AI-built apps ship with critical security flaws by default, scans reveal
Security audits of apps built with AI coding tools like Lovable, Bolt, and Replit consistently reveal serious vulnerabilities before developers write a single line of custom code. A scan of 5,600 production apps by Escape.tech found 1,400 with vulnerabilities and over 400 leaked secrets, while a separate audit found 91.5% of 200-plus apps had at least one AI-generated security flaw. Common issues include Supabase tables with row-level security disabled by default, secret API keys exposed in frontend code, and admin access checks enforced only in the browser rather than on the server. These flaws arise because AI coding tools prioritize making demos functional over securing user data. Developers and non-technical founders are advised to audit live apps for exposed keys, verify database permission settings, and use free tools like securityheaders.com to assess their security posture.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in