Not verified
Tenzai study of AI-built apps
69 vulnerabilities across 15 apps built by five AI coding tools.
2026-02
Not verified
Whether a script can hammer your forms, sign up loop, or paid endpoints without being slowed down.
Needs a signed-in account
Testing a rate limit means sending the traffic that triggers it. That is an attack on your app, and a check that runs on a stranger's URL must not do it.
Send the same form fifty times in a minute from one address and see whether anything stops you.
A reviewer sends controlled repeat traffic to your forms and paid endpoints, with your permission, and records what stopped it.
See what a Launch Review covers69 vulnerabilities across 15 apps built by five AI coding tools.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026