Blog

/Research

State of vibe coding 2026

Lovable says it hosts 60M projects, over 60% of new Supabase databases come from AI tools, and app builders churn 20–40%. The state of vibe coding in 2026, from 29 sources.

·14 min read

Summarize in ChatGPT
Report cover for State of vibe coding 2026: latest valuations (Cursor $60B SpaceX deal, Lovable $13.3B, Supabase $10.5B, Vercel $9.3B, Replit $9B), Cursor's annualised revenue stepping from $100M in Jan 2025 to about $4B in Jun 2026, and four stats: 72.2% of developers say vibe coding isn't part of their work, over 60% of new Supabase databases are launched by AI tools, 20–40% churn across AI app builders, and 10.3% of Lovable showcase apps had broken row-level security.
On this page

In February 2025 Andrej Karpathy gave a name to something many people had quietly started doing: describing an app to an AI, accepting whatever it wrote, and pasting the error messages back in until it worked. Twenty months later the term is a dictionary word of the year, the companies selling it are valued in the tens of billions of dollars, and more than 60% of new databases on Supabase are launched by some sort of AI tool.

Most coverage stops at the funding rounds. We wanted the rest of the picture: who actually builds these apps, what they build, where the apps end up once they exist, and what goes wrong along the way. So we gathered the public data (company announcements, developer surveys, security scans, analyst notes), checked it, and threw out what didn't hold up. Vendor figures are self-reported and labelled that way throughout, and every number below links to its source.

Key findings

  1. 1
    The biggest money sits with tools for professional developers. SpaceX agreed to buy Cursor's parent for $60B in June 2026, while Lovable, the most valuable pure app builder in our data, is valued at $13.3B.
  2. 2
    Professional developers use AI every day but mostly don't vibe code: in Stack Overflow's 2025 survey, 84% use or plan to use AI tools, yet 72.2% say vibe coding is not part of their work.
  3. 3
    App builders grow revenue fast and lose users fast. Lovable says it reached a $500M run-rate in June 2026; Bolt's CEO puts churn across the market at 20% to 40%, because projects are one-off.
  4. 4
    Interest cooled after a spring and summer 2025 peak. Barclays-shared traffic data showed Lovable down 40%, v0 down 64% and Bolt down 27%.
  5. 5
    Value is shifting to whatever holds the app after it's generated. Bolt now bundles hosting and a database into every plan, Lovable, Bolt and Replit all launched their own backends, and Supabase database launches grew 600% in a year.
  6. 6
    Builders are turning into hosts. Lovable says it hosts 60M projects that draw 900M visitors a month, and Netlify says over 1M Bolt-built sites were deployed on it in five months.
  7. 7
    Security is the weak link. A scan found broken access rules in 10.3% of 1,645 Lovable showcase apps, and Escape found 2,000+ vulnerabilities and 400+ exposed secrets across 5,600+ vibe-coded apps.
  8. 8
    Nobody publishes how long these apps live, how many get shared, or with whom. That's the biggest gap in the public data.

$60B

SpaceX's all-stock deal for Cursor's parent, Jun 2026

Source: Reuters

$13.3B

Lovable valuation, Aug 2026

Source: TechCrunch

60M

Projects Lovable says it hosts, drawing 900M visits a month, Aug 2026

Self-reported

Source: TechCrunch

>60%

New Supabase databases launched by an AI tool, Jun 2026

Self-reported

Source: Supabase

72.2%

Developers who say vibe coding is not part of their work, 2025

Source: Stack Overflow

20–40%

Churn across AI app builders, per Bolt's CEO, Aug 2025

Source: Business Insider

1M+

Bolt-built sites deployed on Netlify, Nov 2024 to Mar 2025

Self-reported

Source: Netlify

10.3%

Lovable showcase apps with broken row-level security, 2025

Source: CVE-2025-48757

Where the term came from#

Fully give in to the vibes, embrace exponentials, and forget that the code even exists.

— Andrej Karpathy, on X, 2 Feb 2025

Karpathy's post described a specific way of working. He accepted every change the AI proposed without reading the diffs, pasted error messages straight back into the chat, and let the code grow past the point where he fully understood it. His setup was Cursor Composer running Claude Sonnet, with SuperWhisper so he could talk instead of type. He was also clear about where it belonged: in his words, it was "not too bad for throwaway weekend projects." The post went up late on 2 February UTC, which is why some outlets date it to the 3rd; by 5 October 2026 it had 34,153 likes and 3,630 reposts.

The word spread quickly. Merriam-Webster added it to its "Slang & Trending" list in March 2025, crediting Karpathy as the likely coiner. In early March, Y Combinator's Jared Friedman said a quarter of the Winter 2025 batch had codebases that were 95% AI-generated, and stressed that these were highly technical founders, not people who couldn't code. By November, Collins had named "vibe coding" its word of the year, ahead of a shortlist that included clanker, aura farming, broligarchy and taskmasking.

That origin matters for reading everything below. The person who named the practice scoped it to small, disposable projects where nobody reads the code. Much of what's now marketed as "vibe coding" is something else: engineers using AI heavily and still reviewing every line. The numbers make more sense once you keep those two populations apart.

From a weekend-project post to a $60B deal

Key moments for the term and the companies built on it, Feb 2025 to Aug 2026

  1. 2 Feb 2025

    Karpathy names “vibe coding”

    An X post describes accepting every AI change without reading the diff, for “throwaway weekend projects”.
  2. Mar 2025

    Merriam-Webster lists it

    Added to the dictionary's Slang & Trending section, crediting Karpathy as the likely coiner.
  3. 6 Mar 2025

    A quarter of YC W25 is mostly AI-written

    Jared Friedman says 25% of the batch have codebases that are 95% AI-generated.
  4. 18 Jun 2025

    Wix buys Base44

    About $80M plus earn-outs for a one-founder, six-person app builder with no outside funding.
  5. 6 Nov 2025

    Collins word of the year

    “Vibe coding” is chosen as the Collins Word of the Year 2025.
  6. Feb 2026

    Claude Code passes a $2.5B run-rate

    Anthropic says Claude Code's run-rate revenue doubled since 1 Jan 2026.
  7. 11 Mar 2026

    Replit valued at $9B

    A $400M Series D, six months after a $3B valuation.
  8. 4 Jun 2026

    Supabase valued at $10.5B

    A $500M Series F; AI coding tools now create most of its new databases.
  9. 16 Jun 2026

    SpaceX agrees to buy Cursor

    A $60B all-stock deal for Cursor's parent company, Anysphere.
  10. 12 Aug 2026

    Lovable valued at $13.3B

    A $400M Series C, double its valuation from December 2025.
Sixteen months separate the coinage from the first $60B outcome, and the largest prize went to a tool for professional developers.

Sources: Karpathy on X; Merriam-Webster; TechCrunch; Wix; Collins; Constellation Research; Reuters

The money: valuations and revenue#

Two kinds of companies get lumped together as "vibe coding". App builders such as Lovable, Bolt, Replit, v0 and Base44 take a prompt in the browser and return a running app, aimed at people who may never open the code. Coding agents such as Cursor and Claude Code sit inside a professional's editor or terminal. Both grew extraordinarily fast. The professional side is where the largest numbers are.

In June 2026 SpaceX agreed to buy Anysphere, Cursor's parent, for $60B in stock, after unveiling an option in April to either buy it or pay $10B for a partnership. Lovable raised $400M at a $13.3B valuation in August 2026, double the $6.6B it was valued at in December 2025. Supabase, the database underneath a large share of these apps, raised $500M at a $10.5B valuation in June. Vercel, which makes v0, raised at $9.3B in September 2025, and Replit raised at $9B in March 2026. At the small end, Wix bought Base44 for about $80M plus earn-outs through 2029.

Latest valuations in the vibe-coding economy

Most recent priced round or deal value, in US dollars, Jan 2025 to Aug 2026

Latest valuations in the vibe-coding economy
LabelValue
Cursor (Anysphere), Jun 2026$60B (SpaceX deal)
Lovable, Aug 2026$13.3B
Supabase, Jun 2026$10.5B (post-money)
Vercel (v0), Sep 2025$9.3B
Replit, Mar 2026$9B
Bolt (StackBlitz), Jan 2025~$700M
Base44 (Wix deal), Jun 2025~$80M (plus earn-outs)
Highlighted bars are the app builders that sell vibe coding directly. Muted bars are a coding agent for professionals and the infrastructure the apps run on.

Sources: Reuters; TechCrunch (Lovable); CNBC; SaaStr; TechCrunch (Replit); Sacra; Wix

Revenue run-rates#

Revenue tells the same story. A note on the unit first: almost every figure here is an annualised run-rate, usually a recent month's revenue multiplied by twelve, and almost all of them were disclosed during a fundraise. Nobody audits them. They are still the best public signal of how much people pay.

Cursor's climb is the steepest in our data. A tally by Tech Insider puts it at $100M of annualised revenue in January 2025, $500M by June, $1B by November, $2B by February 2026 and roughly $4B by June 2026. The $2B point is independently reported: TechCrunch, citing Bloomberg, says Cursor reached it in February. Reuters, using company data, put Cursor's annualised business-to-business revenue alone at roughly $2.6B in June 2026. Anthropic says Claude Code passed a $2.5B run-rate in February 2026, having doubled since the start of the year, according to Constellation Research.

Cursor's annualised revenue

Reported run-rate milestones, Jan 2025 to Jun 2026

Cursor's annualised revenue
xy
Jan 2025$100M
Jun 2025$500M
Nov 2025$1B
Feb 2026$2B ($2B)
Jun 2026$4B (~$4B)
Roughly a 40x increase in 17 months. The run-rate doubled in each of the last two steps, three and four months apart.

Sources: Tech Insider (timeline); TechCrunch ($2B)

The app builders are an order of magnitude smaller but grew just as quickly. Lovable hit $100M ARR in June 2025 and says it reached a $500M run-rate a year later. Replit said in September 2025 it was on track for $150M of annualised revenue; Sacra estimates it reached $525M by April 2026, and the company has said it hopes to hit $1B by the end of 2026, which is a goal rather than a result. Replit's own story is a caution against reading these curves as overnight success: it took nine years and a pivot from professional developers to non-programmers to find its market.

Lovable and Replit annualised revenue

Reported and estimated run-rates, Jun 2025 to Jun 2026

Lovable and Replit annualised revenue
Seriesxy
LovableJun 2025$100M
LovableJun 2026$500M
ReplitSep 2025$150M (projected)
ReplitApr 2026$525M (Sacra est.)
Lovable grew fivefold in a year; Replit, by Sacra's estimate, grew 3.5x in seven months. Both converged near $500M. Replit's later point is an analyst estimate, not a company figure.

Sources: Business Insider; TechCrunch; TechCrunch (Replit); Sacra

Latest annualised revenue, by company

Most recent reported or estimated run-rate, in US dollars, Mar 2025 to Jun 2026

Latest annualised revenue, by company
LabelValue
Cursor, Jun 2026~$4B
Claude Code, Feb 2026>$2.5B
Replit, Apr 2026~$525M (Sacra estimate)
Lovable, Jun 2026$500M
Supabase, May 2026~$170M (Sacra estimate)
Bolt, Mar 2025$40M (Sacra estimate)
The two professional coding tools out-earn every app builder in this chart combined. Bolt's figure is the oldest in the set; it hasn't published a newer one.

Sources: Tech Insider; Constellation Research; Sacra (Supabase, Replit); TechCrunch; Sacra (Bolt)

The builders side by side#

The AI app builders compared

Valuation, revenue, backend and scale, as last reported, Jan 2025 to Aug 2026

BuilderValuationRevenue signalBackend and hostingScale signal
Lovable$13.3B (Aug 2026)$500M run-rate (Jun 2026)Lovable Cloud, white-labelled Supabase60M projects hosted, 900M visits a month
Replit$9B (Mar 2026)~$525M, Sacra est. (Apr 2026)Replit Database, on NeonPivoted to non-programmers after 9 years
Bolt (StackBlitz)~$700M (Jan 2025)$40M ARR, Sacra est. (Mar 2025)Bolt Cloud on Supabase, hosting on Netlify7M+ users (Dec 2025)
v0 (Vercel)$9.3B for Vercel (Sep 2025)Vercel revenue +82% a yearDeploys to Vercel3.5M v0 users (2025)
Base44~$80M + earn-outs, Wix (Jun 2025)Not disclosedWixOne founder, six staff, no outside funding
Every builder now owns, or rents, a backend and a host. Revenue figures are self-reported or analyst estimates.

Sources: TechCrunch; Sacra; Sacra (Bolt); SaaStr; Calcalist

Read together, the money says two things. First, the largest sums are going to tools that make professionals faster, not to tools that replace them. Second, the builders that sell to non-programmers can reach hundreds of millions in run-rate within about a year, but, as the next sections show, that revenue is unusually fragile.

Adoption: pros use AI daily but don't vibe code#

The clearest single data set on who vibe-codes is Stack Overflow's 2025 developer survey. It asked whether "vibe coding", which it defined as generating entire applications from prompts, was part of respondents' professional work. Of the 26,564 developers who answered, 72.2% said no and another 5.3% said "no, emphatically". Only about 15% said yes in any form.

Is vibe coding part of your professional work?

Stack Overflow Developer Survey 2025, 26,564 respondents

Is vibe coding part of your professional work?
LabelValue
No72.2%
No, emphatically5.3%
Yes, in some form~15%
More than three in four developers say vibe coding isn't part of their job. The remaining answers were unsure, had only tried it, or were uncategorised.

Source: Stack Overflow, 2025 Developer Survey: AI

That isn't because developers avoid AI. The same survey found 84% use or plan to use AI tools, up from 76% in 2024; 78.5% use them already, and 50.6% of professional developers use them every day. What they don't do is hand over the wheel. In the survey, positive sentiment toward AI tools fell from over 70% to 60%, more developers distrust the accuracy of AI output (46%) than trust it (33%), and 66% name answers that are "almost right, but not quite" as their top frustration. Agents had not gone mainstream by mid-2025 either: 14.1% of respondents used them daily at work.

How developers use AI tools

Share of respondents, Stack Overflow Developer Survey 2025

How developers use AI tools
LabelValue
Use or plan to use AI tools84%
Use AI tools now78.5%
Professional developers using AI daily50.6%
Use AI agents daily at work14.1%
AI assistance is close to universal; letting an agent run unattended is still a minority habit.

Source: Stack Overflow, 2025 Developer Survey: AI

Inside large companies, the share of code written by AI keeps climbing, but always with a human reviewer in the loop. Google says three-quarters of its new code is now AI-generated and reviewed by engineers, up from about a quarter in October 2024 and half in the fall of 2025, Business Insider reports. Satya Nadella estimated in April 2025 that "maybe 20%, 30%" of the code in Microsoft's repositories was written by software. Snap says at least 65% of its new code is AI-generated, and Meta set a goal for the first half of 2026 that 65% of engineers in its creation org write more than 75% of their committed code with AI, according to the same Business Insider report.

Share of new code written by AI at large tech companies

Company statements, Oct 2024 to Apr 2026

Share of new code written by AI at large tech companies
LabelValue
Google, Oct 202425%
Microsoft, Apr 202520–30% (CEO estimate)
Google, fall 202550%
Snap, Apr 2026≥65%
Google, Apr 202675%
Google's share tripled in 18 months. All of these figures describe AI-written code that engineers review, which is the opposite of Karpathy's definition.

Sources: Business Insider; CNBC

The two pictures fit together once you separate the populations. Inside companies, AI writes most of the code and engineers read it, which is AI-assisted engineering. Vibe coding is mostly someone else: people who don't read the diff, and often couldn't. That second group shows up in sign-up counts rather than in developer surveys. GitHub says more than 36 million developers joined it in a single year, more than one per second, and ties the step-change to the launch of Copilot Free in late 2024; 80% of new developers on GitHub use Copilot in their first week. GitHub counts accounts, not people, but the direction is clear.

There's also a perception gap worth knowing about. In a randomised trial by METR, 16 experienced open-source developers worked through 246 tasks on projects they knew well. With AI tools allowed, they took 19% longer, yet afterwards they estimated AI had made them 20% faster. That study used early-2025 tools on mature codebases, so it says little about a weekend prototype. It does say that "it feels faster" is not a measurement.

What gets built, and why builders churn#

There is surprisingly little public data on what people actually build with these tools. The builders talk about audiences, not apps. Bolt describes its customers as "prosumers" and B2B teams doing rapid prototyping and internal tools. Its CEO, Eric Simons, told Sacra that the consumer segment, people building fun side projects and personal apps, churned so quickly that Bolt stopped building the business around them; switching costs were near zero. Product and engineering teams, by contrast, showed what he called classic B2B SaaS retention, and Bolt reoriented toward them from the third quarter of 2025. When companies bring Bolt in, he says, it's first to ship external-facing apps, with internal tools and agents second.

The churn number is the most striking figure in the whole data set. In August 2025 Simons told Business Insider that churn across the AI coding market was running at 20% to 40%, and declined to give Bolt's own figure. His explanation was structural: a project gets built, and then there's less reason to keep paying. He contrasted this with Wix, whose recurring revenue comes mostly from hosting and similar services that people keep paying for long after the site is made. A business that only resells AI inference, he added, is "very fragile".

Traffic data told the same story from the outside. In September 2025 Barclays analysts shared SimilarWeb-based figures showing visits falling after a spring and summer peak: Lovable down 40%, Vercel's v0 down 64% since May, and Bolt down 27% since June, with Replit roughly flat. Barclays warned that much of the headline ARR came from month-to-month subscribers who could leave as quickly as they arrived. Vercel had also added protections against bots scraping v0 output, which may explain part of its drop.

Traffic decline at AI app builders after the 2025 peak

Fall in site visits from the spring or summer 2025 peak, as of Sep 2025

Traffic decline at AI app builders after the 2025 peak
LabelValue
Lovable−40%
v0 (Vercel)−64% (since May)
Bolt−27% (since June)
Each bar is a decline, not growth. Replit, not shown, was roughly flat over the same period. Part of v0's drop may come from new anti-bot measures.

Source: Business Insider, citing Barclays and SimilarWeb

The builders' answer was to stop selling only generation. Alongside those comments, Bolt overhauled its plans so every tier includes hosting, domains, databases, serverless functions, authentication, SEO, Stripe payments and analytics, delivered through partners Netlify and Supabase; the entry price rose from $20 to $25 a month. Over the summer and fall of 2025, Replit launched Replit Database, Bolt launched Bolt Cloud and Lovable launched Lovable Cloud, each aimed at the recurring revenue that comes from an app being used rather than created. Bolt and Lovable built theirs on Supabase's white-label product; Replit chose Neon. Bolt now says it is profitable, with gross margins of around 70%, and that B2B makes up about 25% of revenue and is growing quickly.

Where the apps end up#

If you want to know where vibe-coded apps live, follow the backends and hosts, because that's where the most concrete numbers are.

Supabase is the clearest case. In June 2026, announcing its Series F, it said database launches on its platform had grown 600% in a year and that more than 60% of new databases are launched by some sort of AI tool. It says nearly 10 million developers now build on it, more than double the count eight months earlier, and that growth has accelerated since January 2026 as Claude Code and Codex widen the pool of people who can build. Its CEO told CNBC that Claude Code is the single largest contributor of new databases in 2026, and that the company has more than 250,000 customers. "Developers" here means registered accounts, and Sacra estimates paying customers are about 2.5% of them, paying roughly $700 a year each.

Supabase in numbers, Jun 2026

>60%

New databases launched by an AI tool, Jun 2026

Self-reported

Source: Supabase

600%

Growth in database launches over 12 months, Jun 2026

Self-reported

Source: Supabase

~10M

Registered developers, Jun 2026

Cumulative sign-ups

Source: Supabase

~$170M

Annualised revenue, May 2026

Analyst estimate

Source: Sacra

Sacra's reading of these numbers is that coding agents are moving Supabase's distribution away from the high-churn prosumer channel of the vibe-coding platforms and toward the agents developers use every day. In other words, a growing share of new AI-built apps doesn't come from an app builder at all. It comes from someone running Claude Code or Codex on their own machine.

Hosting shows up in two places. Netlify says more than 1 million AI-generated sites built with Bolt were deployed on it between November 2024 and March 2025, about five months; it doesn't define what counts as a site. And the builders have become hosts themselves: Lovable says it now hosts 60 million projects that attract 900 million visitors a month. v0 deploys straight to Vercel, which reported 3.5 million v0 users in 2025.

The vibe-coded app pipeline, and who sits at each step

From prompt to a link someone else can open, as of Oct 2026

  1. Prompt

    Someone describes the app they want, in a browser or a terminal.

    • App builders

      Lovable, Bolt, Replit, v0, Base44: aimed at people who may never read the code.

    • Coding agents

      Claude Code, Cursor, Codex: run on the user's own machine, mostly by developers.

  2. Generate

    The AI writes the frontend, and often the schema and access rules too.

    • Inside companies

      Google says 75% of its new code is AI-generated and human-reviewed.

    • Outside them

      72.2% of surveyed developers say vibe coding isn't part of their work.

  3. Backend

    Data, sign-in and storage get provisioned, usually automatically.

    • Supabase

      Over 60% of new databases are launched by AI tools; Claude Code is the largest source.

    • Builder backends

      Lovable Cloud and Bolt Cloud white-label Supabase; Replit Database runs on Neon.

  4. Deploy

    The app gets a public URL.

    • Builders as hosts

      Lovable says it hosts 60M projects with 900M monthly visits; v0 deploys to Vercel.

    • Platforms

      Netlify served 1M+ Bolt sites in five months.

  5. Share

    Someone else opens it, signs in and uses the same data.

    • The gap

      No public data on how many apps get shared, with how many people, or for how long.

Every step up to deploy has a company and a number attached. The last step, the one that decides whether an app is used by more than its author, has neither.

Sources: Supabase; CNBC; Sacra; TechCrunch; Netlify; Business Insider; Stack Overflow

The pipeline view makes one thing obvious. The app builders own every step inside their own walls, which is why they're turning into hosts. The coding agents own only the first two: they write the code and, increasingly, spin up a Supabase project, but there's no built-in step that turns the result into a link a colleague can open with the right permissions.

Risks: what goes wrong#

The same properties that make vibe coding fast (nobody reads the code, the backend is provisioned automatically, the app is public by default) are what make it risky. The incidents and studies below are the best-documented ones.

Open databases behind public apps#

The most cited case is CVE-2025-48757. A scan of the homepages of 1,645 apps from Lovable's showcase found 303 endpoints across 170 projects, about 10.3%, with row-level security on their Supabase tables that was missing or wrong. Anyone inspecting the network traffic could read or write whole tables, exposing user records, transactions and API keys. The CVE carries a critical score of 9.3. Two caveats matter. Lovable disputes it, on the grounds that each customer is responsible for protecting their own app's data, and the researchers who published it worked at Replit, a competitor.

CVE-2025-48757: disclosure timeline

Broken row-level security in Lovable-generated apps, Mar to May 2025

  1. 21 Mar 2025

    Scan finds 170 exposed projects

    303 endpoints across 1,645 showcase apps; Lovable is emailed about scope and severity.
  2. 14 Apr 2025

    Independent public exploit

    A Palantir engineer shows live extraction of personal debts, home addresses and API keys; researchers start a 45-day disclosure window.
  3. 24 Apr 2025

    Lovable 2.0 ships a security scan

    The scan checks that some access policy exists, not that it's correct.
  4. 29 May 2025

    CVE published

    CVSS 9.3, critical. Lovable disputes it.
The fix shipped in between checked that a policy existed, not that it protected anything. The CVE came 45 days after the public exploit.

Sources: Matt Palmer, Statement on CVE-2025-48757; NVD

A larger scan in October 2025 suggests the problem wasn't limited to one builder. Escape, a security vendor, analysed more than 5,600 publicly available vibe-coded apps, over 4,000 of them built with Lovable plus samples from Base44, Create.xyz, Vibe Studio and Bolt. It found more than 2,000 vulnerabilities, 400+ exposed secrets and 175 instances of exposed personal data, including medical records and IBANs. The common cause was the same pattern: a Supabase anonymous key in the JavaScript bundle combined with missing or misconfigured row-level security, so much of the data was reachable without signing in. Escape's scans were passive, so treat these counts as a floor.

Escape's scan of public vibe-coded apps, Oct 2025

5,600+

Public apps analysed

Source: Escape

2,000+

Vulnerabilities found

Source: Escape

400+

Exposed secrets

Source: Escape

175

Exposures of personal data, incl. medical records

Lower bound

Source: Escape

GitHub sees the same shift across all code. In its 2025 Octoverse report, Broken Access Control overtook Injection as the most common CodeQL alert, and it now leads in Python, Go, Java and C++, languages where, GitHub says, AI-assisted vibe coding sometimes scaffolds endpoints that look correct but lack critical auth checks.

Code quality#

What studies say about AI-written code

Independent and vendor research, 2024 to 2026

StudySampleFindingDate
Veracode GenAI code security100+ LLMs, Java, JavaScript, Python, C#Risky security flaws in 45% of testsJul 2025
Veracode 2026 reportFollow-up to the 2025 benchmarkAverage security pass rate stuck around 56% for four years2026
GitClear211M lines of codeDuplicated 5+ line blocks up 8x in 2024; moved lines down 39.9%Feb 2025
Google DORAState of DevOps surveyMore AI adoption: code quality +3.4%, delivery stability −7.2%2024
METR16 developers, 246 tasks19% slower with AI, while believing they were 20% fasterJul 2025
Different methods, consistent direction: more code, more duplication, more security flaws, and a gap between how fast it feels and how fast it is.

Sources: Veracode; DevClass on GitClear and DORA; METR via arXiv

Veracode's benchmark found that AI-generated code introduced risky security flaws in 45% of tests, and its 2026 update says the average security pass rate has hovered around 56% for four years. GitClear's analysis of 211 million lines, as reported by DevClass, found that blocks of five or more duplicated lines rose eightfold during 2024, and that 2024 was the first year copy-pasted lines outnumbered moved (refactored) ones. Google's 2024 DORA report, cited in the same article, estimated that more AI adoption improved code quality by 3.4% but cut delivery stability by 7.2%.

What this means if you build with AI#

None of this is an argument against building with AI. The 60 million projects on Lovable and the 600% growth in Supabase databases are people solving their own problems with software they couldn't have written before. But the data points to a short list of habits that separate an app that's useful for a year from one that leaks or disappears.

  1. Check row-level security on every table before you share the link. Roughly one in ten Lovable showcase apps failed this in 2025, and a builder's own "security scan" only checked that a policy existed. Ask your agent to list each table's policies and explain who can read and write each one, then try the app signed out.
  2. Assume anything in your bundle is public, including the database key. Anyone can read it from your JavaScript. Pairing it with open tables is how Escape found 400+ exposed secrets and 175 personal-data leaks.
  3. Keep the agent away from production data you can't lose. Give it a copy, keep backups you control, and don't rely on the agent's own account of what it can undo.
  4. Read the diff where it touches auth, money or personal data. Broken access control is now the most common CodeQL alert on GitHub, and AI code failed Veracode's security tests 45% of the time. Vibe the layout; review the permissions.
  5. Make sure your data is exportable from day one. Builders churn 20% to 40%, pricing changes, and companies get acquired. If the tool goes away, a JSON export is the difference between moving and starting over.
  6. Default to private for anything sensitive. Most of the exposures above came from data that was reachable without signing in. An internal tool for five colleagues doesn't need to be reachable by everyone on the internet.
  7. Pick hosting that outlives the project. Projects are one-off; the app often isn't. Bolt's CEO attributes Wix's lower churn to hosting, the thing people keep paying for after the build is done. Choose a place where the app can keep running, and keep being shared, long after you've closed the chat.
  8. Measure speed, don't feel it. Experienced developers in METR's trial were 19% slower with AI while believing they were 20% faster. If speed is the point, time it.

The last two steps of the pipeline, deploying and sharing with the right people, are the ones with the least tooling and the least data. That gap is why we're building host0: a place where an app your agent built gets a URL you can share with your team, with a database that already exists.

Methodology#

This post is built on a deep-research run we completed on 5 October 2026. It covered six angles: the origin of the term, money, adoption, what gets built, hosting and backends, and risks. The run fetched 29 sources and extracted 140 individual claims, each with a quote and a date. The 25 claims that carry the most weight were each checked by three independent adversarial verification passes, and a claim survived only if at least two of the three upheld it. We then spot-checked the remaining gaps by hand, looking for a second independent outlet, and before publishing re-opened the single-source figures we lean on hardest to confirm they were still on the page.

We dropped anything that didn't hold up: a widely repeated claim that larger, newer models produce more secure code than smaller ones (it was refuted in verification), a breach of a popular dating-safety app that is often cited as a vibe-coding failure but was never shown to involve AI-written code, a prediction attributed to a Microsoft executive and a widely quoted app-generation rate for v0, neither of which we could find in the cited source, and figures from statistics-aggregator sites that mix estimates with facts. Where a figure rests on one outlet, the text names it. Every figure links its source inline, and every chart lists its sources underneath.

Limitations:

  • Vendor numbers are self-reported. Revenue, user counts and "developers" come from companies, usually during a fundraise, and nobody audits them. "Developers" often means cumulative sign-ups.
  • ARR usually means run-rate. Most figures project a recent month over a year, so they move fast in both directions.
  • Traffic is a proxy. The Barclays figures measure site visits, not paying users, and bot filtering can distort them.
  • Security scans are samples. Both scans looked at public showcase or discoverable apps and were passive, so they understate the problem rather than overstate it, and they say nothing about private apps.
  • Everything has a date. This market changes monthly. Every figure in this post carries the date it refers to; GitHub's 2026 Octoverse and Stack Overflow's 2026 survey results weren't out when we wrote it.

Open questions#

The public data has clear holes. These are the questions we couldn't answer from any source:

  1. Retention by builder. The only figure is the market-wide 20% to 40% quoted by Bolt's CEO; no builder publishes its own.
  2. App lifespan. What share of vibe-coded apps are still live, or still used, 30 days after they're created?
  3. Deploy and share rates. What share of generated projects ever get a public URL, and how many are opened by anyone other than their author?
  4. Personal, team or production. How much of what gets built is a personal tool, a team tool or a customer-facing product?
  5. Independent deployment counts. Every deployment figure we found comes from the host or builder itself.
  6. Whether security has improved. The large scans date from 2025. We found no comparable scan from 2026.

Several of these are questions host0's own data can start to answer, and we plan to publish what we find in a follow-up post.

ResearchVibe coding

Built something? Put it online in seconds

host0 is the cloud for small software: bring any coding agent, build the tool only you need — like this one — and say "deploy to host0". Live at a shareable URL, no servers to run.