Base44 (now owned by Wix) lets anyone prompt a full-stack app into existence in minutes — database, auth, and Stripe payments included. It also shipped an auth bypass that let attackers create verified accounts on any Base44 app with nothing but a public app ID. Here’s what’s actually wrong under the hood, and how to fix it.
Get a Free Security Scan Book a Full AuditBase44 is an Israeli “vibe coding” platform, launched February 2025 by solo founder Maor Shlomo, that turns a prompt into a working web or mobile app: frontend, backend, a managed Postgres database, authentication, file storage, and Stripe payments, all in one hosted environment. Wix acquired Base44 for roughly M in a deal announced June 18, 2025 (closed around July 2025), with an additional ~M retention pool for its small team. Base44 passed 400,000 users and, per Wix, scaled to an estimated –100M in annual revenue within months — it now operates as a distinct product under Wix. People use it to spin up internal tools, HR and PII dashboards, customer portals, CRMs, MVPs, booking tools, browser extensions, and Stripe-powered SaaS products.
This is Base44’s security as a company and platform — separate from whether the specific app it generated for you is secure. Both matter, but they are not the same question.
These are the failure patterns security researchers and Zooc Digital audits actually find in live Base44 apps.
Database queries aren’t scoped to the authenticated user, so incrementing or guessing a record ID lets one user read another user’s data. Researchers at shipai.dev call this “the most common and most dangerous gap” in Base44 apps.
The fix: enforce row-level security (RLS) tied to the authenticated user or tenant on every single table and API route — never rely on the frontend to hide what the backend still returns.
Disclosed by Wiz in July 2025: the api/apps/{app_id}/auth/register and verify-otp endpoints accepted nothing but a non-secret app ID — visible in the app’s URL and manifest.json — to create a fully verified account on any Base44-built app, completely bypassing SSO and access controls. Wiz confirmed this against real enterprise apps including chatbots, knowledge bases, and PII/HR tools.
The fix (applied by Wix platform-wide within ~24 hours): registration now requires proof of authorization server-side, not just an app ID.
Imperva researchers found that the login flow’s from_url parameter wasn’t restricted to trusted domains, so a crafted link could forward a victim’s access token straight to an attacker-controlled site. The first fix was itself bypassed using a lookalike domain (app.base44.com.example.com) before a complete fix shipped.
The fix: a strict, exact-match domain allowlist on every redirect parameter — no substring or suffix matching.
The /apps-show/{app-id} route rendered user-generated app code inside the trusted app.base44.com origin without sanitizing it, and premium-feature restrictions were only enforced client-side. Imperva showed this could steal authentication tokens straight out of local storage.
The fix: sanitize or sandbox all user-generated content in an isolated origin or iframe, and enforce access restrictions server-side, never client-side alone.
Base44 account-level JWTs were passed through URLs into user-built app code running arbitrary JavaScript, where they could be trivially extracted — turning a single compromised app into full account takeover.
The fix: never pass primary-account session tokens into user-controlled contexts; issue scoped, short-lived, app-specific tokens instead.
A vendor scan (vibeappscanner, directional only — methodology undisclosed) reported that 73% of scanned vibe-coded apps had at least one security issue, rising to 96% among deep-scanned apps, with 62% rated critical or high severity.
The fix: move secrets into server-side environment variables and add authentication middleware to every server action and route, not just user-facing pages.
Notably, none of Base44’s disclosed platform vulnerabilities carry a formal CVE number — each was reported through responsible-disclosure blog posts rather than tracked as a CVE, which is itself worth knowing if you’re trying to search a vulnerability database for them.
If your Base44 app touches regulated data, these are the gaps that show up in due diligence and audits.
| Framework | Status on Base44 | Learn more |
|---|---|---|
| HIPAA | No BAA offered; ToS restricts storing PHI; no HIPAA-specific audit logging documented. | HIPAA compliance for AI-built apps |
| PCI DSS | Base44 itself is not PCI-certified; payments are delegated to Stripe. Any card data handled outside that flow needs its own assessment. | PCI DSS for AI-built apps |
| SOC 2 | Claimed by Base44 for its own infrastructure (self-reported, unverified); does not extend to or cover the apps built on top of it. | SOC 2 for AI-built apps |
| GDPR / data residency | Adherence claimed, but customers have no independent database access or backup control — data governance is entirely Base44/Wix-managed. | GDPR for AI-built apps |
Base44 is safe for prototyping, but apps built on it commonly ship with broken row-level security, hardcoded secrets, and missing server-side auth checks. The platform itself patched a critical account-takeover bug in 2025. Treat any Base44 app headed to production as needing a security audit first.
Wiz disclosed in July 2025 that Base44’s registration endpoints accepted only a non-secret app ID — visible in any app’s URL — to create a fully verified account on that app, bypassing SSO entirely. Wix fixed it platform-wide within about 24 hours of the report.
No. Base44 does not offer a Business Associate Agreement, and its Terms of Service reportedly restrict storing protected health information. Its claimed SOC 2/ISO status does not substitute for a BAA. Healthcare data should not be stored in a Base44 app without moving to a HIPAA-eligible stack.
Base44’s Trust Center claims RLS with granular CRUD controls is available, but broken or missing RLS is the most commonly reported flaw in real Base44 apps — it has to be correctly configured per table, and default scaffolding doesn’t guarantee it’s scoped correctly to each user.
Base44’s Trust Center claims SOC 2 Type II and ISO 27001 alignment, but no public SOC 2 report or ISO certificate number has been independently verified. Even if accurate, this covers Base44’s own infrastructure, not the security of the specific app built on top of it.
Wix acquired Base44 for roughly M, announced June 2025. Unverified, single-source reports describe price increases of 15–30% by May 2026 and a platform outage in February 2026, but no post-acquisition SOC 2 or HIPAA attestation has been published.
We audit Base44 apps for broken row-level security, exposed secrets, auth bypasses, and compliance gaps — then fix what we find. Get a free scan to see where you stand.
Start Your Free Scan