/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: 5,000+ web apps built using AI coding tools like Lovable, Base44, and Replit have little to no authentication, and ~40% exposed sensitive data

Companies like Lovable, Base44, Replit, and Netlify use AI to let anyone build a web app in seconds—and in thousands of cases …

Wired Andy Greenberg

Context & Ripple Effects

Related coverage had already identified a critical flaw in apps made with Lovable that could expose API keys and users’ personal information. This report broadens the concern from an individual product vulnerability to a recurring security failure across AI-assisted app-building tools.

The pattern also resembles earlier low-code exposure incidents on Microsoft Power Apps and reports that organizations are struggling to review the growing volume of AI-generated code. The issue is therefore not simply code generation, but whether deployment defaults and review processes keep pace with it.

First-order effects

  • Thousands of deployed apps built with Lovable, Base44, Replit, and Netlify-linked AI tooling may require immediate authentication and data-exposure reviews; affected app operators face remediation work and potential user-data risk.
  • The named platforms face pressure to strengthen secure-by-default templates, deployment checks, and warnings around authentication and sensitive-data handling.

Second-order effects

  • Organizations using AI app builders will need to treat generated applications as production software requiring security review, rather than as low-friction prototypes that can be published without governance.
  • Security teams and platform vendors are likely to focus more on automated detection of exposed secrets, public data stores, and missing access controls, because manual review becomes harder as AI increases application output.

Third-order effects

  • If such failures persist, the competitive advantage of AI coding platforms will increasingly depend on guardrails in the build-and-deploy workflow, not just how quickly they generate an app.
  • The recurring connection between low-code and AI-generated app exposures points toward a broader shift: democratized software creation expands the population of publishers who must manage authentication, data access, and security operations.

The trend: AI-assisted development is moving software bottlenecks from writing code toward securing, reviewing, and governing the much larger volume of applications that can now be deployed quickly.

Discussion

  • @a_greenberg Andy Greenberg on x
    Researchers at security firm RedAccess found more than 5,000 vibe-coded apps, created with AI tools from Lovable, Replit, Base44 and Netlify, with essentially no security, accessible on the open web. About 40% exposed sensitive personal or corporate data. https://www.wired.com/..…
  • @couts Andrew Couts on bluesky
    NEW: Using basic search techniques, researchers discovered some 5,000 vibe-coded apps left exposed to the open internet. @agreenberg.bsky.social has the scoop: www.wired.com/story/thousa...
  • M Mohan M Mohan on linkedin
    Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web  —  Wired Productions Magazine just published this report. …
  • @smcgrath.phd Scott McGrath on bluesky
    Corporate data is spilling onto the web as AI vibe-coding tools bypass standard security reviews.  A scan of 5,000 apps found 40% exposed sensitive medical records and financial files.  Building in seconds shouldn't mean stripping away institutional security checks.  —  #MedSky #…