[{"data":1,"prerenderedAt":818},["ShallowReactive",2],{"blog-en-base44-security-scan":3,"blog-index-en":463},{"id":4,"title":5,"body":6,"category":420,"cover":421,"coverAlt":422,"description":423,"draft":424,"extension":425,"faq":426,"image":442,"keywords":443,"meta":451,"navigation":452,"ogTitle":453,"path":454,"published":455,"seo":456,"stem":457,"tldr":458,"updated":455,"__hash__":462},"blog_en\u002Fblog\u002Fbase44-security-scan.md","Base44 security scan: the one thing only it can see",{"type":7,"value":8,"toc":408},"minimark",[9,13,21,24,29,32,127,139,161,165,168,171,178,184,193,197,200,226,233,238,241,249,257,261,264,267,272,275,279,282,296,302,313,317,320,329,347,357,374,377,381,401],[10,11,12],"p",{},"You open your Base44 app's Dashboard, click Security, press Run Security Scan,\nand a few seconds later a list comes back. Or nothing does. Either way you are\nholding a result and wondering whether that was the whole check.",[10,14,15,16,20],{},"Most write-ups of this get it backwards. The usual argument is that a scan from\ninside your project cannot see what the internet sees, so the outside one is the\none to trust. On Base44 that is the wrong way round for the half that matters:\n",[17,18,19],"strong",{},"the Base44 security scan is the only thing that can check whether a stranger\ncan read your data, and we can show you we cannot."," We tried on 1,466 Base44\napps and got an answer from two of them.",[10,22,23],{},"So this is a division of labour. One scan works inside the building. The other\nstands on the pavement and reads what gets handed out the front. Both are worth\ndoing, and on Base44 the inside one is doing the heavier half.",[25,26,28],"h2",{"id":27},"what-does-the-base44-security-scan-check","What does the Base44 security scan check?",[10,30,31],{},"Seven kinds of problem, read from inside your project. It never fetches your\npublished address.",[33,34,35,51],"table",{},[36,37,38],"thead",{},[39,40,41,45,48],"tr",{},[42,43,44],"th",{},"What it checks",[42,46,47],{},"What that means",[42,49,50],{},"Plans",[52,53,54,66,76,86,96,106,117],"tbody",{},[39,55,56,60,63],{},[57,58,59],"td",{},"Data permission issues",[57,61,62],{},"A data table with no permission rules on it, or people with more access than they should have",[57,64,65],{},"All",[39,67,68,71,74],{},[57,69,70],{},"Exposed secrets",[57,72,73],{},"API keys, passwords or tokens left somewhere app visitors could reach them",[57,75,65],{},[39,77,78,81,84],{},[57,79,80],{},"Unauthenticated backend functions",[57,82,83],{},"Something behind the scenes handing out data without checking who is asking. Titled \"Anyone can run this function\"",[57,85,65],{},[39,87,88,91,94],{},[57,89,90],{},"Credit protection",[57,92,93],{},"Your AI, image or email features reachable from outside your app, so someone else can spend your credits",[57,95,65],{},[39,97,98,101,104],{},[57,99,100],{},"App dependencies",[57,102,103],{},"A third-party library with a known security issue, with the version to move to",[57,105,65],{},[39,107,108,111,114],{},[57,109,110],{},"Code vulnerabilities",[57,112,113],{},"Patterns in your own code: missing access checks, unsafe handling of what a user typed",[57,115,116],{},"Builder and up",[39,118,119,122,125],{},[57,120,121],{},"Security header recommendations",[57,123,124],{},"Two browser protections, iframe embedding and unused browser features",[57,126,65],{},[10,128,129,130,134,135,138],{},"All of that was read off Base44's own documentation on 10 October 2026, from the\n",[131,132,133],"code",{},"Running a security scan"," and ",[131,136,137],{},"Base44 security: An overview"," pages. Three things\nin there are worth knowing before you rely on the result:",[140,141,142,149,155],"ul",{},[143,144,145,148],"li",{},[17,146,147],{},"The scan never applies a fix by itself."," You press Fix, and Base44 writes\nthe change into your app's AI chat with a checkpoint before it, so a fix that\nbreaks something can be rolled back from the chat.",[143,150,151,154],{},[17,152,153],{},"The Fix with AI button on an unauthenticated function rejects any caller\nwith nobody signed in."," Base44 says in the same breath that this can break a\npage you show to signed-out visitors, a webhook, or an integration that calls\nthe function. Test those paths afterwards.",[143,156,157,160],{},[17,158,159],{},"It warns at publish and does not stop you."," The publish panel shows a\nSecurity status, which Base44 describes as warning you without stopping you\nfrom publishing.",[25,162,164],{"id":163},"the-one-thing-only-it-can-see","The one thing only it can see",[10,166,167],{},"Whether the people using your app can reach data that is not theirs. On a Base44\napp, nothing outside the platform can check that.",[10,169,170],{},"On most builders your app talks to its database straight from your visitor's\nbrowser. The database therefore has a public address, your page carries that\naddress, and anybody can lift it out and start asking questions. Whether they\nget answers depends on a per-table setting most owners have never opened. A\nBase44 app sends its requests through Base44 instead, so there is no address on\nthe street for anyone to try.",[10,172,173,174,177],{},"The measurement is lopsided enough to settle it. 1,466 of the 5,442 Base44 apps\nwe graded name a Supabase project somewhere in the page. Our row-level-security\ncheck got a usable answer from ",[17,175,176],{},"2"," of them. On Lovable, where the database\nanswers the street directly, 3,553 of 6,535 answered. On Bolt, 35 of 267.",[179,180],"diagram",{"alt":181,"caption":182,"src":183},"Two lanes. In the top lane a lens sits inside a sealed platform panel beside the database and reaches it, ticked. In the bottom lane a lens outside reaches the app page, ticked, and a dashed line from the same lens towards the database stops at the panel wall under a question mark.","Top lane is Base44's scan, working inside the platform where your data lives. Bottom lane is an outside scan, which reads the page your visitors download and stops at the wall.","\u002Fblog\u002Fbase44-security-scan\u002Fthe-two-halves-1600x680.png",[10,185,186,187,192],{},"Two apps is not a rate and we are not going to print one. What the number\nsettles is who can look: on a Base44 app the data permission rules are readable\nfrom the Security page in your own dashboard and from nowhere else.\n",[188,189,191],"a",{"href":190},"\u002Fblog\u002Fis-base44-safe","The full census of what 5,442 Base44 apps scored"," has the\nrest of the figures.",[25,194,196],{"id":195},"why-your-published-app-can-still-be-carrying-a-key","Why your published app can still be carrying a key",[10,198,199],{},"Because the scan reads your project and your visitors download a file. Four\nthings in Base44's own documentation separate those two:",[140,201,202,208,214,220],{},[143,203,204,207],{},[17,205,206],{},"The published version can be older than the one the scan read."," Base44's\ncredit-protection finding has a state for exactly this, and the issue reads\n\"Publish changes before protecting credits\" when your live app is still\nrunning an earlier version.",[143,209,210,213],{},[17,211,212],{},"The status at publish is a warning."," Risks found opens the Security page,\nand you can publish anyway.",[143,215,216,219],{},[17,217,218],{},"An issue you ignore does not come back."," Ignored findings move to their own\nsection at the bottom of the list and, in Base44's words, do not reappear the\nnext time you scan. A clean list can mean somebody dismissed the finding in\nJune.",[143,221,222,225],{},[17,223,224],{},"The code half needs a paid plan."," Code vulnerability scanning runs on\nBuilder and above, as does the optional Wiz integration, which adds static\nanalysis using your own Wiz tenant.",[10,227,228,229,232],{},"From the pavement, that gap has a size. Of the 5,442 Base44 apps we graded,\n",[17,230,231],{},"95 were serving a Google API key in the page",", 11 had something shaped like a\npassword or a token, one had a Stripe restricted key and one a Stripe secret\nkey. The secrets check answered on all 5,442 apps, so those are counts rather\nthan a sample.",[179,234],{"alt":235,"caption":236,"src":237},"Top lane: an editor window with a report beside it carrying a tick. Bottom lane: a published app page carrying an amber key, reached by three visitors at the right edge. A dashed line links the two lanes to show they are versions of one app.","The scan reads the version in your editor. Your visitors download the one you published, which Base44's own credit finding says can be an earlier one.","\u002Fblog\u002Fbase44-security-scan\u002Fthe-publish-gap-1600x600.png",[10,239,240],{},"That 95 is a smaller share than the neighbours, and worth saying plainly: in the\nsame sweep, 727 of 18,563 Lovable apps and 200 of 3,050 Replit ones carried a\nGoogle API key. On this measurement Base44 apps are quieter than the apps built\nnext door.",[10,242,243,244,248],{},"It is also the finding on this list most likely to be fine. Google issues one\nkind of API key and expects it in the browser; what decides whether a stranger\ncan run up a bill on it is whether you restricted it to your own domain, and\nthat restriction lives in the Google console, not in your app.\n",[188,245,247],{"href":246},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","What to check on a Google key you found in your own page","\nis the two settings to read.",[10,250,251,252,256],{},"If you would rather see the whole list of what your published Base44 app hands\nout, our free scan reads your live address and reports what it can see from\noutside. It takes about 20 seconds and needs no account:\n",[188,253,255],{"href":254},"\u002Fsecurity-scanner","scan your app free",".",[25,258,260],{"id":259},"the-check-on-that-list-nobody-expects","The check on that list nobody expects",[10,262,263],{},"Someone calling your app's paid features directly, without going through your\napp at all.",[10,265,266],{},"Base44 calls this credit protection, and the finding appears when a feature of\nyours that uses AI, image generation or email can be reached from outside your\napp. Their documentation is blunt about the consequence: somebody who finds it\ncan run it and spend your integration credits. It is rated High, and depending\non your app the fix is either a single Fix button that restricts those features\nwhile leaving your own access alone, or a Resolve with AI that moves the calls\ninto your backend.",[179,268],{"alt":269,"caption":270,"src":271},"An app page in the middle with a visitor arrow into it. A second arrow from a figure at the left curves around the page and reaches a sparkle and a stack of coins behind it directly, bypassing the page.","The lower route is the one credit protection is about. The feature is reachable without opening your app, and every call spends the same credits yours do.","\u002Fblog\u002Fbase44-security-scan\u002Fcredits-from-outside-1600x560.png",[10,273,274],{},"This is the kind of thing an inside scan is good at and an outside scan has no\nhonest way to test. Finding out whether somebody can run your email feature for\nfree would mean running it, so our scan leaves that one to Base44 and reports\nwhat it can read without spending anything of yours.",[25,276,278],{"id":277},"what-neither-scan-checks","What neither scan checks",[10,280,281],{},"Three things, and the last one is the only item on this page that cannot be\nrepaired afterwards.",[10,283,284,287,288,291,292,256],{},[17,285,286],{},"Your certificate and your domain, if the app is on your own address."," A\nBase44 app on a ",[131,289,290],{},"base44.app"," address inherits Base44's. Move it to a domain you\nbought and the renewal dates become yours, which is\n",[188,293,295],{"href":294},"\u002Fblog\u002Fdomain-and-certificate-expiry","the quietest way a working app goes dark",[10,297,298,301],{},[17,299,300],{},"Files in a Supabase Storage bucket you connected."," Of the 1,466 Base44 apps\nnaming a Supabase project, our bucket check could answer on 5. The same wall\nthat hides the database hides the bucket, and Base44's data permission check\ncovers the tables it manages rather than a bucket in a project you attached\nyourself.",[10,303,304,307,308,312],{},[17,305,306],{},"Whether a copy of your data exists."," No scan on either side of the wall\nchecks that, because it is not a property of your app. It is a property of what\nyou set up somewhere else, and it decides whether a bad migration or an agent\nwith database access ends in a restore or in an email to your users.\n",[188,309,311],{"href":310},"\u002Fblog\u002Fai-agent-deleted-my-database","The day an AI agent deleted a production database","\nis what the second one reads like.",[25,314,316],{"id":315},"keeping-both-halves-covered-after-you-publish","Keeping both halves covered after you publish",[10,318,319],{},"Run both again after anything you change. A result from last week describes last\nweek's app, and on Base44 publishing is one button, so a table added this\nmorning or a key pasted in at midnight is live the moment you press it.",[10,321,322],{},[17,323,324,328],{},[188,325,327],{"href":326},"\u002Fpricing","Reeve Monitor"," runs the nine outside checks again for you:",[140,330,331,334,337,344],{},[143,332,333],{},"all nine checks every hour, on up to three apps",[143,335,336],{},"whether the app is up, every 60 seconds",[143,338,339,340,343],{},"a message when a result ",[17,341,342],{},"changes",", so a new finding does not wait for you to look",[143,345,346],{},"a monthly report of what it saw",[10,348,349],{},[17,350,351,352,356],{},"If your Base44 app keeps its data in your own Supabase project,\n",[188,353,355],{"href":354},"\u002Fsupabase-backups","Reeve Care"," keeps a copy of it:",[140,358,359,362,365,368,371],{},[143,360,361],{},"an encrypted copy of your Supabase database every night, kept where your project cannot reach it",[143,363,364],{},"each copy verified before it counts, by counting the rows in every table",[143,366,367],{},"a one-click restore when you need one",[143,369,370],{},"your uploaded files as well, once you connect a Storage credential",[143,372,373],{},"everything Monitor does",[10,375,376],{},"Both are on the pricing page, which is sometimes below the list figure and never\nabove it.",[25,378,380],{"id":379},"what-to-do-today","What to do today",[382,383,384],"key-takeaways",{},[140,385,386,389,392,395,398],{},[143,387,388],{},"Run the scan from Dashboard → Security before your next publish, and read the findings before you press Fix all issues. The unauthenticated-function fix can lock out a page you meant to leave open.",[143,390,391],{},"Check the Ignored section at the bottom of the list. An issue somebody ignored months ago is still ignored today.",[143,393,394],{},"If your app spends integration credits on AI, images or email, read the credit protection finding first. It is the one on the list that costs money by itself.",[143,396,397],{},"Scan the published address from outside afterwards, because the live app can be an earlier version than the one the scan read.",[143,399,400],{},"Keep a copy of your data somewhere your app cannot reach, if you attached your own Supabase project. Nothing in either scan can tell you whether one exists.",[10,402,403,404,256],{},"Start with the Ignored section, because it takes seconds and it is the one place\na clean report can be hiding a real finding. If you want the plain-language\nversion of everything checkable on a Base44 app from outside, we have\n",[188,405,407],{"href":406},"\u002Fis-your-base44-app-safe","a walkthrough for Base44 apps",{"title":409,"searchDepth":410,"depth":410,"links":411},"",3,[412,414,415,416,417,418,419],{"id":27,"depth":413,"text":28},2,{"id":163,"depth":413,"text":164},{"id":195,"depth":413,"text":196},{"id":259,"depth":413,"text":260},{"id":277,"depth":413,"text":278},{"id":315,"depth":413,"text":316},{"id":379,"depth":413,"text":380},"Security basics","\u002Fblog\u002Fbase44-security-scan\u002Fcover-1200x630.png","A sealed platform panel with a database and an inspector lens inside it, and in front of it an app page handing a copy out to visitors at the edge of the frame.","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.",false,"md",[427,430,433,436,439],{"q":428,"a":429},"Does Base44 scan my app for security problems?","Yes. Open your app editor, click Dashboard, then Security, then Run Security Scan. It checks seven kinds of problem: data permission rules, exposed secrets, backend functions that answer without checking who is asking, features that spend your integration credits, third-party libraries with known issues, patterns in your own code, and two browser security headers. Each finding comes with a recommended fix you can apply, and the scan never applies one on its own. It is available on every plan, including the free one, though the code half only runs on Builder and above. Read on 10 October 2026.",{"q":431,"a":432},"Is Base44's security scan enough?","It is the only scan that can check the part of a Base44 app that matters most, because your data sits behind Base44 rather than at a public address. What it has no reason to do is fetch your published page and read what went out in it. We graded 5,442 live Base44 apps: the database question was answerable on 2 of them, and 95 were serving a Google API key in the page. Run the inside scan before you publish and an outside one afterwards.",{"q":434,"a":435},"Why can't an outside scanner check my Base44 database?","Because there is nothing on the street to knock on. On most builders your app talks to its database straight from the visitor's browser, so the database has a public address, your page carries it, and anybody can lift it out and ask questions. A Base44 app sends its requests through Base44 instead. Of the 1,466 Base44 apps we graded that name a Supabase project anywhere in the page, our row-level-security check got a usable answer from 2. On Lovable, where the database answers the street directly, 3,553 of 6,535 answered.",{"q":437,"a":438},"What does an outside scan find that Base44 does not?","What your visitors actually receive right now. Base44 reads the project in your editor, and four things in their own documentation separate that from the live app: the published version can be older than the one the scan read, the scan warns at publish without blocking it, an issue you ignore once does not come back, and code-level scanning needs the Builder plan. In the 5,442 Base44 apps we graded, 95 had a Google API key in the page, 11 had something shaped like a password or a token, one had a Stripe restricted key and one a Stripe secret key.",{"q":440,"a":441},"Should I run both?","They answer different halves, so one does not stand in for the other. Run Base44's scan from the Security page before you publish, read the findings before pressing Fix all issues, and then check the published address from outside. An outside scan takes about 20 seconds and needs no account.","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",[444,445,446,447,448,449,450],"base44 security scan","base44 security scanner","does base44 check security","base44 app security check","base44 security dashboard","base44 rls check","base44 security review",{},true,"Base44 security scan: what only it can see","\u002Fblog\u002Fbase44-security-scan","2026-10-10",{"title":5,"description":423},"blog\u002Fbase44-security-scan",[459,460,461],"The Base44 security scan runs from inside your project and checks seven kinds of problem, from data permission rules to the libraries you depend on. It is free on every plan, and one of the seven only runs on Builder and above.","On a Base44 app it is the only scan that can answer the question people actually mean by \"is my app safe\": whether a stranger can read your data. We graded 5,442 live Base44 apps and could ask 2 of them.","What it has no reason to read is the page your visitors download. In 95 of those 5,442 apps, a Google API key was sitting in it.","iSWsfjonIOyCd9Q57FJ4Zqmhv4KvIXjJktukRLV4EP4",[464,470,471,477,483,489,494,500,506,512,518,524,530,536,543,549,555,560,566,572,578,583,589,595,601,607,613,619,625,631,637,643,649,655,661,667,673,679,685,691,697,703,709,715,721,727,733,739,745,751,757,763,768,773,779,784,790,796,802,807,813],{"path":465,"title":466,"description":467,"published":468,"category":420,"image":469,"draft":424},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":454,"title":5,"description":423,"published":455,"category":420,"image":442,"draft":424},{"path":472,"title":473,"description":474,"published":475,"category":420,"image":476,"draft":424},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":478,"title":479,"description":480,"published":481,"category":420,"image":482,"draft":424},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":484,"title":485,"description":486,"published":487,"category":420,"image":488,"draft":424},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":190,"title":490,"description":491,"published":492,"category":420,"image":493,"draft":424},"Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":495,"title":496,"description":497,"published":498,"category":420,"image":499,"draft":424},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":501,"title":502,"description":503,"published":504,"category":420,"image":505,"draft":424},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":507,"title":508,"description":509,"published":510,"category":420,"image":511,"draft":424},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":513,"title":514,"description":515,"published":516,"category":420,"image":517,"draft":424},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":519,"title":520,"description":521,"published":522,"category":420,"image":523,"draft":424},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":525,"title":526,"description":527,"published":528,"category":420,"image":529,"draft":424},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":531,"title":532,"description":533,"published":534,"category":420,"image":535,"draft":424},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":537,"title":538,"description":539,"published":540,"category":541,"image":542,"draft":424},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":544,"title":545,"description":546,"published":547,"category":541,"image":548,"draft":424},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":550,"title":551,"description":552,"published":553,"category":541,"image":554,"draft":424},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":556,"title":557,"description":558,"published":553,"category":420,"image":559,"draft":424},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":561,"title":562,"description":563,"published":564,"category":420,"image":565,"draft":424},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":567,"title":568,"description":569,"published":570,"category":420,"image":571,"draft":424},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":573,"title":574,"description":575,"published":576,"category":541,"image":577,"draft":424},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":294,"title":579,"description":580,"published":581,"category":420,"image":582,"draft":424},"Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":584,"title":585,"description":586,"published":587,"category":420,"image":588,"draft":424},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":590,"title":591,"description":592,"published":593,"category":420,"image":594,"draft":424},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":596,"title":597,"description":598,"published":599,"category":420,"image":600,"draft":424},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":602,"title":603,"description":604,"published":605,"category":420,"image":606,"draft":424},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":608,"title":609,"description":610,"published":611,"category":420,"image":612,"draft":424},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":614,"title":615,"description":616,"published":617,"category":420,"image":618,"draft":424},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":620,"title":621,"description":622,"published":623,"category":420,"image":624,"draft":424},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":626,"title":627,"description":628,"published":629,"category":541,"image":630,"draft":424},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":632,"title":633,"description":634,"published":635,"category":541,"image":636,"draft":424},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":638,"title":639,"description":640,"published":641,"category":541,"image":642,"draft":424},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":644,"title":645,"description":646,"published":647,"category":420,"image":648,"draft":424},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":650,"title":651,"description":652,"published":653,"category":420,"image":654,"draft":424},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":656,"title":657,"description":658,"published":659,"category":420,"image":660,"draft":424},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":662,"title":663,"description":664,"published":665,"category":420,"image":666,"draft":424},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":668,"title":669,"description":670,"published":671,"category":420,"image":672,"draft":424},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":674,"title":675,"description":676,"published":677,"category":420,"image":678,"draft":424},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":680,"title":681,"description":682,"published":683,"category":420,"image":684,"draft":424},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":686,"title":687,"description":688,"published":689,"category":420,"image":690,"draft":424},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":692,"title":693,"description":694,"published":695,"category":420,"image":696,"draft":424},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":698,"title":699,"description":700,"published":701,"category":420,"image":702,"draft":424},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":704,"title":705,"description":706,"published":707,"category":541,"image":708,"draft":424},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":710,"title":711,"description":712,"published":713,"category":420,"image":714,"draft":424},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":716,"title":717,"description":718,"published":719,"category":541,"image":720,"draft":424},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":722,"title":723,"description":724,"published":725,"category":420,"image":726,"draft":424},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":728,"title":729,"description":730,"published":731,"category":420,"image":732,"draft":424},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":734,"title":735,"description":736,"published":737,"category":420,"image":738,"draft":424},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":740,"title":741,"description":742,"published":743,"category":420,"image":744,"draft":424},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":541,"image":750,"draft":424},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":541,"image":756,"draft":424},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":420,"image":762,"draft":424},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":246,"title":764,"description":765,"published":766,"category":420,"image":767,"draft":424},"Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":310,"title":769,"description":770,"published":771,"category":541,"image":772,"draft":424},"An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":774,"title":775,"description":776,"published":777,"category":420,"image":778,"draft":424},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":780,"title":781,"description":782,"published":777,"category":420,"image":783,"draft":424},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":785,"title":786,"description":787,"published":788,"category":420,"image":789,"draft":424},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":791,"title":792,"description":793,"published":794,"category":541,"image":795,"draft":424},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":797,"title":798,"description":799,"published":800,"category":420,"image":801,"draft":424},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":803,"title":804,"description":805,"published":800,"category":541,"image":806,"draft":424},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":808,"title":809,"description":810,"published":811,"category":541,"image":812,"draft":424},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":814,"title":815,"description":816,"published":811,"category":420,"image":817,"draft":424},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]