Quttera says AI builders are moving website security into the publish decision
Quttera released new research on Oct. 6 examining how AI application platforms are baking security checks into publishing workflows instead of treating them as post-launch add-ons. The company says continuous verification still matters after deployment because live websites and apps can change hours or weeks later.
Why it matters: - AI application builders are shifting security checks earlier, into the moment a website or app is published. - Quttera argues that one-time launch checks do not prove a live asset stays safe after deployment. - The research frames ongoing verification as more important as websites become targets for both human users and AI agents.
What happened: - Quttera, a provider of continuous website and web application integrity monitoring, released new research on Oct. 6 called “Security Is Moving Into the Publish Flow.” - The report examines how AI application platforms including Base44, Lovable and Replit are integrating security scanning into development and publishing workflows. - The analysis compares those platforms with the more open, assemble-it-yourself security model long associated with WordPress. - Michael Novofastovsky, Quttera’s CTO and co-founder, said security for websites and web applications is moving into the publishing decision, but integrity evidence must continue after an asset goes live.
The details: - Base44 surfaces application security status and scan results in its production workflow. - Lovable says a basic security scan runs automatically when an application is published. - Lovable also lets administrators block publication when critical findings remain unresolved. - Replit pairs pre-publication security analysis with ongoing dependency monitoring after an application goes live. - Quttera says these platforms differ in execution but point in the same direction: builders are answering “Have I secured this correctly?” at publish time. - The research says a deployment-time check cannot guarantee that a live asset remains safe later. - Dependencies can be updated after launch. - New vulnerabilities can be disclosed after launch. - Third-party scripts and embedded resources can change behavior without a new deployment. - Credentials can be compromised. - Configurations can drift. - Content can change. - Quttera separates platform-native security, which uses internal information such as source code, installed packages, permissions, configuration and build history, from independent deployed-state verification, which checks what the live asset actually presents from the outside. - Independent verification looks at public pages, delivered scripts, redirect behavior and blacklist or reputation status. - The report also points to the WebMCP Community Group draft, which explores how web applications could expose structured capabilities for AI agents to discover and invoke. - Quttera says this could make live web assets something AI systems act through, not only something people view or crawlers read. - The analysis cites Cisco Talos research describing a case in which attackers used an AI-assisted web application platform to build a credential-harvesting page. - Quttera uses that example to show how AI building tools can lower the barrier to both legitimate and abusive web applications. - Quttera calls its ongoing-verification model Continuous Web Integrity, meaning evidence about a live web asset’s security and integrity is maintained over time instead of treated as permanent after a single scan or approval. - The company says the research does not announce integrations with Base44, Lovable, Replit or any other AI application platform. - Quttera says it is studying where independent, platform-agnostic evidence can complement existing website and application security controls. - The full research is available on the Quttera Blog.
Between the lines: - The report suggests the market is moving from point-in-time security checks to continuous verification of live assets. - That shift matters because the security state of a published site can diverge from the state that was approved at launch. - Quttera is positioning itself as a layer that validates what is actually live, not just what a platform internally believes is secure.
What's next: - Quttera says it will keep studying how independent verification can complement platform-native controls. - The broader question for AI app builders is whether publish-time scanning will become a baseline requirement rather than a differentiator. - As AI agents become more capable web actors, live-site integrity checks may need to extend beyond human-facing use cases.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Charity, Community, and ME
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.