Skip to content

Opviva Research

The State of Vibe-Coded App Security

The Opviva agent continuously talks to and scans real apps built with AI coding tools, proving each exploit before it counts a finding — then we aggregate what it found, anonymized and never tied to any one app. These numbers update on their own as the sample grows. We publish a statistic only once it’s backed by real, proven data; nothing here is invented.

Based on 20 apps analyzed · updated 2026-08-28

20
AI-built apps scanned
1,873
security issues proven
94
issues per app, on average
90%
graded D or F

What the agent proves most often

Share of analyzed apps where the agent proved at least one exploit in each category.

Exposed secrets & API keys100%
Vulnerable dependencies90%
Broken access control35%
Missing Row Level Security25%
Missing security headers10%
Injection (XSS / SQLi)10%
Permissive CORS5%

Security grade distribution

A0%
B5%
C5%
D0%
F90%

Most common vulnerable dependencies

90% of analyzed apps ship at least one dependency with a known vulnerability. The packages the agent flags most, by share of apps:

postcss80%
vite65%
esbuild60%
js-yaml55%
brace-expansion50%
uuid40%
axios40%
react-router35%
lodash35%
picomatch35%

Methodology

Each app is counted once, using its most recent agent scan. Findings are bucketed into categories and de-duplicated per app, so a single app with three missing headers counts once toward “missing security headers.” All figures are aggregate and anonymized — no customer, repository, or app is ever identified.

Want to know where your own app stands?