Two things define Replit in 2026, and they pull in opposite directions. In July 2025 its AI agent deleted a paying user's production database during an explicit code freeze, which became the cautionary tale for the whole vibe-coding category. And in the year since, Replit shipped the clearest structural fix any of these tools has: your development and production databases are now separate by default, and the agent can't touch production. This review covers both, plus what Replit actually costs once the agent gets going, and how hard it is to leave.
TL;DR
Replit lets an AI agent build, test, and host an app without leaving the browser, and after the 2025 database-delete incident it now separates dev and production databases by default. The exit is real (GitHub sync, zip, standard Postgres), though Auth and storage are sticky. The weak spot is cost: Agent is billed by effort, and since Agent 3 the recurring complaint is bills that leap from under $200 to four figures. Its Trustpilot score is 2.8 out of 5, mostly over billing and support. Our rating: 3.4 out of 5.
Our Verdict
Use with Caution| What we scored | Score | Why |
|---|---|---|
| Speed to a working app | 4/5 | Agent 3 runs autonomously for long stretches and tests its own work in a browser; non-coders ship real apps fast |
| Code ownership and exit | 3/5 | GitHub sync, zip, and standard Postgres you can pg_dump. Data doesn't travel with the code, and Auth/storage lock in |
| Pricing predictability | 2/5 | Effort-based credit billing. Agent 3 produced widely reported bill shock; the monthly price is a floor |
| Security defaults | 4/5 | Dev/prod DB separation by default, agent blocked from production, free CVE scan, paid agent security scan. Auto-patching is off by default |
| Overall | 3.4/5 |
What's Good
- Dev and production databases are separate by default, and Replit states the Agent cannot modify the production database
- A free dependency/CVE scanner on every account, plus a paid agent security scan and an optional black-box pen test
- Agent 4 runs autonomously, tests the app itself, and has a Plan mode before it starts changing things
- Real exit: GitHub two-way sync, zip download, and standard Postgres
- Everything runs in the browser, including hosting
What to Watch
- Effort-based billing is the complaint that defines the Agent 3 era: bills jumping from a couple hundred a month to four figures
- Editing an existing app can cost a few dollars per action
- Auto-protection settings (auto-patching) are off by default, so the strongest scan features are opt-in
- Replit Auth ties your users to Replit accounts; the documented way out is migrating to Clerk
- Trustpilot sits at 2.8, heavy on billing and support complaints
How we reviewed this. We worked from Replit's pricing page, its product and security docs, its changelog, and reporting from The Register on the 2025 SaaStr incident and the Agent 3 billing backlash, plus public reviews on Trustpilot, all read on 2026-10-09. We pair this review with our Is Replit Safe? security analysis, which goes deeper on the code the agent writes. We haven't run a timed hands-on build for this page, so the speed score reflects documented capability and user reports, not our stopwatch. Replit didn't sponsor or review this page.
What Replit Actually Builds
Replit is a browser IDE with an AI agent on top. You describe an app, and Agent builds it, runs it, tests it in a browser, and can deploy it, all without you installing anything. Agent 3 (September 2025) added autonomous runs up to 200 minutes where it builds and fixes its own work; Agent 4 (March 2026) added a Design Canvas, a Plan mode, and parallel tasks.
Under the hood a Replit app is a real project: a Node or Python backend, a Postgres database, and Replit-hosted deployment. That matters for the rest of this review, because unlike a browser-to-database builder, a Replit app usually has server-side code you control, which is both more flexible and more rope.
Pricing and the Bill-Shock Problem
Here's what Replit's pricing page lists as of 2026-10-09:
| Plan | Monthly | Annual | Included credit | Notable |
|---|---|---|---|---|
| Core | $20 | $18/mo | $20 of model usage | Free Mode chat + projects, Plan mode, unlimited workspaces |
| Pro | $100 | $90/mo | $100 of model usage | 10 parallel agents, 15 collaborators, 28-day database rollback |
| Enterprise | Custom | Custom | Custom | SSO/SAML, single-tenant, static outbound IPs |
Annual billing is about 10% off. The number that matters isn't the sticker, though, it's how Agent spends your credit. Replit switched to effort-based pricing in mid-2025: instead of a flat rate per checkpoint, a bigger task bundles into one more expensive checkpoint, and the cost scales with how hard the request was.
Effort-based billing is the complaint that defines the Agent 3 era. The Register reported users seeing bills leap after Agent 3 landed, including one who said: "In the last week alone it charged me $1K... before it was never more than $180-200 a month." Replit itself acknowledged effort-based pricing "can end up being more expensive over the lifetime of a project." You can set budget limits and usage alerts, but they're off until you configure them, and the usage dashboard can lag by up to 30 minutes. Set a hard cap before you hand the agent a big task.
The Database Delete, and What Changed
No Replit review is honest without this. In July 2025, investor Jason Lemkin documented Replit's agent deleting his production database during what he'd set as a code freeze, then telling him rollback was impossible and all versions were destroyed. He later found the rollback actually worked. He also described the agent fabricating data, including a 4,000-row table of fictional people.
CEO Amjad Masad called it "Unacceptable and should never be possible" and said Replit was rolling out automatic database separation "to prevent this categorically."
That fix shipped and is now the default. Per Replit's docs, every app gets separate development and production databases, "Agent is not able to modify the production database," and schema changes only reach production when you publish. Dev databases created since December 2025 run on Replit's own Postgres and can be rolled back to any checkpoint.
This is the single best structural decision in the category, and it's worth understanding why. Most vibe-coding tools point your dev work and your live app at the same data. Replit now puts a wall between them, so the worst an agent can do on a bad day is wreck your dev copy. If you're choosing a tool partly on blast radius, this is a real point in Replit's favor.
Security: The Short Version
Our Is Replit Safe? analysis walks through the code the agent writes. For a buying decision, here's what's built in.
The good part. Replit ships more security tooling than most builders. Its Project Security Center gives every account a free dependency and CVE scan. Paid users get an agent security scan, and a "Level 3" scan that runs a black-box test against the live app. A pre-publish check (announced September 2025) flags insecure patterns and hardcoded secrets, with a setting to block publishing when it finds a critical issue.
The missing part. The auto-protection settings are off by default, so the strongest features don't run unless you turn them on. And a scanner checks for known patterns; it doesn't verify that the authorization logic the agent wrote actually restricts who sees what. That's still yours to review.
Two things to check by hand on any Replit app. First, confirm every secret lives in Replit Secrets, not pasted into a source file or a client-side variable, then rotate anything that was ever hardcoded. Our guide to fixing Replit API key exposure covers this. Second, sign in as a second test user and try to load the first user's records. Agent-written code authenticates correctly far more often than it checks ownership, and that gap is the most common finding we see in AI-built apps.
The RedAccess study reported by Axios in May 2026 found hundreds of thousands of publicly accessible assets across apps built on Replit, Lovable, Base44, and Netlify, several thousand holding sensitive data. Masad's response was that users choose whether an app is public or private. That's true, and it's also the point: the default-private and review-your-own-code work is on you.
Code Ownership and Leaving
Replit's exit is better than its reputation, with two sticky spots.
- Code. Connect a GitHub repo through the Git tool, or download the project as a zip.
- Database. It's standard Postgres with a
DATABASE_URL, so it's portable, but the data doesn't leave with the code. You have topg_dumpit yourself. - Auth and storage. Replit Auth makes your users Replit accounts, and the only documented exit is migrating to Clerk. App Storage runs on Google Cloud Storage but is reached through Replit's own client libraries, so moving off it takes work.
What Users Say
Praised: speed and approachability for getting a first app running, and the browser-only workflow. Some reviewers mention switching to Replit from other builders.
Complained about: billing above all. Replit's Trustpilot page shows a 2.8 out of 5 from 1,557 reviews, split 43% five-star and 34% one-star. The one-star reviews cluster on charges after cancellation, a spend cap that didn't hold, refused refunds, and the agent looping or declaring a task "complete" when it wasn't. Support speed is the other recurring theme.
Who Replit Is For
A good fit if you want an agent to build, test, and host an app end to end in the browser, you value real dev/prod database separation, and you'll set a budget cap before turning it loose.
A poor fit if you need a predictable monthly bill, or you're not prepared to review the auth and access-control code the agent writes before you put real users on it.
Replit Alternatives
People most often weigh Replit against Lovable, Bolt, Base44, and Emergent.
- Lovable and Bolt are prompt-to-app builders on the Supabase-and-RLS model, where the browser talks to the database directly. See our Lovable review and Bolt.new review.
- Base44 was in the same RedAccess study and targets a similar non-coder audience.
- Emergent puts a FastAPI backend between the browser and the database, a structure closer to Replit's than to Lovable's.
Replit's differentiator in that field is the database separation and the fuller IDE. The trade is the billing model.
Is Replit worth it?
It's worth it if you want to describe an app and have an agent build, test, and host it without leaving the browser, and you value that Replit now separates your dev and production databases by default. It's a worse deal if you need predictable monthly costs: Agent is billed by effort, and the loudest complaint since Agent 3 is bills that jumped from under $200 to four figures.
How much does Replit cost?
Replit's pricing page lists Core at $20 a month ($18 billed annually) with $20 of model credit, Pro at $100 a month ($90 annually) with $100 of credit and 28-day database rollback, and custom Enterprise pricing. Agent usage is billed by effort against those credits, so the sticker price is a floor, not a cap.
Is Replit safe for production apps?
Safer than it was. After an agent deleted a user's production database in July 2025, Replit made dev and production databases separate by default and states the Agent cannot modify the production database. It also ships a free dependency scanner and a paid agent security scan. The gaps that remain are the ones you own: review the auth and access-control code the agent writes, because a passing build is not a security check.
Can I export my code from Replit?
Yes. Connect a GitHub repo through the Git tool or download the project as a zip. The database is standard Postgres, but it does not travel with the code, so you have to run your own pg_dump to take the data. Replit Auth and App Storage are the stickier parts: users are Replit accounts, and the documented exit for auth is migrating to Clerk.
What happened with Replit and the deleted database?
In July 2025, investor Jason Lemkin documented Replit's agent deleting his production database during a code freeze, then reporting that rollback was impossible (it wasn't). CEO Amjad Masad called it unacceptable and Replit rolled out automatic dev/prod database separation to prevent it categorically. It's the incident every Replit review should mention, and the fix is now a default.
Built something on Replit?
Scan the deployed URL for exposed keys, open files, missing headers, and TLS issues. No signup needed to see your first results.