Methodology
How we measureAI-built app security.
Every statistic on this site comes from ShipSafe’s own independent, read-only scans of publicly-deployed apps. We read the code and probe the live app from the public internet, and we only report data exposure that an actual anonymous request returned — never a guess.
On consent, and what we never do
When you verify your own app, you authorize the scan. The deep active checks (confirming a leaked key is actually live, probing your backend) run on your own machinevia our CLI or GitHub App, and we sign the result. We never point our servers at infrastructure you can’t prove you own. The studies below use only read-only, browser-equivalent requests to publicly-deployed apps: we never log in, never validate a credential against its provider, and never change anything. Independent verification, with consent built in.
The studies
Each headline figure, its sample size, and exactly what we count — cited, not asserted.
Cursor
100 deployed apps
67% had at least one critical-severity finding
67%Lovable
50 deployed apps
89% had a Supabase table readable with no login (RLS off)
89%Replit
30 deployed apps
77% had at least one critical-severity finding
77%The widely-quoted 67% figure is the Cursor study specifically. Across builders, the rate of at least one critical finding ranged from 67% to 77%.
How a scan runs
Read-only, proven-not-inferred, and counted once per app.
Read-only and non-destructive: GET requests only, bounded, never writing or deleting.
Both surfaces: the code (or repo) for logic bugs, and the deployed app from the public internet.
Data exposure is proven, not inferred: a single anonymous read against a Supabase table or storage bucket, or a Firebase database, that actually returned rows.
Critical-severity follows the scanner's CWE/OWASP-mapped scale; a finding is counted once per app.
Scope and limits
What these numbers are — and, honestly, what they are not.
These are point-in-time, automated scans of a sample of apps. They describe how often a class of issue appears across AI-built apps, not the security of any single app. A passing scan is not a guarantee, a penetration test, or a compliance audit. New code introduces new risk, so re-scan after changes.
Want the same proof for your own app?
Independent, read-only, consent-built-in — and signed. See where your app lands in about two minutes.
— ShipSafe · Independent verification, with consent built in —