Low-Code AI Builders: 40,653 Flowise and 10,860 Dify Title Matches
Low-Code AI Builders: 40,653 Flowise and 10,860 Dify Title Matches A new exposure class with familiar properties Flowise and Dify are low-code platforms for building applications on top of language models. B
Low-Code AI Builders: 40,653 Flowise and 10,860 Dify Title Matches
A new exposure class with familiar properties
Flowise and Dify are low-code platforms for building applications on top of language models. Both provide a web interface where a user assembles prompts, tools and data sources into a workflow, and both store the API keys those workflows use.
On 28 September 2026, title="Flowise" returned 40,653 and title="Dify" returned 10,860. These platforms are recent additions to production estates, and they reproduce a pattern that older tools established: a web application with credentials inside it, deployed quickly by a team, on a host that is reachable from the internet.
What a builder platform holds
The stored material is what makes the exposure significant. A workflow usually needs a model provider key, which is a billable credential that can be used from anywhere. It may need database connections, object storage keys, or API tokens for the services the workflow calls. The platform also holds the prompts and the knowledge base content, which frequently includes internal documents.
The combination of a model provider key and document access is a data-disclosure path: the key allows an attacker to run queries against the knowledge base the platform has indexed, and the documents may be returned.
Why these deployments appear publicly
The deployment model is usually a container image started on a small host, published on a port so a colleague can reach it during evaluation. That evaluation host becomes the production instance, and the port stays open. Authentication is available in both platforms and is not always enabled, because the default configuration prioritises getting started.
A review sequence
Confirm that authentication is enabled and that the initial account credentials were changed at deployment.
Inventory the stored credentials, starting with model provider keys, and rotate any that may have been exposed.
Restrict reachability to the networks that need it, and place the interface behind an access proxy rather than publishing the port.
Review the indexed documents to determine what a read-only access to the platform would reveal, because that is the impact of a credential compromise here.
Limitations
Neither query reports authentication state, and both product names appear in documentation, tutorials and marketplace listings, so the counts include non-service pages. The platforms are also frequently deployed with an obfuscated title, which means the measured population understates the deployed one. Treat these figures as direction, not as an inventory.
References
- ZoomEye cyberspace search engine, queried 28 September 2026: https://www.zoomeye.ai/
- Flowise documentation, authentication and credential handling: https://docs.flowiseai.com/
- Dify documentation, access control and model configuration: https://docs.dify.ai/
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.