Quttera research finds AI builders shifting web security into publish decisions

Quttera research finds AI builders shifting web security into publish decisions

–

A fresh study explores how AI application builders are embedding security into the publishing process—and why ongoing verification remains essential after an asset goes live.

Security for websites and web applications is moving into the publishing decision. Publication is still a point in time, so integrity evidence must continue after the asset goes live.”— Michael Novofastovsky, CTO & co-founder, Quttera

Quttera Research: Website Security Is Shifting Into the Publish Decision Across AI Application Platforms

Quttera, a firm specializing in continuous website and web application integrity monitoring, has unveiled a new study that examines how web security is migrating earlier in the software lifecycle—moving from post-deployment add-ons to the exact moment a website or application is published.

The report, titled “Security Is Moving Into the Publish Flow,” investigates how AI application platforms—including Base44, Lovable, and Replit—are embedding web application security scanning directly into development and publishing workflows. It contrasts this approach with the more open, DIY security model traditionally seen on platforms like WordPress.

“Security for websites and web applications is moving into the publishing decision,” stated Michael Novofastovsky, CTO and co-founder of Quttera. “But publication is still a single point in time. Integrity evidence has to continue after the asset goes live.”

Each platform examined in the research follows a distinct path toward the same goal. Base44 displays application security status and scan results within its production workflow. Lovable runs a basic security scan automatically whenever an application is published, and allows administrators to block publication when critical issues remain unresolved. Replit combines pre-publication security analysis with ongoing dependency monitoring after the application is live.

While the specifics differ across platforms, Quttera’s analysis identifies a consistent trend: the question developers once had to answer on their own—“Have I secured this correctly?”—is now increasingly addressed inline, at the point of publishing.

This shift prompts the central question the research explores: what happens after Publish?

A security check performed at deployment does not permanently ensure that a live web asset remains safe. Dependencies are updated. New vulnerabilities are disclosed. Third-party scripts and embedded resources can change behavior without a new deployment. Credentials can be compromised. Configurations drift. Content changes. The asset verified at launch is not guaranteed to remain in the same state weeks—or even hours—later.

To bridge this gap, Quttera’s research distinguishes between two complementary perspectives on a live asset’s security and integrity.
Platform-native security draws on internal information only the builder can see: source code, installed packages, permissions, configuration, and build history.

Independent deployed-state verification instead examines what the live asset actually presents and does from the outside—its public pages, delivered scripts, redirect behavior, and blacklist or reputation status—regardless of which platform created it.

The research also looks ahead to how this question may expand as websites and applications become accessible not just to human visitors and browsers, but directly to AI agents. It points to the WebMCP Community Group draft, which explores how web applications could expose structured capabilities for AI agents to discover and invoke—meaning a live web asset may increasingly be something an AI system acts through, not only something a person views, or a crawler reads.

The analysis also cites Cisco Talos research documenting a case in which attackers used an AI-assisted web application platform to build a credential-harvesting page—illustrating, Quttera argues, how the same tools that lower the barrier to building legitimate web applications can also lower the barrier to building abusive ones.

Quttera calls this ongoing-verification model Continuous Web Integrity: maintaining evidence about a live web asset’s security and integrity over time, rather than treating a single successful scan, deployment, or approval as permanent proof of safety.

The research does not announce integrations with Base44, Lovable, Replit, or any other AI application platform. Instead, Quttera says it is studying where independent, platform-agnostic evidence can complement—not duplicate—the website and application security controls these platforms already provide.

The full research, “Security Is Moving Into the Publish Flow,” is available on the Quttera Blog.

About Quttera

Quttera delivers continuous integrity and threat monitoring for websites and digital assets that must remain safe, discoverable, and commercially viable for both human visitors and AI-driven systems. Its patented behavioral engine and API-first architecture protect the live environment where modern risks emerge after deployment, between audits, and beyond point-in-time validation.

Quttera Media Relations
Quttera Ltd
+1 323-540-5642
contactus@quttera.com
Visit us on social media:
LinkedIn
Facebook
YouTube
Other


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.