research
security
How Non-Technical Founders Are Shipping Real Apps Without Engineers — and What It's Costing Them
The shift is real
A few years ago, "I built an app" from a non-technical founder usually meant a no-code tool with hard limits, or a freelancer hired off Upwork. Today it increasingly means: they described it to Lovable, Bolt, Replit, or v0, and a working product came out the other side — auth, database, payments, all of it.
Roughly 84% of people using AI coding tools have no engineering background. That's not a fringe stat about hobbyists — it's the majority of the user base. The barrier to shipping a real, working product has effectively collapsed, and that's genuinely good news for anyone who's ever had an idea and no way to build it.
The part that doesn't show up in the demo
Here's what that same shift quietly created: a huge and growing number of production apps, handling real user data, built by people who were never in a position to know what "check your RLS policies" even means — because nobody told them it was something to check.
The numbers back this up:
- AI-generated code has roughly 2.7x more security flaws than human-written code, on average.
- About 1 in 3 publicly scanned AI-built apps had a serious, exploitable flaw.
- Some studies of AI-built apps have found figures as high as ~67% with critical vulnerabilities.
These aren't apps built by careless people. They're apps built by people who did exactly what the tools promised — describe it, ship it — and were never given a reason to think about the plumbing underneath. A professional developer checks for exposed keys and open databases out of habit, built from years of getting burned. A first-time builder using an AI tool has no equivalent instinct yet, because nothing in the experience prompts one.
Why this gap is invisible until it isn't
The apps work. That's the whole problem — a leaked Stripe secret key or an open Supabase table doesn't break anything visibly. Signup still works, the dashboard still loads, the demo still looks great. The only way to find out something's wrong is to specifically go looking, or to have someone else find it first — and "someone else" finding it first is rarely a friendly discovery.
Meanwhile, the people building these apps are already paying real money for the privilege of speed: Lovable, Bolt, and Replit users are already spending $20–25/month on their build tools. Security has, so far, been an afterthought bolted onto that spend rather than a default part of it.
What actually helps here
Not "learn to code" — that defeats the entire reason these tools exist. What helps is something that does the checking automatically, explains findings in plain English instead of developer jargon, and tells you exactly what to paste back into your AI builder to fix it. Continuous, not one-time — because a fresh AI generation can just as easily reintroduce a fixed issue as a new feature next week.
That's the gap between "anyone can build an app now" and "anyone can build a safe app now." Closing it doesn't require turning every founder into a security expert. It requires giving the AI builder a second pass it was never designed to give itself.
Find out where your app stands: run a free scan — no login, no code, just a URL and sixty seconds.
Hardik Desai


