All posts

March 5, 2026 · 5 min read

Base44's Worst Bug Fixed in a Day. Getting Acquired Didn't Prevent It From Happening.

Base44's first year is worth walking through as its own case study, because the timeline compresses a lot of what I write about into a single, fast-moving story: launch, rapid growth, acquisition, a serious bug, and a genuinely fast fix, all within about six months.

The timeline

Base44 launched in January 2025. By around March, it was reportedly already profitable with over 20,000 paying customers, a fast climb for a brand new AI app builder. By June 18, Wix acquired it for 80 million dollars, with the platform reportedly around a quarter million users by then. Weeks after that acquisition closed, Wiz Research privately reported a critical bug to Wix: unauthenticated endpoints that let anyone register themselves into any private Base44-built app using nothing but that app's public ID, no password, no invitation. Wix patched it within roughly a day of the report. Wiz published the full writeup about three weeks later, making the issue public.

What I think is actually worth taking from this

It's tempting to read a story like this as evidence that a well-funded platform, backed by an established company, is safer than a scrappier one. The timeline doesn't really support that read. The bug existed regardless of Base44's funding, growth, or new corporate parent. What the acquisition and resources actually bought was a fast, competent response once the bug was reported: patched in about a day is a genuinely good outcome for a critical, actively exploitable flaw. Scale and backing didn't prevent the mistake. They appear to have shortened the time between report and fix.

Why that distinction matters for how you evaluate any platform

If you're choosing a tool partly based on 'this one's more established, so it's probably more secure,' this story is a useful correction. Established platforms still ship real, serious bugs. What's worth actually evaluating instead is how a platform behaves once something is found: does it patch quickly, does it communicate honestly, does it have the resources and processes to move fast when it matters. Base44's response here, by the public account, was genuinely solid. That's a different claim than 'this platform doesn't have serious bugs,' and it's worth being precise about which one you're actually relying on.

What this means if you're building on Base44 today

This specific bug is patched, and it's been under Wix's ownership for some time now, presumably with whatever additional security process that brings. None of that changes the standing advice for any platform: check your own app's specific access rules yourself, don't assume a public app ID or a similar identifier is being treated as sensitive unless you've confirmed it, and remember that a platform fixing its own bug quickly says something good about its incident response, not something guaranteed about the next mistake it hasn't made yet.

Related reading

Harbova is a security service for apps built with AI tools. Start with a free scan, and if it finds something serious, we can fix it and prove it is closed.