Skip to main content

Methodology

How we measureAI-built app security.

Every statistic on this site comes from ShipSafe’s own independent, read-only scans of publicly-deployed apps. We read the code and probe the live app from the public internet, and we only report data exposure that an actual anonymous request returned — never a guess.

On consent, and what we never do

When you verify your own app, you authorize the scan. The deep active checks (confirming a leaked key is actually live, probing your backend) run on your own machinevia our CLI or GitHub App, and we sign the result. We never point our servers at infrastructure you can’t prove you own. The studies below use only read-only, browser-equivalent requests to publicly-deployed apps: we never log in, never validate a credential against its provider, and never change anything. Independent verification, with consent built in.

01

The studies

Each headline figure, its sample size, and exactly what we count — cited, not asserted.

Cursor

100 deployed apps

67% had at least one critical-severity finding

67%

Lovable

50 deployed apps

89% had a Supabase table readable with no login (RLS off)

89%

Replit

30 deployed apps

77% had at least one critical-severity finding

77%

The widely-quoted 67% figure is the Cursor study specifically. Across builders, the rate of at least one critical finding ranged from 67% to 77%.

02

How a scan runs

Read-only, proven-not-inferred, and counted once per app.

01

Read-only and non-destructive: GET requests only, bounded, never writing or deleting.

02

Both surfaces: the code (or repo) for logic bugs, and the deployed app from the public internet.

03

Data exposure is proven, not inferred: a single anonymous read against a Supabase table or storage bucket, or a Firebase database, that actually returned rows.

04

Critical-severity follows the scanner's CWE/OWASP-mapped scale; a finding is counted once per app.

03

Scope and limits

What these numbers are — and, honestly, what they are not.

These are point-in-time, automated scans of a sample of apps. They describe how often a class of issue appears across AI-built apps, not the security of any single app. A passing scan is not a guarantee, a penetration test, or a compliance audit. New code introduces new risk, so re-scan after changes.

Want the same proof for your own app?

Independent, read-only, consent-built-in — and signed. See where your app lands in about two minutes.

— ShipSafe · Independent verification, with consent built in —