17.5% of AI-built sites
leak secrets.
Is yours one of them?
We scanned 683 production sites. The data is in. See where yours stands in 60 seconds.
of AI-built sites leak secrets in public code.
of hand-coded sites leak secrets.
the gap between AI-built and hand-coded.
n = 683 production sites, deduplicated by domain, updated 2026-06-01
The patterns we keep finding
of AI-built sites we scanned ship real API keys (Supabase service role, Stripe secret, OpenAI tokens) in their client bundle. One dev-tools open, full account compromise.
of AI-built sites have no Content Security Policy. One compromised dependency and attacker JavaScript runs in every customer browser.
of AI-built sites have CORS misconfigured (wildcard origin with credentials). Cross-site request forgery and session hijacking become trivial.
How it actually works
Yours, or run it on demo.unpwned.io to see it first.
36 scanners, 700+ checks. Automated, non-destructive outside-in requests.
Each finding ships with a paste-ready prompt for Claude or Cursor.
The AI wrote your code.
Find out what it left open.
60 seconds, no signup, unpwned.io
