v0
Prompt-to-production platform with Git workflows, embedded VS Code, database connectivity, MCP/OAuth integrations, and enterprise governance.
Dimension breakdown
Score · confidencePrompt-to-production platform with Git workflows, embedded VS Code, database connectivity, MCP/OAuth integrations, and enterprise governance. May 12, 2026 update adds terminal command execution (permission-prompted) and OAuth-authorized MCP servers.
April 2026 Vercel data breach via Context.ai OAuth supply-chain attack remains unresolved — KB bulletin last updated April 24 (ad-hoc cadence, no post-mortem, scope expanded post-disclosure); compliance capped at 5.
Vercel $340M ARR run-rate (Feb 2026), 84% YoY growth, IPO-ready per CEO Rauch — though March 2026 layoffs/reorg with morale decline now corroborated (Glassdoor/Blind). Independent SWE-WebDevBench (arXiv May 2026) confirms v0-Max strong frontend (72%) but full-stack-weak (0% schema design, 85% under-clarification).
Reliability complaints persist (April 8 v0-pro regression, March 30 forced-upgrade breakage, Trustpilot 2.8/5 billing/support issues). Upgrade requires breach closure + sustained reliability improvement.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Critical security vuln
securityTemporaryUnpatched critical security vulnerability
Caps Enterprise / Compliance at 25
Removed when — CVE patched and verified, or security incident resolved with post-mortem published
Reliability complaints
trustTemporaryWidespread reliability complaints (breaks often, unreliable output)
Caps Autonomy at 60
Removed when — 90+ days of improved reliability with community acknowledgment
Status rationale
Detected because the April 2026 Vercel data breach via Context.ai OAuth supply-chain attack remains under investigation — KB bulletin last updated April 24, 2026 with no closure announcement, no final post-mortem, and scope expanded post-disclosure; critical-security-vuln cap caps compliance at 5. Persistent agent reliability complaints (April 8 v0-pro quality regression, March 30 forced-upgrade breakage, Trustpilot 2.8/5 billing/support/history-loss) hold reliability-complaints cap at autonomy ≤12.
Structurally strong governance (SOC 2 Type II, ISO 27001:2022, PCI DSS, HIPAA BAA, SSO/SCIM) and accelerating business position ($340M ARR run-rate, 84% YoY growth, IPO readiness, 4M+ users) — tempered by newly-corroborated March 2026 layoffs/morale decline. First independent benchmark (SWE-WebDevBench May 2026) keeps unvalidated-benchmarks cap removed but quantifies the full-stack gap competitors exploit.
Enterprise trust requires breach closure and reliability turnaround.
Movement triggers
Upgrade to Tracked if: (1) Vercel publishes final breach post-mortem with closure language → critical-security-vuln cap lifted, compliance restored toward 15; (2) reliability-complaints cap lifted with 90+ days of materially reduced build/preview/regression reports and Trustpilot trend reversal; (3) no new trust incidents in 60-day window. Downgrade if: breach investigation reveals broader exposure than disclosed, reliability worsens, layoffs deepen into product-velocity decline, or full-stack benchmark gap (0% schema) drives enterprise customers to Replit Agent / Lovable for production app builds.
Risks & limitations
Critical Security Vuln
ModerateRadar cap: critical-security-vuln
Reliability Complaints
ModerateRadar cap: reliability-complaints
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category