First-quarter 2026 assessment of 200 apps
183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.
Not verified
Whether the row rules behind the app actually stop one signed in account reading another's rows.
Needs a signed-in account
A check can see that a table answers the public key. Whether the rule on it is the right rule requires reading the policy, and policies are not published.
Sign in as one account and request another account's record by id through the API.
A reviewer reads the policies, then asks for another account's record by id and confirms the database refuses.
See what a Launch Review covers183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.
An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
An unprotected storage instance exposed tens of thousands of user images, including identity documents.
Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
Broken access control reported across 170 production applications built with Lovable.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026