Can you build a business website with Lovable?
Lovable will produce a good business website in 2026. What it will not do is decide what the site should say, tell you what it decided for you, or own the result in month seven.
Published:
Quick answer: yes. In 2026 Lovable will produce a business website that looks good, loads fast and gets indexed. So will Bolt, Replit, v0 and the AI inside Wix. We sell the alternative, so read this with that in mind. The argument follows anyway, including the parts where the tools win outright and the part where our way costs you something real.
The product facts here come from the vendors' own documentation and pricing pages, read in August 2026. The security section names its own sources where it uses them: a public vulnerability record and one published scan. The product facts change often, which is one of the points this article makes rather than a caveat about it.
What Lovable is, and what it is not
Lovable is an AI app builder. You describe what you want, it writes code, and you get a working project. Bolt, v0 and Replit do the same job in the same shape, so most of this article covers all four. They were built for software with logins and databases. A marketing website is a small job for them, which is part of why they do it well.
They are not the other thing the phrase "AI website builder" covers, and the two get confused constantly. Wix, Squarespace and Hostinger put AI in front of a template product, and a wizard fills it for you in about a minute. You get a good site inside an account you keep paying for.
Do you own the code Lovable writes? Yes, and it is the strongest thing in the tool's favour. Lovable syncs to GitHub on every plan, including the free one, so the project can leave the platform even when you do not. With AI inside a classic builder, no. What you hold there is a subscription. That difference outlives every feature comparison, so it is the one worth deciding first.
What does Lovable cost?
Lovable, Bolt, v0 and Replit all sit around 20 to 25 US dollars a month at the entry plan. The number tells you almost nothing, because none of them sell you months. They sell you a meter, and each one meters something different.
Lovable bills credits. A small style change costs about 0.50 credits, a landing page with images about 2.00, and a single balance covers building, hosting, the backend and any AI features running inside your live site. Their documentation is blunt about what happens when the balance empties: "Building stops", work in progress pauses, and "Built-in backend services will pause". Bolt bills tokens. Replit bills checkpoints priced by effort. v0 bills tokens too, at its own rates.
Three vendors, three units, no exchange rate between them. Nobody can tell you what a website will cost on any of these platforms, because the meter does not run on the website. It runs on how many attempts you need.
Which raises the variable that actually decides the bill, and it is not the tool.
Is Lovable bad for SEO?
It was, and that argument is now out of date, so we are not going to use it.
Until recently these tools shipped single-page apps that arrived at a crawler as an empty shell. Lovable changed that on 13 May 2026: new projects render on the server, and every request returns rendered HTML. Older projects get pre-rendering for verified crawlers instead. The visibility problem people still repeat in forum threads was real and got fixed.
What did not get fixed is the quiet half. Lovable's own documentation says it plainly: "Sitemaps, robots.txt, metadata, and other SEO elements are not always generated up front." Those are the parts of a website that produce customers and the parts you can never see, which is a bad combination when the only person checking is you. Nobody prompts for a sitemap. You would have to know it was missing.
The tool agrees with you
Every one of these products exists to do what you asked. That is the entire feature. It is also the problem, and it is the one nobody writing about them raises.
An AI builder will never tell you that your homepage leads with the wrong thing. Ask it for a hero that says "Your partner for digital solutions" and you get a beautiful hero that says nothing, in about nine seconds. Ask a supplier who has looked at forty other businesses in your position and you get an argument first.
We prepare several design directions from your questionnaire before the kickoff, and you choose one in the meeting. That sounds like a scheduling detail. It is not. Choosing between prepared options is a different mental act from judging an endless stream, because prompting has no end state built into it. Ask twice, get two different websites, both fine. There is nothing to converge on, so you re-roll instead of deciding, and re-rolling feels like progress.
Nothing tells you when to stop
A builder has no handover. No date, no moment when the work stops being yours, no state that a second person agreed to.
This is why "I built our site in a weekend" is so often followed by six months of Sunday evenings. The project never closed. It cannot close on its own, because closing needs someone else to declare the work over and to carry the consequences of declaring it.
Our whole product is named after that moment. Startklar is a state your website reaches on a date you agreed at the kickoff, and if we miss the date you get €500 back. Anyone can get a website now. What is still hard to buy is the end of the project.
You are the one person who cannot see it
Once you have prompted your website into existence you can never read it as a stranger again. You know what you meant, so you see what you meant. The most useful thing an outsider brings to your website is not design or code. It is not knowing your business.
The same blind spot hides breakage. A self-built site fails in ways its owner never notices, because the owner arrives knowing where everything is:
- The contact form that stopped delivering when a key expired
- The consent banner that blocks your own analytics, so you conclude nobody visits
- The link preview that renders as a grey box in every WhatsApp message
- The sitemap still offering Google a page you deleted in March
None of that shows up when you visit your own website. You find out when someone tells you, and someone tells you on the day it has already cost you an enquiry.
Every default is a decision nobody defended
A five-page business website is a few hundred small decisions. What sits above the fold. How many services to list before a list stops being read. Whether prices appear at all. What the form asks for, and what the visitor sees after they send it. Whether the phone number is tappable on a phone. What the page says when a page is missing.
An AI builder makes every one of them, instantly and plausibly. That is worse than making them badly. A bad decision is visible, so you fix it. A plausible one sits there for two years. You end up with a website that nobody can defend, yourself included, and no way to know which of the several hundred defaults is the one costing you enquiries.
There is a visual version of the same trap. These tools generate the middle of what a website looks like in 2026, which is exactly why the output is good. The middle is also where every other business is standing. The gradient hero, the three-column feature grid, the accordion, the same component library underneath. Your visitor cannot name the resemblance and registers it anyway. Prompting your way out is harder than it sounds, because you would first have to know what the default was.
Is Lovable safe to use?
A five-page website that stores nothing is about as safe as a website gets, whoever built it. No login, no records, nothing for anybody to read. On that question the tools are fine and we will not pretend otherwise.
It changes the moment your site keeps something, which is worth knowing before you act on the advice we gave two sections ago about using these tools when you need a database.
In May 2025 a critical vulnerability was published against Lovable as CVE-2025-48757. The entry in the United States National Vulnerability Database is one sentence: an insufficient row-level security policy "in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites". It scores 9.3 out of 10. It also carries a disputed tag, because Lovable's position is that securing an application's data belongs to the customer who built it.
The date inside that quotation matters. The record describes Lovable as it stood up to April 2025 rather than as it stands now, and we would want the same reading if somebody quoted a vulnerability of ours.
The scale arrived a year later. On 7 May 2026 the Israeli security firm RedAccess reported a scan of roughly 380,000 publicly reachable applications built on Lovable, Base44, Netlify and Replit. About 5,000 of them were exposing sensitive corporate or personal material, among it patient conversations at a care facility, a bank's internal financials and a retailer's customer service transcripts. The platforms answered that users control their own privacy settings. Replit's chief executive put it this way: "Public apps being accessible on the internet is expected behavior."
Read that exchange twice, because it is this entire article in miniature. Nobody in it is lying. The setting existed, the customer owned it, and the customer did not know that the setting was a decision.
For a brochure website the practical version is narrower and still real: your contact form. As soon as enquiries land in a database you are keeping other people's names, addresses and reasons for writing to you, and that store is the exact component the findings above are about.
Our answer is structural rather than clever. The sites we build are static, and an enquiry goes straight to your inbox through the form service. There is no store of visitor data behind your website, so there is no security policy on it to get wrong. The safest database is the one that does not exist.
The second year
Here is the part that is easy to miss while the building is still fun.
Lovable changed the stack under its own product on 13 May 2026. Projects made after that date render on the server on a newer framework. Projects made before it do not. Nobody did anything wrong, and the change was an improvement. The platform moved, as platforms do, and a whole population of projects became the previous kind on a Tuesday.
That is the honest shape of the second year. You come back fourteen months later to change your opening hours, and the interface has moved, the model has moved, the vocabulary that used to work has moved, and your project is now an artifact of the tool as it stood in 2026. The half hour you budgeted turns into an afternoon of relearning a tool you use twice a year.
Our side changes too. The difference is whose afternoon it is.
Who pays when it goes wrong
Follow the money on a single mistake, because it points at the whole difference.
If your builder has a bad run and breaks something, you pay to fix it, in credits. If we miss the date we agreed, we pay you €500. A subscription cannot owe you anything. There is no counterparty inside a credit balance: nobody to be disappointed in, nobody who loses something when your website is wrong, nobody whose Tuesday gets worse because your form has been failing silently for three weeks.
This is not an argument about artificial intelligence
You might expect a web company to explain next that software cannot replace human craft. We are not going to tell you that.
What a supplier uses to produce your work is not the interesting question, and we do not think you should put it to us either. Put these three instead: what arrives, on what date, and whose problem it is when something is wrong. Three answers describe a supplier completely. An inventory of the tools in their building describes nothing at all.
We have no distance to claim here in any case. We build on Next.js and host on Vercel, and Vercel makes v0, one of the tools in this article.
When a builder is the right call
Can you build a business website with Lovable? Yes, and in several situations it is the better purchase.
Use one when you are still testing whether an idea has customers, and the website's job is to find that out this month. Use one when what you need is software rather than a website: a login, a dashboard, records, anything with a database under it. Use one when rebuilding in six months is the plan rather than the risk. Use one when you enjoy building things, because then the evenings are not a cost.
Buy a built website instead when it is the front of a business that already has customers, when nobody in the building wants to own a website, and when the date matters to something else that is already booked.
The middle case is the one that catches people. The site is fine, it went up in a weekend, and eighteen months later the copy still says what you typed at eleven at night in the voice of a tool that has never met one of your customers.
What we do instead, and what it costs you
One package at €3,590. One kickoff of about two hours, then five working days, and your website is startklar on the date agreed in that meeting. We write the copy after asking you about the business. You choose your design from directions prepared before we meet. The code is yours from day one and we hand it over free whenever you ask. Hosting afterwards is €29 a month, and changing text and images yourself costs nothing at all.
A built example rather than an argument: frauenarzt-luebeck.de, a medical practice site whose staff have never opened a dashboard.
Now our side of the trade, stated straight. You cannot add a section at eleven at night. You ask, we quote it, and it has a price and a date. With a builder you would have had something on screen before the kettle boiled, and sometimes that version would have been fine. If your website changes every week, buy the builder. We would rather say so now than after an invoice.
Where the money goes when you hire anyone at all is a separate question we ran the numbers on in what a website costs. The same argument about who carries the maintenance, on the other side of the market, is in why we do not build on WordPress. And the nine separate jobs hiding inside the phrase "website design" are laid out in small business website design services.
Five questions before you pick either one
- When does this website stop being a project, and who says so?
- If it is wrong in six weeks, who fixes it, and what does that cost me?
- How many of my hours does this need, and which hours are they?
- Who decided what the homepage says, and can they defend the decision?
- If I stop paying, what do I still have?
Five answers separate the two purchases better than any feature table. Here are ours:
| Question | Our answer |
|---|---|
| When it stops | On the Startklar Date agreed at your kickoff. We say so, and if we miss it you get €500 back. |
| Wrong in six weeks | Ours to fix. One revision round after handover is included, and you send the notes in one go. |
| Your hours | One questionnaire and one kickoff of about two hours. Nothing to write, nothing to assemble. |
| The homepage | We decided it, from what you told us, and we will defend every line of it to you. |
| If you stop paying | The domain, the content and the code stay yours. We hand them over free, whenever you ask. |
If you want to check that against your own situation, our website package is published in full. Or book an intro call. It takes twenty minutes and costs nothing.