The catch is what most people skip. AI-generated themes routinely miss nonce verification on forms, sanitize_text_field on inputs, proper escaping on output, and translation-ready strings. They also tend to hardcode things that should sit in the customizer or ACF. Upload that to production and you have a security incident waiting for a slow Tuesday.