Get a Quote

Base44 App Security Audit: Vulnerabilities & Fixes

Base44 (now owned by Wix) lets anyone prompt a full-stack app into existence in minutes — database, auth, and Stripe payments included. It also shipped an auth bypass that let attackers create verified accounts on any Base44 app with nothing but a public app ID. Here’s what’s actually wrong under the hood, and how to fix it.

Get a Free Security Scan Book a Full Audit
What Base44 Builds

A Full-Stack App From a Prompt — Database Included

Base44 is an Israeli “vibe coding” platform, launched February 2025 by solo founder Maor Shlomo, that turns a prompt into a working web or mobile app: frontend, backend, a managed Postgres database, authentication, file storage, and Stripe payments, all in one hosted environment. Wix acquired Base44 for roughly M in a deal announced June 18, 2025 (closed around July 2025), with an additional ~M retention pool for its small team. Base44 passed 400,000 users and, per Wix, scaled to an estimated –100M in annual revenue within months — it now operates as a distinct product under Wix. People use it to spin up internal tools, HR and PII dashboards, customer portals, CRMs, MVPs, booking tools, browser extensions, and Stripe-powered SaaS products.

Platform Security

Base44’s Own Security Posture

This is Base44’s security as a company and platform — separate from whether the specific app it generated for you is secure. Both matter, but they are not the same question.

  • Base44’s Trust Center claims SOC 2 Type II and ISO 27001 alignment, GDPR adherence, row-level security with granular CRUD controls, Google SSO, and pre-deployment scans for hardcoded secrets and exposed endpoints — these are self-reported; no public SOC 2 report or ISO certificate number has been independently located.
  • Payments are delegated to Stripe (PCI-certified); Base44 itself is not PCI-certified.
  • Base44 does not sign a Business Associate Agreement (BAA), and its Terms of Service reportedly restrict storing protected health information (PHI).
  • Unverified, single-source reporting (base44devs.com) describes pricing increases of 15–30% by May 2026, reduced credits, deprecated custom integrations, and a platform-wide outage on 2026-02-03 (2h 53m, HTTP 502s, no SLA) with further incidents on Feb 17 and Feb 20 — treat these as lower-confidence than the Wiz and Imperva findings below.
Common Vulnerabilities

What Breaks in Apps Built With Base44

These are the failure patterns security researchers and Zooc Digital audits actually find in live Base44 apps.

1. Broken or missing row-level security (IDOR)

Database queries aren’t scoped to the authenticated user, so incrementing or guessing a record ID lets one user read another user’s data. Researchers at shipai.dev call this “the most common and most dangerous gap” in Base44 apps.

The fix: enforce row-level security (RLS) tied to the authenticated user or tenant on every single table and API route — never rely on the frontend to hide what the backend still returns.

2. Auth bypass via undocumented registration endpoints

Disclosed by Wiz in July 2025: the api/apps/{app_id}/auth/register and verify-otp endpoints accepted nothing but a non-secret app ID — visible in the app’s URL and manifest.json — to create a fully verified account on any Base44-built app, completely bypassing SSO and access controls. Wiz confirmed this against real enterprise apps including chatbots, knowledge bases, and PII/HR tools.

The fix (applied by Wix platform-wide within ~24 hours): registration now requires proof of authorization server-side, not just an app ID.

3. Open redirect that leaks OAuth tokens

Imperva researchers found that the login flow’s from_url parameter wasn’t restricted to trusted domains, so a crafted link could forward a victim’s access token straight to an attacker-controlled site. The first fix was itself bypassed using a lookalike domain (app.base44.com.example.com) before a complete fix shipped.

The fix: a strict, exact-match domain allowlist on every redirect parameter — no substring or suffix matching.

4. Stored XSS inside the trusted app domain

The /apps-show/{app-id} route rendered user-generated app code inside the trusted app.base44.com origin without sanitizing it, and premium-feature restrictions were only enforced client-side. Imperva showed this could steal authentication tokens straight out of local storage.

The fix: sanitize or sandbox all user-generated content in an isolated origin or iframe, and enforce access restrictions server-side, never client-side alone.

5. Platform session tokens exposed to app code

Base44 account-level JWTs were passed through URLs into user-built app code running arbitrary JavaScript, where they could be trivially extracted — turning a single compromised app into full account takeover.

The fix: never pass primary-account session tokens into user-controlled contexts; issue scoped, short-lived, app-specific tokens instead.

6. Hardcoded secrets and unauthenticated server actions

A vendor scan (vibeappscanner, directional only — methodology undisclosed) reported that 73% of scanned vibe-coded apps had at least one security issue, rising to 96% among deep-scanned apps, with 62% rated critical or high severity.

The fix: move secrets into server-side environment variables and add authentication middleware to every server action and route, not just user-facing pages.

CVEs & Incidents

Base44’s Own Disclosed Incidents

Notably, none of Base44’s disclosed platform vulnerabilities carry a formal CVE number — each was reported through responsible-disclosure blog posts rather than tracked as a CVE, which is itself worth knowing if you’re trying to search a vulnerability database for them.

  • Wiz auth bypass — reported to Wix 2025-07-09, fix verified 2025-07-10, confirmed by Wix 2025-07-13, publicly disclosed 2025-07-29. No CVE assigned.
  • Imperva findings>/strong> (open redirect, stored XSS, JWT exposure, client-side-only premium enforcement) — found March 2025, patched by Base44/Wix around April 2025, publicly disclosed August 2025. No CVE assigned.
  • Per Wix’s own statements, there is no evidence either issue was exploited in the wild before disclosure.
Compliance

Compliance Blockers for Base44 Apps

If your Base44 app touches regulated data, these are the gaps that show up in due diligence and audits.

FrameworkStatus on Base44Learn more
HIPAANo BAA offered; ToS restricts storing PHI; no HIPAA-specific audit logging documented.HIPAA compliance for AI-built apps
PCI DSSBase44 itself is not PCI-certified; payments are delegated to Stripe. Any card data handled outside that flow needs its own assessment.PCI DSS for AI-built apps
SOC 2Claimed by Base44 for its own infrastructure (self-reported, unverified); does not extend to or cover the apps built on top of it.SOC 2 for AI-built apps
GDPR / data residencyAdherence claimed, but customers have no independent database access or backup control — data governance is entirely Base44/Wix-managed.GDPR for AI-built apps
Fix-It Checklist

Security Checklist for Your Base44 App

  • Test every table and route with a low-privilege account by incrementing/guessing IDs — confirm row-level security actually blocks cross-user access.
  • Search your app for API keys, Stripe secret keys, or credentials hardcoded into frontend code.
  • Confirm registration and login flows validate more than a public app ID, and that redirect parameters use an exact-domain allowlist.
  • Verify premium/paid feature gates are enforced server-side, not just hidden in the UI.
  • Check that no account-level session tokens are ever passed into user-facing app code or URLs.
  • If you plan to store health data, do not proceed without a signed BAA — Base44 does not offer one.
  • Request or independently verify any SOC 2/ISO claims before relying on them for enterprise procurement.
  • Run a full third-party security audit before handling real customer data or payments.
FAQ

Base44 Security: Frequently Asked Questions

Is Base44 safe to use for building apps?

Base44 is safe for prototyping, but apps built on it commonly ship with broken row-level security, hardcoded secrets, and missing server-side auth checks. The platform itself patched a critical account-takeover bug in 2025. Treat any Base44 app headed to production as needing a security audit first.

What was the Base44 authentication bypass vulnerability?

Wiz disclosed in July 2025 that Base44’s registration endpoints accepted only a non-secret app ID — visible in any app’s URL — to create a fully verified account on that app, bypassing SSO entirely. Wix fixed it platform-wide within about 24 hours of the report.

Is Base44 HIPAA compliant?

No. Base44 does not offer a Business Associate Agreement, and its Terms of Service reportedly restrict storing protected health information. Its claimed SOC 2/ISO status does not substitute for a BAA. Healthcare data should not be stored in a Base44 app without moving to a HIPAA-eligible stack.

Does Base44 have row-level security by default?

Base44’s Trust Center claims RLS with granular CRUD controls is available, but broken or missing RLS is the most commonly reported flaw in real Base44 apps — it has to be correctly configured per table, and default scaffolding doesn’t guarantee it’s scoped correctly to each user.

Is Base44 SOC 2 or ISO 27001 certified?

Base44’s Trust Center claims SOC 2 Type II and ISO 27001 alignment, but no public SOC 2 report or ISO certificate number has been independently verified. Even if accurate, this covers Base44’s own infrastructure, not the security of the specific app built on top of it.

What happened with Base44 after the Wix acquisition?

Wix acquired Base44 for roughly M, announced June 2025. Unverified, single-source reports describe price increases of 15–30% by May 2026 and a platform outage in February 2026, but no post-acquisition SOC 2 or HIPAA attestation has been published.

Is Your Base44 App Actually Secure?

We audit Base44 apps for broken row-level security, exposed secrets, auth bypasses, and compliance gaps — then fix what we find. Get a free scan to see where you stand.

Start Your Free Scan