by Eduardo Monteiro
I did not set out to collect this data. I set out to sell security audits.
Three weeks ago I pivoted from a clinical documentation SaaS that had zero paying customers after two months. I had twenty years in IT infrastructure and no product that anyone wanted to buy. So I built something I understood: a security scanner for SaaS products.
I pointed it at the internet and started collecting data.
Here is what 279 scans look like:
Average score: 46 out of 100.
Minimum score: 0.
Maximum score: 90.
Risk distribution:
Critical: 20 products (7%)
High risk: 158 products (57%)
Medium risk: 71 products (25%)
Low risk: 30 products (11%)
64% of AI-built SaaS products scanned have high or critical security exposure. Only 11% are in good shape.
These are not legacy products or careless developers. These are founders who shipped fast with Claude, Cursor, Lovable, and Supabase. Smart people building real products for real users.
What the scanner actually found
The scanner runs 78 black-box checks against any live domain. No code access. No installation. Just a URL and what any attacker would see from the outside in the first five minutes.
The most common findings across 279 scans:
Security headers absent. The browser has no restrictions on what scripts can run on the page. A single injected script can steal every user session on the platform.
Email domain fully spoofable. SPF records missing or misconfigured. Anyone can send emails pretending to be your domain.
Stack exposed in HTTP responses. The exact framework, server version, and hosting region announced in every response. A roadmap for targeted attacks.
Tech stack disclosed in JavaScript bundles. Not just framework names. In some cases, API keys. In one case, the Supabase service role key, which bypasses all Row Level Security and gives read, write, and delete access to every row in every table.
That last one I found manually during an audit. The founder had real users and had no idea.
Why this keeps happening
I audited a financial SaaS last month. The founder told me his biggest fear before I started.
"Please don't take down my server."
Three requests later, the server was down.
Not through exploitation. Not through anything sophisticated. I sent three requests with unexpected parameters to an endpoint that had no error handling. A single exception took the entire application offline for several minutes.
He thought it was a deployment error on his side.
It was not.
This is the pattern. The AI generates code that works. The feature ships. The demo looks great. Nothing breaks. There is no signal that anything is wrong until there is.
AI writes insecure code differently than junior developers do. A junior developer leaves traces. Weird variable names. Spaghetti logic. You look at it and something feels off.
AI writes insecure code that looks like it was written by a senior engineer. Clean abstractions. Proper naming. Comments that explain the logic. The vulnerability hides inside code that gives you no reason to distrust it.
The gap nobody is closing
Most security tools work at the code level. They review what you wrote, scan your dependencies, check for known vulnerabilities in libraries.
None of that catches what the scanner catches.
DNS misconfigurations. TLS weaknesses. Security headers. Exposed endpoints. Email spoofability. Reputation checks. Subdomain takeover vectors. Secrets in public JavaScript bundles.
These do not live in the code. They live in the infrastructure around the code. They get scaffolded by AI, never reviewed, and sit there silently until someone who knows where to look finds them.
The scan runs 78 of these checks in sixty seconds against any live domain. Five are free. The full report is $29.90.
What I have learned in three weeks
The product works. I have direct evidence: a founder who went from 28 to 80 after running the scan and fixing what it found. Another who found his SPF record missing on the root domain after serving it correctly on subdomains for months. Neither of them knew. Nothing was broken. No test was failing.
The scanner gave the signal that normal monitoring never would have.
What does not work: posting about the product. Every post about the scanner gets ignored. Every post about what the scanner finds gets engagement.
The most useful thing I did was share two real audit findings on Reddit. Server down in three requests. Database master key in a public JavaScript bundle. That post got 23 upvotes, 92 comments, and over 15,000 views in 24 hours. People responded because the findings were real, not because I built a tool.
Distribution is the problem. Not the product. 279 scans and only two paying customers. Somewhere between scanning and buying, people are leaving.
I think I know why. Most of them are curious, not scared. The scan shows them a number. They do not feel the number. They do not connect a score of 39 out of 100 to a real consequence for their business.
That is the thing I am still trying to figure out.
Two asks
If you have an AI-built SaaS product, run a scan. scan.mosai.com.br. Five checks free, sixty seconds, no signup. Tell me what you find.
If you have cracked the gap between people engage with the content and people buy the product, what specifically moved the needle? Not theory. What actually worked?
I know a few indie hackers and founders who have successfully converted content engagement into product sales for their SaaS businesses; they might be willing to answer your questions for free. Let me know if you want me to pass them along.
Sure, I’d appreciate that. I’m specifically looking for people who turned content engagement into paid SaaS customers and can share what actually moved the needle.
There's a community called "replyz" where you can connect with exactly the kind of people you're looking for. Just search for the type of person you want to talk to and you'll get thoughtful, detailed replies from them. The only thing is that members are expected to share their own knowledge with others too, which is what keeps the community valuable. Feel free to ask if you have any questions!
What's been the hardest part of getting other indie hackers to share the specific strategies that actually moved the needle for them? I happen to know a few successful indie hackers personally and could intro you to a couple for free to chat about it.