Last week I built an upload form for a Symfony project. With AI helping me write the code, the whole thing took a fraction of the time it normally would. A few years ago, this task alone might have eaten a full day. This time, it took me a minutes.
The form worked. It looked clean. It did exactly what it was supposed to do. I was happy.
Then I looked closer.
Underneath the shiny result, there were a few security problems. Nothing that jumped out at first glance. The kind of thing you only catch if you know what to look for. If I did not have years of experience building web apps, I probably would have shipped it as is.
That thought stuck with me.
Speed Is Not the Same as Safety
AI tools are incredible at helping us move fast. They write working code in seconds. They handle boring, repetitive tasks so we can focus on bigger problems. This is a real gain, and I do not want to pretend otherwise.
But speed hides a trap. A form, a login page, or a file upload can look perfect on the surface and still have holes underneath. The code runs. The tests pass. The client is happy. And none of that tells you whether the app is actually safe.
This is fine if you are experimenting on a side project. Nobody gets hurt if a hobby site has a bug. But if you are building something for a real business, with real customers and real data, those small gaps can turn into a big problem. A single unsafe form can lead to lost data, stolen accounts, or worse.
Why Basics Matter More, Not Less
There is a strange effect happening right now. As AI writes more of our code, understanding the fundamentals of web development becomes more important, not less.
When you did everything by hand, you were forced to think through each piece. Now, a tool can write a form, a login flow, or an API endpoint before you have even finished reading the requirements. That is powerful. But if you do not understand what is happening under the hood, you cannot tell good code from risky code. You are just trusting that it is fine.
Experience is what lets you spot the difference. It is what makes you pause and ask, “wait, what happens if someone sends bad data here?” or “can anyone else access this file?” AI will not always ask those questions for you.
What I Am Doing About It
I want to help close that gap a little bit. Starting soon, I will be writing a series of blog posts about basic web security. Simple explanations, no heavy jargon, aimed at anyone building on the web today, whether by hand or with AI as a partner.
We will cover things like:
- CSRF attacks, and why a form without protection can be tricked into doing things the user never intended
- Cross origin attacks, and why your browser’s rules around this actually matter
- Other common weak spots that show up again and again in real projects
The goal is simple. If you are building something for yourself, have fun and experiment freely. But if you are building something for a business, a little bit of knowledge about these basics can save you from a very bad day later.
AI is a great tool. It just does not replace understanding what you are building. Sometimes going back to basics is exactly what moving forward requires.