17.5% of AI-built sites
leak secrets.
Is yours one of them?
We scanned 683 production sites. The data is in. See where yours stands in a couple of minutes.
of AI-built sites leak secrets in public code.
of hand-coded sites leak secrets.
the gap between AI-built and hand-coded.
n = 683 production sites, deduplicated by domain, updated 2026-06-01
The patterns we keep finding
of AI-built sites we scanned ship real API keys (Supabase service role, Stripe secret, OpenAI tokens) in their client bundle. One dev-tools open, full account compromise.
of AI-built sites have no Content Security Policy. One compromised dependency and attacker JavaScript runs in every customer browser.
of AI-built sites have CORS misconfigured (wildcard origin with credentials). Cross-site request forgery and session hijacking become trivial.
How it actually works
Yours, or run it on demo.unpwned.io to see it first.
The currently enabled Deep Scan with up to 702 configured checks spans 33 coverage scanners plus a supporting endpoint-discovery pass after current ownership proof.
Paid reports add a paste-ready prompt for each completed finding.
The AI wrote your code.
Find out what it left open.
no signup, unpwned.io
