Vespez Research — October 2026

We scanned 100 Lovable apps for GDPR and security. Not one came back clean.

100 apps from the Lovable showcase 86 successfully scanned Public pages only

Every single app that could be scanned had at least 3 likely issues. The median app had 6. Here is what we found.

How we did it

100 apps were taken from the public Lovable showcase. Each was scanned on its public pages only — no logins, no databases, nothing behind authentication. Vespez assigned each app a security score and a GDPR score (0–100), plus a count of findings. Every result below is a "likely issue." Automated scanners can be wrong, and findings have not been individually verified by hand. We are publishing totals only — no app names — because the point is the pattern. Where we found something serious, we contacted the owner privately.

14 of 100 couldn't be scanned

13 apps didn't respond at all. 1 was only reachable over plain http://. That leaves 86 apps scanned.

14% of the showcase was dead, moved or unreachable. That says something about how long many of these projects actually live.

GDPR: this is where it falls apart

38
Average GDPR score (out of 100)
45
Median GDPR score
62%
Scored below 50
16%
Scored exactly 0
Scored 60 or higher38% (33 apps)
Scored 80 or higher3 apps

A score of 0 means the scanner found the basics missing: a privacy policy, a cookie consent flow, trackers loading before consent. These aren't exotic findings. They are the first things a regulator or a client's lawyer looks at.

Security: mostly average, with a long tail

77
Average security score (out of 100)
80
Median security score
26%
Scored below 80
45
Lowest score recorded

59 of 86 apps landed on exactly 80 — which suggests one common issue that most apps share. Only 5 scored 90 or higher.

1 app exposed a live OpenAI API key in its frontend JavaScript. That key was readable by any visitor. We contacted the owner privately before publishing this.

96% of scanned apps had no Content-Security-Policy header — meaning the browser has no instruction on what scripts or resources the page is allowed to load.

Findings per app

Custom domains did worse on GDPR

lovable.app subdomains

44
avg. GDPR score · 36 apps

Custom domains

34
avg. GDPR score · 50 apps

Small samples, so treat it as a pattern worth checking, not a law. Apps on their own domain are more likely to be real businesses with real visitors — which makes the gaps matter more, not less.

What this means

AI builders make it easy to ship something that looks finished. They don't prompt you to think about consent banners, privacy policies, or what a tracker does before the visitor says yes. If you build apps for clients, that gap becomes your problem at handover.

A quick pre-launch checklist:

Limits of this study

100 apps from one showcase is not all of Lovable. Showcase apps skew toward hobby projects. The scores come from Vespez, so they reflect what Vespez checks. These are likely issues, not confirmed violations — some will be false positives.

Check your own app Vespez is free to try. We'd rather you tell us where it's wrong than where it's right.
Try Vespez →