woocommerce-hack-cleanup): Three backdoors removed after a scanner plugin failed twice, entry point closed, and the store back online clean — all in under 24 hours. - [CVE-2025-48757: 170+ Lovable Apps With Open Supabase Tables](https://michaelbir.es/case-studies/lovable-supabase-rls-security-audit): Matt Palmer's coordinated disclosure found 303 exposed endpoints across 170 Lovable projects — including Linkable, a Lovable marketing site. What happened, what leaked, and how I fix the same pattern for founders. - [Documented: Stripe Bypass on Linkable (CVE-2025-48757 Follow-Up)](https://michaelbir.es/case-studies/lovable-stripe-webhooks-saas): Matt Palmer's May 2025 re-test of Linkable showed payments could be marked 'paid' via a direct Supabase POST — bypassing Stripe. The same RLS class of bug breaks legitimate webhook flows in Lovable SaaS apps. - [Documented: Lovable Google Login Redirects to localhost:3000](https://michaelbir.es/case-studies/lovable-google-login-custom-domain): A published Medium walkthrough by Ishwar Rimal (Intuit) describes the exact failure: Google OAuth works locally but redirects to localhost on Lovable preview URLs. Industry triage data puts this at ~15% of broken Lovable deploys. - [Documented: Non-Technical PM Stuck in AI Debug Loops for 3 Months](https://michaelbir.es/case-studies/lovable-production-rescue-after-ai-loop): Andreea Papillon's published 3-part series describes building with AI without dev resources: 90% backend bugs, auth taking 3–5× longer, and Claude/Cursor going in circles for days. The rescue pattern I sell exists because of stories like this. ## Contact - [Contact form](https://michaelbir.es/contact): describe the problem, get a reply within 24 hours - Email: hello@michaelbir.es - LinkedIn: https://www.linkedin.com/in/michael-bires/ ## Optional - [llms-full.txt](https://michaelbir.es/llms-full.txt): full text of every guide and case study in one file