Aggregated, anonymized data

State of vibe coding security

Statistics computed across every Vetora scan. No URL or site is ever identified here — only global counts.

60
Scans analyzed
88
Findings detected
0%
Have ≥1 critical finding

Score distribution

A
63% (38)
B
8% (5)
C
22% (13)
D
7% (4)
F
0% (0)

Findings by category

Sécurité de base
100%
Stripe & Supabase
0%
Patterns vibe coding
0%
Infrastructure
0%
Dépendances (CVE)
0%
Exploitation active (domaine vérifié)
0%

Most frequent findings

#1Header de sécurité manquant : X-Frame-Options
16×
#2Header de sécurité manquant : Content-Security-Policy (CSP)
14×
#3Header de sécurité manquant : Strict-Transport-Security (HSTS)
10×
#4Header de sécurité manquant : Permissions-Policy
10×
#5Cookie sans flag Secure
9×
#6Header de sécurité manquant : X-Content-Type-Options
8×
#7Cookie sans attribut SameSite
8×
#8CORS trop permissif (Access-Control-Allow-Origin: *)
7×

Is your app part of these numbers?

The only way to know is to scan. Free, under 30 seconds.

Scan my app