Home
World Journal of Advanced Engineering Technology and Sciences
International, Peer reviewed, Referred, Open access | ISSN Approved Journal

Main navigation

  • Home
    • Journal Information
    • Abstracting and Indexing
    • Editorial Board Members
    • Reviewer Panel
    • Journal Policies
    • WJAETS CrossMark Policy
    • Publication Ethics
    • Instructions for Authors
    • Article processing fee
    • Track Manuscript Status
    • Get Publication Certificate
    • Issue in Progress
    • Current Issue
    • Past Issues
    • Become a Reviewer panel member
    • Join as Editorial Board Member
  • Contact us
  • Downloads

ISSN: 2582-8266 (Online)  || UGC Compliant Journal || Google Indexed || Impact Factor: 9.48 || Crossref DOI

Fast Publication within 2 days || Low Article Processing charges || Peer reviewed and Referred Journal

Research and review articles are invited for publication in Volume 20, Issue 3 (September 2026).... Submit articles

Security Benchmarking of AI-Generated Web Application Code: An OWASP-Based Comparative Study of Coding LLMs

Breadcrumb

  • Home
  • Security Benchmarking of AI-Generated Web Application Code: An OWASP-Based Comparative Study of Coding LLMs

Mohammad-Jamiu Babatunde Balogun 1, *, Ahmed Sani Geza 1 and Yusuf Umar Jimada 2

1 Department of Electrical Engineering, Faculty of Engineering, Bayero University, Kano, Kano State, Nigeria.
2 Department of Computer Science, Faculty of Computing, Sokoto State University, Sokoto State, Nigeria.

Research Article

 

World Journal of Advanced Engineering Technology and Sciences, 2026, 19(03), 009-017

Article DOI: 10.30574/wjaets.2026.19.3.0292

DOI url:https://doi.org/10.30574/wjaets.2026.19.3.0292

Received on 20 April 2026; revised on 29 May 2026; accepted on 01 June 2026

Large Language Models (LLMs) are increasingly used to generate application code, but their security-by-default behavior remains uncertain. This study evaluates the security posture of four contemporary AI coding systems: Gemini 3.5 Flash accessed through Antigravity, and DeepSeek V4 Flash, Kimi K2.5, and GPT-5.4-mini accessed through OpenCode via their APIs. Ten standardized prompts covering common web application tasks, including authentication, CRUD operations, SQL search, file upload, access control, secret handling, input validation, frontend login, and session management, were submitted once to each system. The resulting 40 code samples were analyzed using Semgrep OSS with manual review for selected logic and architectural issues. Findings were normalized by model, prompt, severity, and OWASP Top 10 category. The benchmark identified 64 normalized security findings, including 62 Critical/High findings and 2 Medium findings. GPT-5.4-mini produced the lowest number of findings (10), while Gemini 3.5 Flash produced the highest (21). The most frequent weaknesses were missing Cross-Site Request Forgery protections, insecure cookie/session settings, path traversal risks in file handling, and security misconfigurations in generated infrastructure. These results suggest that one-shot AI-generated web application code can be functionally useful but should not be considered production-ready without security review, automated scanning, and manual validation.

Artificial intelligence; Software security; Large language models; OWASP Top 10; Code generation; Static application security testing

https://wjaets.com/sites/default/files/fulltext_pdf/WJAETS-2026-0292.pdf

Get Your e Certificate of Publication using below link

Download Certificate

Preview Article PDF

Mohammad-Jamiu Babatunde Balogun, Ahmed Sani Geza and Yusuf Umar Jimada. Security Benchmarking of AI-Generated Web Application Code: An OWASP-Based Comparative Study of Coding LLMs. World Journal of Advanced Engineering Technology and Sciences, 2026, 19(03), 009-017. Article DOI: https://doi.org/10.30574/wjaets.2026.19.3.0292

Get Certificates

Get Publication Certificate

Download LoA

Check Corssref DOI details

Issue details

Issue Cover Page

Editorial Board

Table of content


Copyright © Author(s). All rights reserved. This article is published under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, sharing, adaptation, distribution, and reproduction in any medium or format, as long as appropriate credit is given to the original author(s) and source, a link to the license is provided, and any changes made are indicated.


Copyright © 2026 World Journal of Advanced Engineering Technology and Sciences

Developed & Designed by VS Infosolution