/research · monthly · October 2026 · first edition

State of AI-built app security, October 2026

This is the first edition. Every month we count what apps built with AI send to every visitor: the browser protections, HTTPS, files left open, secret keys in public code and the services behind them. Counts and percentages only; no app is named.

Published Edition 1Permalink 7it.co.il/research/ai-app-security/2026-10/
The short version

October 2026 in four numbers.

From the public panel of 439 live apps built with an AI app builder.

93.4%

of apps ship with no Content Security Policy

3 of 7

Median number of the seven standard browser protections an app sends

89.5%

of apps enforce HTTPS with HSTS

61.7%

of apps name a Supabase project in the code they send

The public panel

What 439 live apps send to every visitor.

The standard protections a reviewer turns on before launch, and the defaults an AI builder tends to leave out.

Which protections ship

Share of 439 apps that send each of the seven standard browser protections.

Content Security Policy 6.6%
HTTPS enforced (HSTS) 89.5%
Clickjacking protection 9.3%
No MIME sniffing 82.5%
Referrer policy 80.6%
Permissions policy 6.2%
Cross-origin isolation 2.3%
Show as a table
ItemAppsShare
Content Security Policy29 of 4396.6%
HTTPS enforced (HSTS)393 of 43989.5%
Clickjacking protection41 of 4399.3%
No MIME sniffing362 of 43982.5%
Referrer policy354 of 43980.6%
Permissions policy27 of 4396.2%
Cross-origin isolation10 of 4392.3%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/protections/" title="Which protections ship, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>

How many protections at once

Apps by how many of the seven they send. The median is 3 of 7.

5.9% 0 of 7
11.6% 1 of 7
3.6% 2 of 7
70.2% 3 of 7
1.1% 4 of 7
3.2% 5 of 7
3.2% 6 of 7
1.1% 7 of 7
Show as a table
ItemAppsShare
0 of 726 of 4395.9%
1 of 751 of 43911.6%
2 of 716 of 4393.6%
3 of 7308 of 43970.2%
4 of 75 of 4391.1%
5 of 714 of 4393.2%
6 of 714 of 4393.2%
7 of 75 of 4391.1%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/protection-count/" title="How many protections at once, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>

HTTPS and source maps

Share of 439 apps. A public source map lets anyone rebuild the original source code.

89.5%
Send HSTS (HTTPS enforced)
97.5%
Send plain http:// visits to https://
1.6%
Serve a public source map
Show as a table
ItemAppsShare
Send HSTS (HTTPS enforced)393 of 43989.5%
Send plain http:// visits to https://428 of 43997.5%
Serve a public source map7 of 4391.6%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/https/" title="HTTPS and source maps, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>

How many use Supabase

Share of 439 apps whose public code names a Supabase project. We read the address only, never the data.

61.7%
Use Supabase
Show as a table
ItemAppsShare
Name a Supabase project in the code they send271 of 43961.7%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/supabase/" title="How many use Supabase, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>

Where they are hosted

Hosting detected from public response headers, 439 apps. Small groups are folded into "Other".

Cloudflare 41.5%
The builder's own hosting 37.4%
Vercel 10%
Netlify 3.9%
Other or not detected 7.3%
Show as a table
ItemAppsShare
Cloudflare182 of 43941.5%
The builder's own hosting164 of 43937.4%
Vercel44 of 43910%
Netlify17 of 4393.9%
Other or not detected32 of 4397.3%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/hosting/" title="Where they are hosted, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>

Page weight

The home page plus the scripts and stylesheets it links, before compression. Median 1,020 KB across 439 apps.

3.4% Under 250 KB
10.3% 250 to 500 KB
35.5% 500 KB to 1 MB
30.8% 1 to 2 MB
20% Over 2 MB
Show as a table
ItemAppsShare
Under 250 KB15 of 4393.4%
250 to 500 KB45 of 43910.3%
500 KB to 1 MB156 of 43935.5%
1 to 2 MB135 of 43930.8%
Over 2 MB88 of 43920%
Link to this chart
Embed this chart
<iframe src="https://7it.co.il/research/ai-app-security/2026-10/embed/page-weight/" title="Page weight, October 2026. Source: 7IT" width="100%" height="460" style="border:0;max-width:720px" loading="lazy"></iframe> <p style="font-size:13px">Source: <a href="https://7it.co.il/research/ai-app-security/2026-10/">7IT, State of AI-Built App Security, October 2026</a></p>
From the 7IT checks

Exposed files and secret keys.

From sites people checked with 7IT this month. Secret keys and exposed files are counted only where the owner proved the site is theirs.

Not enough checks this month to publish these numbers without risking that a site could be picked out. They will appear here once there are enough. Check your own app or run the Supabase check.
Method

How we count, and what we never do.

Where the numbers come from

  • The public panel. Live apps their makers list on a public showcase of an AI app builder. Each month we visit each listed app once, the way a browser does, and read only what any visitor receives: the response headers, the home page, the scripts and stylesheets it links, the first bytes of a source map next to the first script, and where a plain http:// visit is sent. This edition: 439 apps answered out of 517 listed.
  • The 7IT checks. Sites people ran through the app security check and the Supabase check, and owner-verified deep scans. Each site counts once a month. Secret keys and exposed files are counted only for sites whose owner proved the site is theirs. This edition: 0 header checks, 0 deep scans, 0 Supabase checks.
  • Apps under watch. Apps watched by 7IT Guard whose owners allow counting. This edition: 0.

What we never do

  • We never log in, submit a form, call an app's API or read a database. Supabase usage is counted from the project address in the public code, never from the data.
  • We never look for secret keys in the code of apps whose owners did not ask us to.
  • We never publish a site name, address or anything that points at a site or its owner. Small groups are folded together or left out, so no single app can be picked out. A source with too few apps in a month is not published that month.

How to read it

Each source answers a different question, so the sources are never mixed into one number. Missing headers are not the whole security picture, but they are a reliable sign that nobody has done the security pass before launch. Percentages are rounded to one decimal place. The panel was read from outside the United States, so this edition shows no speed numbers.

Window: October 1, 2026 to October 4, 2026 for the 7IT checks; the panel was read on October 5, 2026. Published October 5, 2026, the first edition. License CC BY 4.0: use it with a link to this page.

Data and citation

Use it, with a link.

The aggregates behind every chart, as a spreadsheet and as JSON. Each chart above has its own embed code with the source line built in.

Cite it as:

7IT Solutions, "State of AI-Built App Security, October 2026", https://7it.co.il/research/ai-app-security/2026-10/

Is your app in good shape? Check its protections, run the Supabase check, or keep it watched with 7IT Guard.

All editions · All research