The AI builder defect index
Which AI builder platforms ship which security problems, measured from real scans rather than guessed at. Every number here is a count of scans xlogs actually ran. When we do not have enough data to say something honestly, this page says so instead of showing a number.
2026-09
Based on 23 scans this month. A rate is shown only where a platform has at least 30 completed checks of that kind; anything thinner is left blank on purpose.
- Missing security headersnot enough data
- Secret key in the browsernot enough data
- Other addresses on the domainnot enough data
- Private files publicnot enough data
- Source code downloadablenot enough data
- Database readable by anyonenot enough data
- Dangling DNSnot enough data
- Scripts from compromised CDNsnot enough data
- No email spoofing protectionnot enough data
Repositories, 2026-09
The same counting applied to the repo scanner: how often code in each ecosystem ships one of the high-signal problems. Based on 12 repositories scanned this month. No repository names are stored or published, ever.
- Dependency from a git or archive sourcenot enough data
- Reads local credentials or cloud metadatanot enough data
- A real secret committed in the codenot enough data
- CI runs untrusted PR code with secretsnot enough data
- Decodes and runs a hidden payloadnot enough data
- Contacts a known exfiltration channelnot enough data
- Runs a script when you install itnot enough data
- Poisoned AI-instruction filenot enough data
- Runs a script when you install itnot enough data
- Decodes and runs a hidden payloadnot enough data
- Dependency from a git or archive sourcenot enough data
- Reads local credentials or cloud metadatanot enough data
- Contacts a known exfiltration channelnot enough data
- CI runs untrusted PR code with secretsnot enough data
- Poisoned AI-instruction filenot enough data
- A real secret committed in the codenot enough data
- A real secret committed in the codenot enough data
- CI runs untrusted PR code with secretsnot enough data
- Poisoned AI-instruction filenot enough data
- Runs a script when you install itnot enough data
- Reads local credentials or cloud metadatanot enough data
- Decodes and runs a hidden payloadnot enough data
- Contacts a known exfiltration channelnot enough data
- Dependency from a git or archive sourcenot enough data
What is counted, and what is not
We store four things per scan and nothing else: the month, which builder platform the app appears to use, which check ran, and whether it found something. Plus a coarse bucket for how long the scan took.
We do not store the URL, the hostname, an IP address, a timestamp finer than the month, any finding detail, or any data from your app. There is no identifier of any kind in this, so there is nothing that could be traced back to a person or an app. See the privacy policy for the full statement.
We will never publish a list of affected sites. This index is counts only. Naming a stranger's app because our scanner found something would be the same adversarial disclosure we refuse to do anywhere else.
Why this can exist here and not elsewhere
Most security scanners only see the customers who signed a contract and connected a repository, which is a self-selected group that already bought a security tool. xlogs scans whatever anyone pastes in, for free, with no account, so what it sees is closer to the actual population of deployed AI-built apps. That is the only reason these numbers are worth anything.
It also means the sample is not random: it is apps whose owners cared enough to check. Read the numbers as "among apps that got scanned", not as a census of everything ever built.
