Skip to main content
UNPWNED
AI Code Security Audit

17.5% of AI-built sites
leak secrets.
Is yours one of them?

We scanned 683 production sites. The data is in. See where yours stands in a couple of minutes.

No signup|No card|Authorized scans only
17.5%

of AI-built sites leak secrets in public code.

0.9%

of hand-coded sites leak secrets.

19x

the gap between AI-built and hand-coded.

n = 683 production sites, deduplicated by domain, updated 2026-06-01

The patterns we keep finding

Exposed secrets
17.5%

of AI-built sites we scanned ship real API keys (Supabase service role, Stripe secret, OpenAI tokens) in their client bundle. One dev-tools open, full account compromise.

No CSP header
82.5%

of AI-built sites have no Content Security Policy. One compromised dependency and attacker JavaScript runs in every customer browser.

Open CORS
26.3%

of AI-built sites have CORS misconfigured (wildcard origin with credentials). Cross-site request forgery and session hijacking become trivial.

How it actually works

01
Paste URL

Yours, or run it on demo.unpwned.io to see it first.

02
We scan

The currently enabled Deep Scan with up to 702 configured checks spans 33 coverage scanners plus a supporting endpoint-discovery pass after current ownership proof.

03
You fix

Paid reports add a paste-ready prompt for each completed finding.

The AI wrote your code.
Find out what it left open.

no signup, unpwned.io