Does ChatGPT write vulnerable code?
Yes, ChatGPT regularly produces code with security vulnerabilities. Studies have shown that AI-generated code contains exploitable flaws in a significant percentage of cases, particularly in areas like authentication, input handling, and database queries. The model tends to prioritize code that works functionally over code that is secure, often omitting error handling, access controls, and security headers. ChatGPT also cannot verify that its suggestions are safe for your specific deployment environment. UNPWNED assesses current outside-in exposure, configuration, dependency, endpoint, CORS, form, and error-disclosure signals. It does not attribute findings to the code generator or certify compliance with an industry standard.
Check your ChatGPT app now
Run free security scanLast reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.
