
Cyber Security
Endor Labs Launches 2025 State Of Dependency Management Report, Finds 80% Of AI-Suggested Dependencies Contain Risks

Annual report reveals how AI-generated code and MCP integrations are expanding the software supply chain attack surface
PALO ALTO, Calif., Nov. 4, 2025 /PRNewswire/ -- Endor Labs, the fastest growing company in application security, today released its annual State of Dependency Management 2025: Security in the AI-Code Era report. Now in its fourth iteration, the report sends a clear message: AI-assisted development isn't the future; it's already here, and most enterprises are blindly inheriting a massive new attack surface full of hallucinated, vulnerable, and unvetted code.
The report found that only 1 in 5 dependency versions recommended by AI coding assistants were safe to use, containing neither hallucinations nor vulnerabilities. The rapid adoption of Model Context Protocol (MCP) servers, which connect AI agents to thousands of third-party tools and integrations, further amplifies the risk by centralizing access points where unvetted code can enter enterprise systems. Without proper governance, organizations are inheriting a new, expanding attack surface that threatens even their most critical code and infrastructure.
Endor Labs analyzed more than 10,000 GitHub repositories and tested AI coding agents across major ecosystems, such as PyPI, npm, Maven, and NuGet, to determine which recommended dependencies were real, safe, or vulnerable, while also assessing the security of the servers supporting these AI tools. The analysis revealed several key insights:
- High Vulnerability Rates in AI-Imported Dependencies: Depending on the AI model, 44-49% of dependencies imported by coding agents contained known security vulnerabilities, showing that even existing dependencies can introduce risk if not properly vetted.
- Security Tools Significantly Improve AI Outcomes: When AI agents are equipped with security tools, the proportion of safe dependency recommendations jumps from roughly 20% to 57%–nearly a threefold improvement. While this demonstrates the value of integrating safeguards into AI workflows, gaps remain if organizations rely solely on AI without proper oversight.
- The MCP Ecosystem Lacks Market Maturity, Adds New Risks: In an attempt to keep pace with AI's speed of innovation, more than 10,000 MCP servers were created in under a year, 40% of which had no license. About 75% were built by individuals without enterprise-grade protections, and 82% interact with sensitive APIs, creating additional vulnerabilities that complicate safe adoption at scale.
"AI coding agents have become an integral part of modern development workflows," said Henrik Plate, Security Researcher at Endor Labs. "They introduce new types of dependencies — some of which may be hallucinated or insecure. At the same time, thousands of third-party MCP servers are being developed and published by open-source maintainers, waiting to be integrated into projects. Without sufficient verification, however, they could open new paths for exploitation. Effective governance is essential to balance innovation with accountability, enabling AI to accelerate development without letting untrusted code into critical systems."
Download the full State of Dependency Management 2025 for recommended actions your organization needs to take now, here.
About Endor Labs
Endor Labs is building the application security platform for the software development revolution. From open source to AI-generated code, it helps teams identify, prioritize, and fix the vulnerabilities that actually matter—faster. With deep program analysis, automated remediation, and unmatched dataset coverage, Endor Labs empowers modern engineering and security teams to move fast without compromise.
Media Contact
Rebecca Reese
endorlabs@meetkickstand.com
View original content:https://www.prnewswire.com/news-releases/endor-labs-launches-2025-state-of-dependency-management-report-finds-80-of-ai-suggested-dependencies-contain-risks-302603438.html
SOURCE Endor Labs
Frequently Asked Questions
What are the key findings of the Endor Labs 2025 State of Dependency Management report?
The report finds high vulnerability rates in AI-imported dependencies, highlights the value of security tools in improving AI outcomes, and reveals the risks associated with the evolving MCP ecosystem.
What is the impact of AI coding assistants on software security?
AI coding agents can introduce new types of dependencies, some of which may be hallucinated or insecure, potentially expanding the attack surface of software systems.
What is an MCP server and what risks does it introduce?
MCP servers connect AI agents to third-party tools, and a significant number of these servers lack proper security measures, posing a risk of exploitation and vulnerabilities for integrated projects.
First published on Tue, Nov 4, 2025
Enjoyed what you've read so far? Great news - there's more to explore!
Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.
Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.
Dive into TechDogs' treasure trove today and Know Your World of technology!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Trending PR Newswire
Propelr Named One Of 2025'S Best Enterprise LMS Platforms By Talented Learning
24 Exchange Appoints Gina Tuccio As Chief Financial Officer
Cyble And Botswana Communications Regulatory Authority (BOCRA) Sign Mou To Advance National Cybersecurity In Botswana
HOPPR Introduces Its AI Foundry: A Scalable, Secure Platform Accelerating The Development Of AI In Medical Imaging
Kia's All-Electric PV5 Secures Industry's Most Prestigious LCV Award
Join Our Newsletter
Get weekly news, engaging articles, and career tips-all free!
By subscribing to our newsletter, you're cool with our terms and conditions and agree to our Privacy Policy.

Join The Discussion