Most common vulnerability classes in AI-built apps
Distribution of finding categories across the Vibe Security 50 controls. Which controls most frequently produce detected candidates, and which most frequently produce verified findings.
Research
Original research from LyraShield AI scans. All statistics are derived from anonymized, privacy-safe scan metadata — no target names, repository URLs, finding payloads, user identities, or IP addresses are published.
Last updated:
Distribution of finding categories across the Vibe Security 50 controls. Which controls most frequently produce detected candidates, and which most frequently produce verified findings.
What fraction of detected candidates are independently verified? What fraction of verified findings are retest-confirmed after a fix? How many remain inconclusive?
Which of the 7 evidence-required controls most frequently lack operational or human evidence outside the scan? Which of the 43 code/URL review controls most frequently return inconclusive?
When a fix proposal is generated and applied, how often does the retest confirm the condition is absent? How often does it remain inconclusive? This measures the effectiveness of the fix-then-retest loop.
How do finding rates, coverage, and evidence-state distributions differ across scan modes? Are there control categories where deeper analysis consistently produces more verified findings?
When published, statistics on this page may be cited as: "LyraShield AI, [report name], lyrashieldai.com/research, [access date]." Each statistic includes its sample size, control version, and collection period. Do not cite a statistic without including its stated limitations.
Registration is open in the beta. New research is published to the guides feed.