Our own data

State of vibe-coded security

What we actually find when we check apps built with AI tools. These are our own numbers, from our own checks, updated as more apps are checked.

how to read this

  • No app is named, ever — not here, not in a post, not privately. Percentages only.
  • Each figure is a share of distinct hosts, not of scans, so a customer checked daily for a month counts once.
  • We publish nothing below 100 distinct apps, because a percentage from a small sample is a made-up number with a decimal point.
  • Passive findings are things we can see in published files. Confirmed findings only come from apps whose owners verified ownership and asked us to check.

Not enough data to publish yet.

We have checked 2 distinct apps. The first report goes out at 100, and not before.

We could publish something now. Plenty of companies would. But a security vendor quoting a percentage from a handful of samples is exactly the kind of thing that turns out to be wrong in public, and being right later is worth more than being quoted this month.

Add your app to the sample — free

What we are measuring

So you know what to expect, and so the methodology is public before the numbers are:

  • Share of apps shipping a live third-party credential in their browser bundle.
  • Share exposing an AI provider key — where the loss is a bill, not a breach.
  • Share whose database table names are readable from published JavaScript.
  • Share with a table confirmed readable by an anonymous request (verified apps only).
  • Share serving a source map that reconstructs their original code.
  • Share missing each of the five response headers we check.
  • How long a newly exposed table stays exposed before it is fixed.

Methodology: figures are computed from completed checks in our own database, deduplicated by host. Passive checks read only files an application publishes publicly. Confirmed checks run only against applications whose owners verified control of the domain. We never publish a hostname, a URL, or an owner. See our scanner policy.