Comparisons
Builderdex Editorial12 min read15 views

AI App Builder Security Scanning (2026): Which Builders Scan the App They Just Wrote

Four of eight AI app builders ship a scanner that audits the app their AI generated. Base44, Lovable, Bolt.new and Bubble all scan, and all four put the paywall somewhere different. A 2026 comparison of what each one checks and what it costs.

Flat schematic diagram in slate blue on a cream background: one tall rounded rectangle representing an application, connected by straight lines to a vertical stack of eight rounded rectangles representing security scan findings, each marked with a small circle.
Flat schematic diagram in slate blue on a cream background: one tall rounded rectangle representing an application, connected by straight lines to a vertical stack of eight rounded rectangles representing security scan findings, each marked with a small circle.
On this page

Quick answer. Four of the eight builders in this comparison ship a scanner that inspects the app the AI just wrote: Base44, Lovable, Bolt.new and Bubble. The other four do not. Replit and Softr hand you a written checklist, v0 documents security analysis that protects its own platform rather than auditing your project, and Webflow reduces the surface area instead of scanning it. Among the four that do scan, the interesting difference is not depth but where each one puts the paywall, and all four put it somewhere different.

AI app builder security scanning at a glance, October 2026

Scroll to see more

BuilderScans the app it wrote?Deepest check availableWhere the paywall sits
Base44 logo Base44Yes, 7 finding classes, plus optional WizCode vulnerabilities, mapped to OWASP and CWEScan is free on every plan; code-vulnerability scanning needs Builder or above
Lovable logo LovableYes, Quick scan on every publish plus a Deep scanDeep scan over all application code, plus Wiz and Aikido connectorsScanning is free; the conversation about findings costs credits; scheduled scans are Enterprise
Bolt.new logo Bolt.newYes, project audit plus a separate database checkFull project audit across 6 categoriesProject audit is paid plans only; database check is on all plans
Bubble logo BubbleYes, security dashboard with issues explorer10 basic plus 12 advanced checksDetection runs on every plan; the explanation is withheld below Growth
Replit logo ReplitNo scannerA written security checklist with agent promptsn/a
Softr logo SoftrNo scanner for self-serveServer-side architecture plus a do and do-not guideSecurity audit is Enterprise plan only
v0 logo v0No, and the analysis points the other wayPlatform-side code analysis before executionn/a
Webflow logo WebflowNo, by designFewer dependencies to have vulnerabilities inn/a

The real finding: four scanners, four different paywalls

Every comparison of this category treats a security scanner as a feature you either have or do not have. Read the four that have one side by side and the feature is almost the same each time. What differs is the commercial boundary, and the four arrangements are mutually exclusive.

Base44 gives the scan away and gates the deepest check. Its documentation is explicit that "The security scan is available on all plans, including the free plan." Six of its seven finding classes are therefore free forever. The seventh, code vulnerabilities, carries its own notice: "Code vulnerability scanning is available on the Builder plan and above." So a free Base44 user gets told about exposed secrets and missing permission rules, and is not told whether the code itself contains an exploitable pattern.

Bolt.new inverts that. Its full audit is listed as "Available on paid plans", while the narrower database review is "Available on all plans." A free Bolt user gets the database half and none of the code half. The dividing line is the same shape as Base44 and falls on the opposite side.

Bubble does something stranger and more interesting than either. Its advanced checks page states that "detailed information is limited unless your plan includes advanced checks." The detection itself is not gated. On the Starter plan Bubble will tell you that one of twelve advanced issues exists in your app, including database exposure risks, unprotected backend workflows and compromised API tokens, and will not tell you which or where. That is a genuinely unusual product decision: you are sold the alarm and charged for the diagnosis.

Lovable gates neither, and charges for the conversation. Running either scan is free, and so are the first ten fixes. But asking the assistant to review your security in the project chat "is treated as standard build usage and consumes credits", and so is referencing a finding in chat to ask about it.

Nobody writing about this category has set those four sentences next to each other, because doing it requires reading four separate billing-adjacent pages that each sit one click away from the security documentation rather than in it.

The button is free and the chat costs money, on two platforms independently

The Lovable boundary above has an exact counterpart at Bolt.new, and the two vendors arrived at it separately. Bolt is blunt about it: "Always use the Run security audit button in the Publish menu to audit your project, since this option doesn't use tokens. Prompting Bolt to audit your project decreases your token balance."

Two platforms, two different currencies, the same rule. The deterministic scanner is free because it is cheap to run; the model reading your code conversationally is metered because it is not. The practical consequence is identical on both: if you ask the assistant in chat to check your app over, you pay for an answer that the button beside you would have given for nothing. This is worth knowing precisely because the chat is the interface these products train you to use for everything else.

Bolt adds the only documented rate limit on this axis in the whole comparison: "You can run up to 30 security audits per day."

Static analysis, and the one platform that goes dynamic

Every scanner here reads your code and configuration and flags patterns that look wrong. That is static analysis, and it has a known ceiling: it tells you what looks exploitable, not what is.

Lovable is the only platform in the set that documents a route past it, and it explains the distinction itself. Its built-in scanners and the optional Wiz connector are static. Its Aikido connector is not: AI agents "interact with your running application, send real payloads, and attempt to exploit authentication, authorization, and API flows like a real attacker would." The consequence Lovable draws from that is the part worth quoting, because it is a claim about false positives rather than about coverage: "every reported finding is exploitable rather than theoretical."

Lovable also publishes the sequencing, which is the kind of thing vendors usually leave you to work out: "The recommended order is: run the security scanners first, fix what they surface, then validate with a pentest before a major release."

Base44 and Lovable both integrate Wiz, and both describe it the same way, as software composition analysis for third-party packages your app depends on plus static testing of your own source. Base44 requires the Builder plan or higher for it and runs the Wiz CLI "in an isolated, single-use sandbox" against your own tenant, so the scan follows your organisation policies rather than Base44 policies.

What the scanners actually look for, and the one class unique to this category

The finding classes overlap heavily across the four scanners, as you would expect: permissions, authentication, injection, exposed credentials, vulnerable dependencies. Base44 groups its seven as data permission issues, exposed secrets, unauthenticated backend functions, credit protection, app dependencies, code vulnerabilities and security header recommendations. Lovable splits a Quick scan covering database review, dependency audit and an MCP server check, from a Deep scan adding access control, abusable endpoints, injection, leaked credentials, payments and billing, account security and exposed personal data. Bolt covers six categories in plain language, including "Ways your app can be misused", which is its name for business-logic flaws like changing a price or claiming a single-use item twice.

One class has no equivalent in ordinary application security, and it exists only because these are AI builders: credit protection. Base44 scans for whether your own AI, image-generation and email features can be reached from outside your app, because somebody who finds them can run them and spend your integration credits. The threat model is not data theft, it is somebody else spending your balance. No conventional scanner looks for this, because until this product category existed there was nothing to find.

Two other details are worth carrying. Base44 is the only vendor of the nine documentation sets I searched that maps findings to industry classifications, giving each code vulnerability "an OWASP Top 10 category and a CWE number" alongside an attack scenario. And Base44 warns that its own fix for unauthenticated functions can break things, since it rejects any caller with no signed-in user and may therefore break a page for signed-out visitors, a webhook or an external integration. A scanner that documents the blast radius of its own one-click fix is being more honest than most.

Both Base44 and Lovable also surface exposed credentials as a finding class, which makes where each builder stores secrets the upstream question: a scanner that finds a key in your client bundle is telling you the key was in the wrong place to begin with.

The four that do not scan, and why two of them are defensible

Replit publishes a checklist, not a scanner. It is a real document with code samples and ready-made prompts to paste at the agent, and it is honest about its own position: "it's important to understand and implement more security measures for your specific application needs." That is guidance, and guidance only helps the people who go and read it.

Softr gates its audit entirely. Its app-security page is a careful architectural explanation of server-side evaluation plus a do and do-not list, and then one line settles the axis: "Security audit is available for users on the Enterprise plan." For everyone below Enterprise, Softr is guidance too.

v0 is the sharpest case, because it looks like it has a scanner and the scanner is pointed elsewhere. Its security documentation describes real analysis: "We consider all code potentially incorrect or adversarial" and "All generated code undergoes security analysis before execution." Read carefully, that is v0 defending the v0 platform against the code its own model produces, which is a sensible thing to do and is not an audit of your project. The one genuinely user-facing check is narrow: v0 analyses where you have used the public environment-variable prefix and warns when that looks risky. Useful, and not a scanner.

Webflow declines the axis on purpose, and the argument is coherent. It has no app scanner and does not pretend to, positioning instead on having less to scan: "No customer-managed updates, no dependency drift, and far fewer vulnerabilities to track." Its vulnerability programme points inward, a formal Vulnerability Disclosure Program for reporting flaws in Webflow itself. If you are shipping a marketing site with no custom backend, fewer dependencies really is a better answer than a scanner. If you are shipping an application with its own data model, it is not an answer at all.

The one public artefact nobody else has

Lovable publishes a Trust center on the app's own domain, a human page at a well-known trust path and a machine-readable equivalent beside it. It is the only thing in this comparison that turns a security scan into something you can show a customer, and Lovable names automated vendor review by "An AI agent doing an automated vendor review" as an intended consumer. It generates a software bill of materials "in a standard format (CycloneDX) that security tools can read", though the inventory itself is not publicly downloadable.

Its stated limitations are more useful than the feature. "Only checks that currently pass are included." And therefore: "If a check is omitted, Lovable makes no claim about its state." A reviewer cannot tell from the page whether an omitted check failed or was never run. Lovable says so itself, which is the correct disclosure and also means the page is weaker evidence than it first appears. Lovable also notes that "The page is excluded from search engines." It is a link you send, not a page anyone finds.

Verdict, October 2026

If you want the most scanning for nothing, Base44. Six of seven finding classes on the free plan is the most generous position in the comparison, and the OWASP and CWE mapping means a finding is something you can hand to someone who knows what it means.

If you want the deepest assessment and will pay for it, Lovable. It is the only platform with a Deep scan over all application code, the only one offering dynamic testing through Aikido, and the only one with a shareable trust artefact. Budget for the credits, and use the buttons rather than the chat.

If you are on Bolt.new, run the audit from the Publish menu before every release and remember the free tier gives you the database half only.

If you are on Bubble below Growth, understand what you have bought. The dashboard will tell you an advanced issue exists and not what it is. That is worth knowing before you rely on it rather than after.

If you are on Replit or Softr self-serve, you are your own scanner. Both document that clearly, and neither is hiding it.

If you are on Webflow with a marketing site, the absence is not a gap. If you have built an application on it, treat the lack of scanning as a real cost.

The axis to watch is whether static scanning stays the default. Lovable has already shipped the dynamic alternative behind a connector, and once one platform in a category demonstrates that findings can be confirmed by exploitation rather than inferred from pattern matching, the standard for what counts as a security scan tends to move.

Sources

All verified live on 5 October 2026. Plan names and gating mechanisms are quoted rather than prices, because the mechanisms outlast the prices attached to them.

Frequently asked questions

Which AI app builders actually scan the app they generate in 2026?

Four of the eight in this comparison: Base44, Lovable, Bolt.new and Bubble. Replit and Softr publish written guidance instead of a scanner, v0 documents security analysis that protects its own platform rather than auditing your project, and Webflow positions on having fewer dependencies to scan rather than on scanning them.

Is security scanning free on these platforms?

It depends which part you mean, and all four scanners draw the line somewhere different. Base44 makes the scan free on every plan but puts code-vulnerability scanning on Builder and above. Bolt.new makes the full project audit paid-plans-only while leaving the database check on all plans. Bubble runs detection on every plan but limits the detail below Growth. Lovable charges for neither scan and meters the chat conversation about findings instead.

What is the difference between a static scan and a penetration test here?

A static scan reads your code and configuration and flags patterns that look exploitable. A penetration test interacts with the running application and tries to exploit it. Lovable is the only platform in this set documenting both, and its Aikido connector is the dynamic half. Lovable argues the practical difference is false positives, saying that because each issue is confirmed through a real attack scenario, every reported finding is exploitable rather than theoretical.

Does Bubble tell me what is wrong on the Starter plan?

Not for the twelve advanced checks. Bubble documents that the dashboard can detect those issues regardless of plan, but that detailed information is limited unless your plan includes advanced checks. In practice that means you can be told an advanced issue exists without being told which one or where. The ten basic checks are fully available on every plan.

Why would asking the AI chat to review my security cost money?

Because the deterministic scanner and the model reading your code are different operations with different costs, and two vendors document exactly that split. Bolt.new says the Run security audit button does not use tokens while prompting Bolt to audit your project decreases your token balance. Lovable treats a conversational security review as standard build usage that consumes credits. On both, the button is the cheaper route to the same answer.

Do any of these scanners map findings to OWASP or CWE?

One. Base44 is the only vendor of the nine documentation sets checked for this comparison whose scanner gives a code-vulnerability finding an industry classification, listing an OWASP Top 10 category and a CWE number alongside an impact summary, the evidence in your code and an attack scenario. That matters if you ever need to hand a finding to somebody who works in those terms.

Is Webflow less secure because it has no app scanner?

Not necessarily, and the answer depends entirely on what you built. Webflow argues it removes the weekly patch cycles and plugin hardening other platforms require, with no customer-managed updates, no dependency drift and far fewer vulnerabilities to track. For a marketing site with no custom backend that is a reasonable trade. For an application with its own data model and authentication, the absence of any scanning is a real cost rather than a simplification.