Skip to content

Vibe Coding Security Index

How secure are AI-built apps really?

Aggregated, anonymous analysis of all voluntarily shared rescue scans. No URLs, no personal data — only score distribution, verdicts and the most common rule hits. Citable under CC-BY.

1

Scans analysed

74

Median score (VRS)

Verdict distribution

  • Go: 0 %
  • Iterate: 100 %
  • Stop: 0 %

Most common findings

RSC-SEC-002HSTS header missing100 %
RSC-SEC-003No Content-Security-Policy100 %
RSC-ACC-002Images without alternative text100 %
RSC-ACC-003Form fields without labels100 %
RSC-ACC-004Accessibility violations in the rendered state100 %
RSC-SEC-005No clickjacking protection100 %
RSC-SEC-004MIME sniffing not disabled100 %
RSC-SEC-024No Referrer-Policy100 %
RSC-ARC-004No canonical link100 %
RSC-SCL-003Images without optimisation100 %
RSC-SCL-004No caching strategy100 %
RSC-DET-002Framework stack detected100 %

By platform

Dataset available openly under CC-BY. Please cite as “decivo Vibe Coding Security Index”. index.json