AI-built app security report 2026: what 799 live apps show (Sekrd dataset)
Short answer
Across 799 publicly reachable hosts scanned by Sekrd between March 22 and September 10, 2026 (174 on lovable.app subdomains, plus Vercel, Bolt, Replit, Netlify, Cloudflare Pages, Firebase Hosting and custom domains), 4.4% had at least one critical finding and 6.8% received a Block (do-not-ship) verdict. The most widespread gaps were deployment-level: 81.5% served no Content-Security-Policy, 93.4% disclosed server software versions, 60.3% had no privacy-policy link and 25.3% offered no visible account- or data-deletion mechanism. High-severity secret leaks appeared on 2.1% of hosts. Figures are external, unauthenticated scans and may be cited with attribution to Sekrd.
Last updated · Sekrd Research
- Sample: 799 unique hosts, latest completed scan per host, March 22 – September 10, 2026.
- Platforms: 174 hosts on lovable.app; the rest on Vercel, Bolt, Replit, Netlify, Cloudflare Pages, Firebase Hosting, Render and custom domains.
- Critical finding: 4.4% of hosts. Block verdict: 6.8%.
- No Content-Security-Policy: 81.5%. Server version disclosed: 93.4%. No HSTS: 13.5%.
- No privacy-policy link: 60.3%. No account/data deletion mechanism: 25.3%.
- License: you may cite these figures with attribution to Sekrd (sekrd.com).
Method
Each host was scanned from the outside, without credentials or a signed-in session — the view any visitor or attacker gets. Hosts came from research sweeps of AI-coding deploy platforms (sampled from Certificate Transparency logs) and from scans users ran on their own apps. For hosts scanned more than once we used only the most recent completed scan. Sekrd’s own domains and test fixtures were excluded, as were findings Sekrd marks low-confidence or tentative. Hosts are not named, and per-platform results are not published.
Headline numbers
| Finding | Share of 799 hosts |
|---|---|
| Server software version disclosed | 93.4% |
| No Content-Security-Policy header | 81.5% |
| No privacy-policy link found | 60.3% |
| No account/data deletion mechanism found | 25.3% |
| Missing Strict-Transport-Security (HSTS) | 13.5% |
| Google Analytics loaded without cookie consent | 8.1% |
| Internal or staging URLs in production JavaScript | 7.3% |
| CSP allows ‘unsafe-eval’ | 6.5% |
| At least one critical finding | 4.4% |
| innerHTML with dynamic content (DOM XSS risk) | 3.8% |
| High-severity secret leak in client code | 2.1% |
| High-severity payment issue (e.g. unsigned webhook) | 0.6% |
Grade distribution
Sekrd grades each scan A–F. Of 799 hosts: A — 42 (5.3%), B — 463 (57.9%), C — 196 (24.5%), D — 55 (6.9%), F — 43 (5.4%).
The critical findings
Critical and high-severity issues seen on more than one host included: JavaScript source maps exposing original source code (12 hosts), Supabase tables readable without authentication (4), CORS reflecting arbitrary origins (4), payment webhooks accepting unsigned requests (Stripe and Lemon Squeezy, 2 each), what appeared to be Supabase service_role keys and Telegram bot tokens in client code (2 each), and an unauthenticated user endpoint returning another user’s data (2).
What the numbers mean
- Most risk is set at deploy time, not in code. Headers, server banners and missing legal pages dominate, and none of them are visible to a source-code scanner.
- Critical leaks are rare but severe. 4.4% of hosts is a small share, but each case is an exposed database, a usable secret or free goods.
- Compliance gaps are the norm. Six in ten apps had no privacy-policy link, which matters for app-store review and for GDPR and CCPA notice obligations.
Limitations
- External scans cannot read database policies; Supabase and Firebase exposure is undercounted. Use in-database checks for a definitive answer.
- The sample is not random across the whole web: it over-represents AI-coding platforms and apps whose owners chose to scan them, and includes some non-AI-built sites.
- Automated detection can produce false positives; low-confidence and tentative findings were excluded to reduce them.
Frequently asked questions
How secure are AI-built web apps in 2026?
In Sekrd’s dataset of 799 live hosts scanned March–September 2026, 4.4% had at least one critical finding and 6.8% received a do-not-ship verdict, while deployment gaps were widespread: 81.5% had no Content-Security-Policy and 60.3% had no privacy-policy link.
What is the most common security issue in vibe-coded apps?
Missing deployment hardening. In Sekrd’s 2026 dataset, 93.4% of hosts disclosed server software versions and 81.5% served no Content-Security-Policy header; these are set by hosting configuration rather than application code.
Can I cite Sekrd’s security statistics?
Yes. The figures in the AI-built app security report 2026 may be cited with attribution to Sekrd (sekrd.com), together with the stated method and limitations.
Sources
Don't ship until you're sekrd
Run a free scan to find the vulnerabilities your AI missed.
Scan Your App Free