Skip to main content
AI Code Security Audit

17.5% of AI-built sites
leak secrets.
Is yours one of them?

We scanned 683 production sites. The data is in. See where yours stands in 60 seconds.

No signup|No card|Authorized scans only
17.5%

of AI-built sites leak secrets in public code.

0.9%

of hand-coded sites leak secrets.

19x

the gap between AI-built and hand-coded.

n = 683 production sites, deduplicated by domain, updated 2026-06-01

The patterns we keep finding

Exposed secrets
17.5%

of AI-built sites we scanned ship real API keys (Supabase service role, Stripe secret, OpenAI tokens) in their client bundle. One dev-tools open, full account compromise.

No CSP header
82.5%

of AI-built sites have no Content Security Policy. One compromised dependency and attacker JavaScript runs in every customer browser.

Open CORS
26.3%

of AI-built sites have CORS misconfigured (wildcard origin with credentials). Cross-site request forgery and session hijacking become trivial.

How it actually works

01
Paste URL

Yours, or run it on demo.unpwned.io to see it first.

02
We scan

36 scanners, 700+ checks. Automated, non-destructive outside-in requests.

03
You fix

Each finding ships with a paste-ready prompt for Claude or Cursor.

The AI wrote your code.
Find out what it left open.

60 seconds, no signup, unpwned.io