Method & numbers
How often the free check is right
We publish our accuracy, including the misses. This is the latest run, with everything you need to judge it.
The result
8 of 10 deliberately vulnerable apps caught. 0 false alarms on the 4 clean reference apps. All 14 apps were reached.
Live run on 15 September 2026, one pass, at most about one request a second per app.
What was tested
- The free check only. No login, no ownership proof, no paid key, so no database or AI-endpoint tests. The paid audit's live proofs and code checks are not part of this number.
- gapbench: a public set of 14 small web apps, 10 with planted problems and 4 clean ones. It is maintained by VibeEval, one of the products on our comparison page. We didn't build it, and we don't control it.
- Missing security headers show up on every app, clean ones included, so they're left out of the count.
The misses
- supabase-clone: reached, but nothing reported. Its database runs on a self-hosted server, and we deliberately only test databases hosted by Supabase itself, so the free check records the host and stops there.
- session-fixation: a problem in how logins behave. Spotting it means logging in, which the free check never does.
Caveats
- Fourteen apps is a small set, and planted problems are easier to find than real ones. Treat 8 of 10 as a rough guide, not a guarantee.
- An app counts as caught when the check reports its planted problem. Several findings on one app still count once.
- We'll re-run it when the check changes, and publish the new number here even if it goes down.