Opviva Research
The State of Vibe-Coded App Security
The Opviva agent continuously talks to and scans real apps built with AI coding tools, proving each exploit before it counts a finding — then we aggregate what it found, anonymized and never tied to any one app. These numbers update on their own as the sample grows. We publish a statistic only once it’s backed by real, proven data; nothing here is invented.
Based on 20 apps analyzed · updated 2026-08-28
What the agent proves most often
Share of analyzed apps where the agent proved at least one exploit in each category.
Security grade distribution
Most common vulnerable dependencies
90% of analyzed apps ship at least one dependency with a known vulnerability. The packages the agent flags most, by share of apps:
Methodology
Each app is counted once, using its most recent agent scan. Findings are bucketed into categories and de-duplicated per app, so a single app with three missing headers counts once toward “missing security headers.” All figures are aggregate and anonymized — no customer, repository, or app is ever identified.
Opviva