Skip to main content
World Wide TechnologyBenchAI tool benchmarks
App Builder
StatusEmerging
SignalDetected
EvidenceGrade B

Lovable

59
C +4 vs last quarter

Lovable 2.0 (May 2026) Cloud backend, real-time multiplayer (20 users), Dev Mode, Wiz SCA+SAST scanning, iOS/Android apps (Apr 2026). $500M ARR (confirmed June 2026, was $400M Feb 2026); in talks for Series C at ~$12B valuation [unverified — in talks, June 2026]; $6.6B prior valu

UX / DXCapabilityReliabilityValueCommunityEnterpriseAutonomyIntegration

Dimension breakdown

Score · confidence
UX / DX
50% conf45
Capability
50% conf55
ReliabilityIncomplete data at this time
Value
50% conf80
CommunityIncomplete data at this time
Enterprise / Compliance
50% conf65
Autonomy
50% conf50
Integration
50% conf60
Sources blend review platforms, community sentiment, the Signal Radar and practitioner ratings. Scores re-blend each quarter.

Lovable 2.0 (May 2026) Cloud backend, real-time multiplayer (20 users), Dev Mode, Wiz SCA+SAST scanning, iOS/Android apps (Apr 2026). $500M ARR (confirmed June 2026, was $400M Feb 2026); in talks for Series C at ~$12B valuation [unverified — in talks, June 2026]; $6.6B prior valuation, 146 FTE, TIME100 Most Influential Companies 2026 — extraordinary growth.

Watch

third major security incident in 13 months (April 2026 48-day BOLA exposure, Feb 3–Apr 20, exposing source code/DB credentials/AI chat history) with initial denial+HackerOne blame-shift before a remediation-only response (no validated post-mortem) damages enterprise trust.

CVE-2025-48757 RLS policy correctness gap persists. TrustFall attack class (May 2026) exposes Lovable users at the CLI-agent layer.

Platform abused at scale for malware/phishing (Proofpoint: hundreds of thousands of malicious Lovable URLs per month since Feb 2025 — Tycoon MFA kits, crypto drainers, Microsoft/UPS impersonation). NEW governance positives — regional data residency (EU/US/AU) and Wiz/Aikido scanning — partly offset the pattern.

No CLI/headless access (no-automation-mode). Backend feature satisfaction lowest of all surfaces (20-30%); reliability-complaints cap applied.

Prototype-tier positioning persists; promotion to Tracked deferred until security incident rate stabilizes.

Recommended

Use cases

Not yet assessed — this section fills in as ACES research covers the tool.

Score caps

Risk flags

  • No automation mode

    capabilityConditional

    No CLI, API, or headless mode for CI/CD integration

    Caps UX / DX at 60

    Removed whenCLI, API, or headless mode launched

  • Reliability complaints

    trustTemporary

    Widespread reliability complaints (breaks often, unreliable output)

    Caps Autonomy at 60

    Removed when90+ days of improved reliability with community acknowledgment

Assessment

Status rationale

Hold at Detected. The 2026-05-05 demotion from Assessed was driven by the security-incident pattern, now confirmed as three incidents in 13 months with precise dates (CVE-2025-48757 May 2025; Feb 2026 inverted-auth finding; Apr 2026 48-day BOLA) plus an escalating platform-abuse dimension (Proofpoint: hundreds of thousands of malicious URLs/month since Feb 2025) and TrustFall CLI-layer exposure.

The April 2026 response published remediation actions but is not a validated post-mortem, and the initial denial+HackerOne blame-shift remains an enterprise-trust regression. NEW governance positives — regional data residency (EU/US/AU) and Wiz/Aikido scanning — are real improvements but address feature posture, not the incident-frequency conditions that triggered the demotion.

Lovable 2.0 is a genuine capability expansion (Cloud backend, multiplayer, Dev Mode, mobile apps) and adoption signals remain extraordinary ($500M ARR confirmed June 2026, 146 FTE, TIME100, named Fortune 500 prototyping use; Series C at ~$12B [unverified — in talks, June 2026]). Promotion to Tracked deferred until movement-trigger upgrade criteria are met.

Watch maintained because company viability is exceptional and the governance feature set (SOC 2 Type II, ISO 27001, SAML/SCIM/RBAC/audit logs, regional residency, Wiz scanning) is strong for the tier — the gap is in security incident frequency and policy enforcement, not feature posture.

Watch for

Movement triggers

Upgrade to Tracked if: (a) security incident rate drops to <15 incidents/quarter sustained 90 days, AND (b) full April 2026 post-mortem published with independent validation (the existing response post is remediation-only), AND (c) no new major incidents for 120 days, AND (d) platform-abuse enforcement shifts from reactive removal to proactive prevention. Downgrade to Deferred if: fourth major security incident in 2026, OR critical-security-vuln cap triggered (unpatched critical CVE), OR incident frequency exceeds 80/90d, OR enterprise customer reference loss publicly reported.

Caution

Risks & limitations

  • No Automation Mode

    Moderate

    Radar cap: no-automation-mode

  • Reliability Complaints

    Moderate

    Radar cap: reliability-complaints

Capabilities

Integration surface

Not yet assessed — this section fills in as ACES research covers the tool.

Proof points

Adoption & benchmarks

Not yet assessed — this section fills in as ACES research covers the tool.

Spotted something wrong or missing here? Suggest a change →

Per-source contributions

Click any dimension to see the underlying sources and citations.