DIY STRESS TEST

Patch the app

👇Click to find the flaw 👇

close
0:28

Found  

1

/3

Login form

API response

Password reset

REVEALED FLAW

No rate limiting.

1,000 login attempts per second are accepted with no lockout. Attackers brute-force passwords in minutes, not months.

REVEALED FLAW

Sensitive data in headers.

The response returns email, subscription tier, and account age in plain response headers — visible to anyone who opens DevTools.

REVEALED FLAW

User enumeration via timing.

Password reset takes 200ms for real accounts, 1ms for fake ones. An attacker can build a list of every valid email in seconds.

Time's up!  

You found

X

of 3.

But AI coding tools missed all 137 critical edge cases.

Get the full report on all 137

THE SECURITY COST OF VIBE CODING: A STUDY

We built four apps just
to break them.

We gave four AI coding tools the same prompt. The apps shipped, so did 137 vulnerabilities across 4 different ways of getting the same 9 things wrong.

Findings surfaced by Astra's autonomous pentesting agents.

DIY STRESS TEST

Patch the app

3 flaws, 30 seconds, zero shortcuts. Spoiler alert: AI coding tools had way longer,
and still missed 137 of these.

HOW TO PLAY

You have 30 seconds - the countdown starts when you click Start

Find the hidden flaw in each card.

Can you find all 3, before the timer hits zero?

THE METHODOLOGY

Same build, same pressure, every time

Emergent, Replit, Lovable, and Base44 all received an identical prompt, no advance notice, and
the same bar for what counted as a real finding with Astra's autonomous pentesting platform.

Zero advance notice to ensure unbiased & authentic testing.

No platform knew this was coming, and no vendor relationship affected access, testing, or results.

2 autonomous pentest bots that don't talk to each other.

Structured Pentest mapped the app and built attack chains, while Bug Bounty Hunter Bot went in cold, simulating an unbriefed attacker.

A validator agent tried to break every finding again.

Nothing moved forward until it was independently reproduced.

Then a human security engineer checked it all anyway.

Every finding was reviewed a second time before it counted, and anything unconfirmed was cut before analysis.

THE WEAK POINTS

Four builds, one failure mode

Four separate codebases, four separate frameworks, and the same nine weak points gave out anyway.

The four pressure points

Prompt specificity

Vague asks, like “secure login,” instead of an exact threshold.

Finding volume vs. severity

High counts didn’t mean higher risk. Severity did.

Access control enforcement

The most severe failure, when it appeared, almost every time.

Fix complexity

Config-level for the universal patterns, data-layer for the rest.

See exactly where all four
builds gave out, and how to
reinforce yours.

Download the Report

Log in 8 times with the wrong password.

Attempt 6 should return a 429, not a 200.

Check any response's headers in DevTools.

No Content-Security-Policy means this is already a real finding.

Reset a password with a fake email, then a real one.

The response, wording, and timing should be identical either way.

See what gave out

Your next AI-generated app
hasn't been through this yet

Get the full report for every fracture point, every fix, and the prompt
built to hold up before you ship.

Get the PDF

Does the State of Continuous Pentesting Report include security recommendations?

Yes. Every finding in the report is paired with a specific, actionable recommendation. We don’t provide generic best-practice advice. These recommendations are extracted directly from the data. Some practical implementation recommendations include which surface to prioritize based on the findings, whether you need to move from total-count dashboards to severity-weighted reporting, and what a cross-surface testing scope should cover to close the credential exposure gap. The report also includes the OWASP APTS governance framework for organizations evaluating autonomous pentesting tools in 2026, co-authored by Astra Security.

What is the State of Continuous Pentesting Report?

The State of Continuous Pentesting Report is Astra Security's annual data analysis of the risk profile and vulnerabilities from real-world security programs. The aim of the report is to help security leaders understand what the programs are measuring wrong and what that gap is costing them. The 2026 edition is built on 6.8 million findings from 150,000+ scans and 8,000+ engagements across 1,000+ organizations in 70 countries. In contrast to generic, survey-based industry reports, this year’s report is based on actual penetration tests conducted across web, API, cloud, mobile, and network environments over the past year.

How does Astra Security collect data for the State of Pentesting Report?

The entire data in the report comes directly from penetration tests conducted by Astra Security in 2025. This includes automated scans, manual pentests, and continuous testing engagements spanning across six attack surfaces: web applications, APIs, cloud infrastructure, iOS, Android, and network. We have not used any modeled estimates, nor have we used third-party data sets.

Important Note: All findings are anonymized and aggregated from real pentesting activity on Astra’s platform. We never share customer data, company names, or vulnerability specifics, only data-backed insights to elevate your security posture.

I have a specific scope, can you tailor the pricing?

Absolutely, you can schedule a call with our sales engineers. In the call they review the scope, show our platform and are happy share a tailored pricing specific to your needs.
Click here to update your cookies settings