60 Percent of Developers Don

60 Percent of Developers Don't Trust the Security of their Applications

New research suggests that attacks based on open source code vulnerabilities will increase by 20 percent this year.

60 percent of developers aren’t confident in the security of their applications, and only 31 percent feel confident that their code doesn’t contain vulnerabilities, according to a new joint developer survey from NodeSource and Sqreen.

Enterprises are increasingly turning to open source tools like Node.js to save time and money while creating higher quality applications. According to Forrester, more than 76 percent of developers are currently using open source technology “at some level.”[1]

Yet, this enthusiastic adoption is not without risks. New research suggests that attacks based on open source code vulnerabilities will increase by 20 percent this year.[2]

While the developer community fully understands the risks of operating in the open internet and the complexities of building reliable, secure code, these same developers are not taking advantage of tools that can identify and mitigate threats. 

Surprisingly, fewer than a third of developers combine manual and automatic code reviews to search for flaws, or use automated tools to discover vulnerable modules. And a full 40 percent don’t check if there are known vulnerabilities in their third-party dependencies.

“Our survey results clearly demonstrate that security is a concern for developers — but not a priority,” said Joe McCann, CEO of NodeSource.

Only 35 percent of companies with fewer than 1,000 employees combine both code reviews and automated tools to check for vulnerabilities. Larger organizations make this more of a priority, with 62 percent saying they do both.

Prevention is a key piece of the security puzzle, but identification and remediation of attacks are also critical. Shockingly, the vast majority of the developers (79 percent) have poor to no insight into when their applications are under attack. And fewer than a quarter of Node.js developers use any form of real-time protection against attacks.

“Node is revolutionizing development for enterprises, but there is a lot of work to do to ensure the ecosystem remains secure,” said Jean-Baptiste Aviat, Co-Founder and CTO of Sqreen. “Developers have a wide array of security tools at their disposal that they are simply not using. We have more work to do evangelizing the importance of security tools for the health of the Node ecosystem.”

About the Author

Joe McCann is the Founder and CEO of NodeSource.

Featured

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events
  • Meeting Modern Demands

    Door hardware and access control continue to be at the forefront of innovation within the security industry, continuously evolving to meet the dynamic needs of commercial spaces. Read Now

  • Leveraging IoT and Open Platform VMS for a Connected Future

    The evolution of urban environments is being reshaped by the convergence of Internet of Things (IoT) technology and open platform VMS. As cities worldwide grapple with growing populations and increasing operational complexities, these integrated technologies are emerging as powerful tools for creating more livable, efficient, and secure urban spaces. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.