Skip to main content

Cybersecurity statistics / Coding Agents

Related statistics

Of three leading coding agents evaluated (Claude, Codex, and Gemini), Codex finishes with the fewest vulnerabilities and demonstrates stronger remediation behavior during development.
DryRun Security, 27/05/2026
26 of 30 pull requests (87%) introduce at least one vulnerability.
DryRun Security, 27/05/2026
Anthropic's Claude produced the highest number of unresolved high-severity vulnerabilities in the final applications.
DryRun Security, 27/05/2026
143 security issues are identified across 38 security scans.
DryRun Security, 27/05/2026
No AI coding agent evaluated (Claude, Codex, and Gemini) produced a fully secure application.
DryRun Security, 27/05/2026
Four authentication-related weaknesses appeared in every final codebase: insecure JWT verification and management; lack of application-level brute force protections; exposure to token replay attacks; and insecure defaults for refresh token cookie configurations.
DryRun Security, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.