[{"data":1,"prerenderedAt":904},["ShallowReactive",2],{"blog-en-domain-and-certificate-expiry":3,"blog-index-en":551},{"id":4,"title":5,"body":6,"category":509,"cover":510,"coverAlt":511,"description":512,"draft":513,"extension":514,"faq":515,"image":528,"keywords":529,"meta":538,"navigation":539,"ogTitle":540,"path":541,"published":542,"seo":543,"stem":544,"tldr":545,"updated":542,"__hash__":550},"blog_en\u002Fblog\u002Fdomain-and-certificate-expiry.md","Domain expired, website down: what actually happens next",{"type":7,"value":8,"toc":496},"minimark",[9,13,16,28,33,36,44,58,64,70,73,79,93,97,100,103,106,109,113,116,122,128,133,136,202,205,209,212,221,224,227,232,241,245,248,263,266,326,329,333,336,342,348,359,363,366,374,428,435,438,441,452,459,463,488],[10,11,12],"p",{},"Your app worked on Friday. On Monday it is a full page of browser warning, or it\nis not there at all, and nothing in your code changed. Someone sends you a\nscreenshot and you type the words on it into a search box: domain expired,\nwebsite down.",[10,14,15],{},"Here is the part most advice on this gets wrong. Two different failures produce\nthat morning, they run on two different clocks, and the one that sounds cheaper\nis the serious one. A lapsed certificate is loud, embarrassing and replaceable\ntoday. A lapsed domain is quiet at first, and if you leave it long enough your\napp is not down. It belongs to someone else.",[10,17,18,19,23,24,27],{},"Two things sit between your app and the people who use it. The ",[20,21,22],"strong",{},"domain"," is the\nlease on the shop: the name above the door and the right to keep using it. The\n",[20,25,26],{},"certificate"," is the licence in the window saying this shop really is the one\non the sign. You rent both. Both renew on a date you set once and have not\nlooked at since.",[29,30,32],"h2",{"id":31},"what-happens-when-my-domain-expires","What happens when my domain expires?",[10,34,35],{},"Your app goes dark, and then you are on a clock that runs in three stages.",[10,37,38,39,43],{},"For ",[40,41,42],"code",{},".com"," and the other generic domains the timetable comes from ICANN rather\nthan from your registrar, so it is broadly the same wherever you bought the\nname.",[10,45,46,49,50,57],{},[20,47,48],{},"Still yours, already off."," Your registrar keeps the name renewable at the\nordinary price for a window it chooses, usually a few weeks. ICANN's\n",[51,52,56],"a",{"href":53,"rel":54},"https:\u002F\u002Fwww.icann.org\u002Fresources\u002Fpages\u002Ferrp-2013-02-28-en",[55],"nofollow","Expired Registration Recovery Policy","\nrequires them to break your DNS during it: for at least the last eight days the\nname is still renewable, it has to stop pointing anywhere. So your app goes\noffline well before the name goes anywhere, which is usually how the owner finds\nout.",[10,59,60,63],{},[20,61,62],{},"Deleted, and still recoverable."," When the registrar finally deletes the\nregistration, a 30-day Redemption Grace Period begins. ICANN requires it of\nalmost every generic registry. Only you can bring the name back during it, only\nthrough the registrar that deleted it, and you pay a restore fee on top of the\nrenewal. ICANN does not set that fee, and it is a great deal more than a\nrenewal.",[10,65,66,69],{},[20,67,68],{},"Pending delete."," About five days in which nothing you or your registrar does\nmakes any difference. Then the name drops.",[10,71,72],{},"The same policy says your registrar has to write to you: twice before the\nregistration expires, roughly a month and a week ahead, and again within five\ndays afterwards. So if a domain of yours has ever lapsed without warning, the\nthing to check is not the calendar. It is which address your registrar account\nhas on it.",[74,75],"diagram",{"alt":76,"caption":77,"src":78},"A horizontal band in four parts, with one figure standing at its left end. The first part is solid; a rule marks the expiry date and the band turns hatched. A second rule marks deletion, after which one segment is amber and numbered 30 and the next is red and numbered 5. The band then ends, followed by an empty dashed slot and three more figures.","The three stages after a domain expires, for .com and the other generic domains. The name is recoverable in the first two and anyone's after the third.","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fthe-clock-after-expiry-1600x540.png",[10,80,81,82,85,86,85,89,92],{},"Country domains run their own timetables. ",[40,83,84],{},".io",", ",[40,87,88],{},".co.uk",[40,90,91],{},".de"," and the rest sit\noutside that policy, and some of them are considerably less forgiving. If your\napp is on one, read your registry's own lifecycle page rather than this section.",[29,94,96],{"id":95},"can-someone-take-my-domain-after-it-expires","Can someone take my domain after it expires?",[10,98,99],{},"Yes, once it drops, and that is what makes this different from everything else\non a security report.",[10,101,102],{},"Every other finding is a mistake in something you own. You can go and fix it. A\ndropped domain leaves your ownership entirely: the name is registered to somebody\nelse, and everything that pointed at your app points at them now. Bookmarks. The\nlink in your welcome email. The address on the card you handed out at a\nconference. The password reset link you sent last week.",[10,104,105],{},"Names get caught quickly, too. There are businesses whose entire product is\nasking for a domain the second it becomes available, which is why a name with\nany traffic on it rarely sits unregistered for long.",[10,107,108],{},"You can still try to buy it back. You are negotiating with whoever got there\nfirst, at whatever price they name. A certificate that expired this morning can\nbe replaced this morning; a domain that dropped last month may not be for sale.",[29,110,112],{"id":111},"why-does-my-website-say-not-secure-when-it-was-fine-yesterday","Why does my website say \"not secure\" when it was fine yesterday?",[10,114,115],{},"Two different things produce that, and which one you have is written on the\nscreen.",[10,117,118,121],{},[20,119,120],{},"\"Not secure\" in the address bar"," is your browser saying the page arrived over\nplain HTTP, with no certificate involved at all. Your page still loads\nunderneath it. Nothing expired. Something is serving your site without HTTPS,\nwhich is its own problem and not this one.",[10,123,124,127],{},[20,125,126],{},"An expired or untrusted certificate is not a label. It is a wall."," Your app is\nreplaced by a full page: \"Your connection is not private\" in Chrome, \"Warning:\nPotential Security Risk Ahead\" in Firefox. Reaching your site means finding an\nAdvanced button and clicking through a warning that says the site is unsafe.\nMost visitors will not.",[74,129],{"alt":130,"caption":131,"src":132},"Two browser frames. In the first, the page renders normally and a small crossed circle sits in the address bar. In the second there is no page at all: an opaque panel fills the frame, carrying a warning mark and a single button.","Left, the page still loads and the browser is commenting on it. Right, the certificate failed and there is no page to comment on.","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fa-label-and-a-wall-1600x820.png",[10,134,135],{},"Read the code underneath the warning before you change anything, because it says\nwhich repair you need:",[137,138,139,155],"table",{},[140,141,142],"thead",{},[143,144,145,149,152],"tr",{},[146,147,148],"th",{},"What the browser prints",[146,150,151],{},"What it means",[146,153,154],{},"What fixes it",[156,157,158,177,191],"tbody",{},[143,159,160,171,174],{},[161,162,163,166,167,170],"td",{},[40,164,165],{},"NET::ERR_CERT_DATE_INVALID"," in Chrome, ",[40,168,169],{},"SEC_ERROR_EXPIRED_CERTIFICATE"," in Firefox",[161,172,173],{},"The certificate is past its end date",[161,175,176],{},"A new certificate",[143,178,179,185,188],{},[161,180,181,184],{},[40,182,183],{},"NET::ERR_CERT_AUTHORITY_INVALID"," in Chrome",[161,186,187],{},"Nothing signed it that the browser trusts, or a link in the chain was never installed",[161,189,190],{},"A certificate from a trusted authority, or the missing link. Renewing does nothing",[143,192,193,196,199],{},[161,194,195],{},"\"Your clock is behind\" or \"Your clock is ahead\"",[161,197,198],{},"The visitor's own device has the wrong date",[161,200,201],{},"Nothing on your side",[10,203,204],{},"That last row is worth reading before you go looking at your host. One person\nreporting a certificate warning can be one person's laptop.",[29,206,208],{"id":207},"why-an-https-certificate-stops-renewing-without-anything-breaking","Why an HTTPS certificate stops renewing without anything breaking",[10,210,211],{},"Because renewal is supposed to happen a month before the certificate matters,\nand a failed renewal changes nothing you can see.",[10,213,214,215,220],{},"Most apps built this way are served by a host that gets certificates from Let's\nEncrypt and renews them on your behalf. Let's Encrypt\n",[51,216,219],{"href":217,"rel":218},"https:\u002F\u002Fletsencrypt.org\u002Fdocs\u002Ffaq\u002F",[55],"issues 90-day certificates and recommends renewing every 60 days",",\nso the process keeping your site alive is meant to succeed with 30 days still on\nthe clock.",[10,222,223],{},"To get a new one, your host has to prove to the authority that it still controls\nyour name: either by serving a file the authority asks for at your domain, or by\nwriting a record into your DNS. Anything that breaks the proof breaks the\nrenewal. Moving your DNS to a new provider. Putting a proxy in front of the app.\nPointing the name somewhere else to try something and pointing it back. Adding a\nCAA record, which is a DNS entry naming which authorities are allowed to issue\nfor your domain and which quietly forbids every authority it does not name.",[10,225,226],{},"None of that takes your site down. The certificate you already have goes on\nworking, so the app stays up and the padlock stays there while the renewal fails\nagain every day for a month with nobody watching.",[74,228],{"alt":229,"caption":230,"src":231},"Two stacked tracks over one span marked 0, 60 and 90. The upper track is the renewal: an outlined box with a tick in it running to day 60, then six crosses spaced out to day 90. The lower track is what visitors see: solid accent across the whole span, turning into an amber block at day 90.","The renewal starts failing at day 60 and the site looks perfect until day 90. Everything that would have told you is on the upper track.","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fnothing-visible-for-30-days-1600x620.png",[10,233,234,235,240],{},"The letter that used to arrive has also stopped.\n",[51,236,239],{"href":237,"rel":238},"https:\u002F\u002Fletsencrypt.org\u002F2025\u002F06\u002F26\u002Fexpiration-notification-service-has-ended",[55],"Let's Encrypt ended its expiration notification emails on 4 June 2025",",\nhaving announced it in January of that year: renewal is automated for most\nsubscribers now, and holding millions of email addresses against issuance\nrecords was a privacy cost they preferred not to carry. Both reasons are good\nones. It still removed the one message that reached a human when the automation\nstopped.",[29,242,244],{"id":243},"do-lovable-or-vercel-renew-my-certificate-for-me","Do Lovable or Vercel renew my certificate for me?",[10,246,247],{},"While your app is on the builder's own subdomain, both dates belong to them and\nneither is something you can get wrong.",[10,249,250,251,254,255,258,259,262],{},"On ",[40,252,253],{},"yourapp.lovable.app",", or a ",[40,256,257],{},"vercel.app"," or ",[40,260,261],{},"netlify.app"," address, the\nplatform owns the name, renews the registration, and issues and renews the\ncertificate. Our own domain check does not even look these up. It reports that\nthe app is on a managed platform domain and that there is nothing here for you\nto track.",[10,264,265],{},"Connecting a domain of your own moves one of the two to you for certain and the\nother sometimes:",[137,267,268,281],{},[140,269,270],{},[143,271,272,275,278],{},[146,273,274],{},"What",[146,276,277],{},"On a builder subdomain",[146,279,280],{},"On your own domain",[156,282,283,294,305,315],{},[143,284,285,288,291],{},[161,286,287],{},"Who owns the name",[161,289,290],{},"The platform",[161,292,293],{},"You, through your registrar",[143,295,296,299,302],{},[161,297,298],{},"Who renews the registration",[161,300,301],{},"The platform, automatically",[161,303,304],{},"You, on a card",[143,306,307,310,312],{},[161,308,309],{},"Who issues and renews the certificate",[161,311,290],{},[161,313,314],{},"Usually still your host, automatically, for your domain",[143,316,317,320,323],{},[161,318,319],{},"Who hears about it when it breaks",[161,321,322],{},"Nobody needs to",[161,324,325],{},"You, if something is watching",[10,327,328],{},"The renewal row is the one people are surprised by. Nothing in the builder\nannounces it. You add a domain, the app loads on it, and you now own a calendar\nentry you never made.",[29,330,332],{"id":331},"how-do-i-check-both-right-now","How do I check both right now?",[10,334,335],{},"From outside, without signing in to anything.",[10,337,338,341],{},[20,339,340],{},"The certificate."," Open your app, click the padlock in the address bar, open\nthe certificate details and read the \"Valid until\" date. On a standard 90-day\ncertificate anything more than 30 days out means renewal is working. Less than\n30 days means the renewal that should already have happened has not.",[10,343,344,347],{},[20,345,346],{},"The domain."," Sign in to your registrar and read three things. The expiry\ndate. Whether the card behind auto-renew is still valid, because auto-renew with\na dead card is the commonest way this happens to somebody who was sure it could\nnot. And the email address on the account, which is where every warning you are\nowed will be sent.",[10,349,350,353,354,358],{},[20,351,352],{},"Both at once."," Our free scan reads both from outside, along with seven other\nchecks, in about 20 seconds and with no account:\n",[51,355,357],{"href":356},"\u002Fsecurity-scanner","scan your app",". It prints the certificate's end date and,\nfor a domain you registered yourself, the registration's. On a builder subdomain\nit says so rather than inventing a date for you.",[29,360,362],{"id":361},"what-we-found-across-30998-apps","What we found across 30,998 apps",[10,364,365],{},"Both findings are rare, and every single one of them belonged to somebody who\nhad connected a domain of their own.",[10,367,368,369,373],{},"Between 12 and 14 August 2026 we ran the same nine external checks over 30,998\nlive apps built with Lovable, Bolt, v0, Replit and Base44. Of the apps each\ncheck got an answer from, 55 out of 30,980 had a domain expired or expiring, and\n32 out of 30,851 had a certificate expired, expiring or untrusted. The full\nnumbers are in ",[51,370,372],{"href":371},"\u002Fresearch\u002Fvibe-coded-app-security-2026","our scan report",".",[137,375,376,386],{},[140,377,378],{},[143,379,380,383],{},[146,381,382],{},"Finding",[146,384,385],{},"Apps",[156,387,388,396,404,412,420],{},[143,389,390,393],{},[161,391,392],{},"Domain expiring within 60 days",[161,394,395],{},"54",[143,397,398,401],{},[161,399,400],{},"Domain already expired",[161,402,403],{},"1",[143,405,406,409],{},[161,407,408],{},"Certificate expiring within 30 days",[161,410,411],{},"19",[143,413,414,417],{},[161,415,416],{},"Certificate already expired",[161,418,419],{},"5",[143,421,422,425],{},[161,423,424],{},"Certificate no browser will trust",[161,426,427],{},"8",[10,429,430,431,434],{},"That is 87 apps, which reads like a rounding error until you ask who they were.\n1,090 of the scans in that sweep were on an app whose owner had registered the\ndomain. ",[20,432,433],{},"All 87 were in that group",", and not one app on a builder subdomain\ncarried either finding. Among the apps that can have this problem at all, that\nis roughly one in twelve.",[10,436,437],{},"Most of that column is a warning rather than an outage, and that is the useful\npart: somebody still had time. Five of the domains were inside seven days and\none had already gone. Thirteen of the apps were showing every visitor a browser\nwarning at the moment we looked, five with an expired certificate and eight with\none nothing trusts.",[10,439,440],{},"Both of these are a date going past while nobody looks at it, which is the kind\nof problem something checking every hour is actually good at.",[10,442,443,447,448,451],{},[51,444,446],{"href":445},"\u002Fpricing","Reeve Monitor"," re-runs all nine checks every hour on up to three\napps, watches uptime every 60 seconds and sends a monthly report. For these two\nfindings it does something it does for nothing else: it emails you about a\ncertificate or a registration running out ",[20,449,450],{},"even when your grade has not\nchanged",". Monitor is $12 a month at list, with seven days free before it\ncharges you, and the pricing page is sometimes below the figure here and never\nabove it.",[10,453,454,455,373],{},"Monitor watches and nothing more. If you also want a copy of your database kept\nsomewhere your builder cannot reach it,\n",[51,456,458],{"href":457},"\u002Fsupabase-backups","that is Care, and it covers Supabase",[29,460,462],{"id":461},"what-to-do-right-now","What to do right now",[464,465,466],"key-takeaways",{},[467,468,469,473,476,479,482,485],"ul",{},[470,471,472],"li",{},"Read the \"Valid until\" date on your certificate through the padlock in your address bar. More than 30 days out means the renewal is working.",[470,474,475],{},"Sign in to your registrar and read the expiry date and the card behind auto-renew. A dead card is how auto-renew fails.",[470,477,478],{},"Put both dates in the calendar you actually read, a month ahead of each.",[470,480,481],{},"If a warning is already showing, read the code under it first. A date error needs a new certificate; an authority error needs a different one, and renewing will not touch it.",[470,483,484],{},"If a domain has already lapsed, renew it today. Every stage after this one costs more than the last, and after the redemption period it is not yours to renew.",[470,486,487],{},"If you are still on your builder's subdomain, neither of these is yours yet. They arrive with your custom domain, on the same day.",[10,489,490,491,495],{},"Neither of these is a mistake anyone made in your app, which is why they are so\neasy to leave off the list. Put them on it. If you would rather work through\neverything at once, the ",[51,492,494],{"href":493},"\u002Fchecklist","10-minute security checklist"," covers all\nnine checks in the order they are worth doing.",{"title":497,"searchDepth":498,"depth":498,"links":499},"",3,[500,502,503,504,505,506,507,508],{"id":31,"depth":501,"text":32},2,{"id":95,"depth":501,"text":96},{"id":111,"depth":501,"text":112},{"id":207,"depth":501,"text":208},{"id":243,"depth":501,"text":244},{"id":331,"depth":501,"text":332},{"id":361,"depth":501,"text":362},{"id":461,"depth":501,"text":462},"Security basics","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcover-1200x630.png","Two tall record cards, each with a seal at its foot. The left one is lit in accent; the right sits in shadow with its colour drained.","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.",false,"md",[516,518,520,523,525],{"q":32,"a":517},"Your app goes dark first and the name stays recoverable for a while afterwards. For .com and the other generic domains, your registrar keeps it renewable at the ordinary price for a window it chooses, and ICANN requires your DNS to stop working for at least the last eight days of that window. After the registrar deletes it, a 30-day Redemption Grace Period starts, during which only you can restore it and only through that registrar, for a fee. Then about five days of pending delete when nobody can do anything, and then the name is available to whoever asks for it next.",{"q":96,"a":519},"Yes, once it has finished the redemption and pending-delete periods and dropped. At that point the name is registered first come, first served, and there are businesses whose whole product is asking for a name the moment it becomes available. Everything that pointed at your app still points at the name: bookmarks, the link in your welcome email, the address in your app store listing. You can try to buy it back from whoever got it, at whatever price they decide.",{"q":521,"a":522},"Why does my site say \"not secure\" today when it was fine yesterday?","Those are two different problems and the screen tells you which one you have. A grey \"Not secure\" label in the address bar, with your page still loading underneath it, means the page arrived over plain HTTP and no certificate was involved at all. An expired or untrusted certificate is not a label: it replaces your app with a full-page warning that the visitor has to click through, headed \"Your connection is not private\" in Chrome or \"Warning: Potential Security Risk Ahead\" in Firefox.",{"q":244,"a":524},"On their own subdomain they own everything and there is nothing for you to track. Once you connect a custom domain, the registration is yours from then on and the certificate is usually still issued and renewed by whoever hosts the app. That split is why a broken renewal is easy to miss: nobody tells you it was being done for you, and it stops being done without an error that reaches anyone.",{"q":526,"a":527},"How far ahead should I want to be warned?","A month for each, which is roughly when each one starts being fixable without drama. A standard certificate is renewed about 30 days before it expires, so a certificate with less than 30 days left is already telling you the renewal did not work. A domain is worth catching before the registration lapses at all, because every stage after that costs more than the one before it.","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",[530,531,532,533,534,535,536,537],"domain expired website down","ssl certificate expired","my website says not secure","domain expiry check","certificate expired what happens","can someone take my domain","https certificate not renewing","renew domain before it expires",{},true,"Domain expired, website down: what happens next","\u002Fblog\u002Fdomain-and-certificate-expiry","2026-09-22",{"title":5,"description":512},"blog\u002Fdomain-and-certificate-expiry",[546,547,548,549],"If your domain expired and your website is down, you are on a clock. For .com and most generic domains that is a few weeks to renew at the ordinary price, then 30 days to buy it back for a fee, then about five days when nothing can be done at all.","A certificate that expires is loud and you can replace it today. A domain that drops belongs to whoever registers it next, along with every link anyone ever made to your app.","Your registrar has to warn you about the domain, and does. Nothing has to warn you about the certificate, and Let's Encrypt stopped sending its own expiry emails on 4 June 2025.","On a builder subdomain neither of these is yours: the platform owns the name and the certificate and renews both. They become yours the day you connect a domain of your own.","OPz0WbQkhX9kYtpt73F80jC6cUfzEvngrsLCcqarjB4",[552,558,564,570,576,582,588,594,600,606,612,618,624,631,637,643,648,654,660,666,667,673,679,685,691,697,703,709,715,721,727,733,739,745,751,757,763,769,775,781,787,793,799,805,811,817,823,829,835,841,847,853,859,865,870,876,882,888,893,899],{"path":553,"title":554,"description":555,"published":556,"category":509,"image":557,"draft":513},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":559,"title":560,"description":561,"published":562,"category":509,"image":563,"draft":513},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":565,"title":566,"description":567,"published":568,"category":509,"image":569,"draft":513},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":571,"title":572,"description":573,"published":574,"category":509,"image":575,"draft":513},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":577,"title":578,"description":579,"published":580,"category":509,"image":581,"draft":513},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":583,"title":584,"description":585,"published":586,"category":509,"image":587,"draft":513},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":589,"title":590,"description":591,"published":592,"category":509,"image":593,"draft":513},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":595,"title":596,"description":597,"published":598,"category":509,"image":599,"draft":513},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":601,"title":602,"description":603,"published":604,"category":509,"image":605,"draft":513},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":607,"title":608,"description":609,"published":610,"category":509,"image":611,"draft":513},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":613,"title":614,"description":615,"published":616,"category":509,"image":617,"draft":513},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":619,"title":620,"description":621,"published":622,"category":509,"image":623,"draft":513},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":625,"title":626,"description":627,"published":628,"category":629,"image":630,"draft":513},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":632,"title":633,"description":634,"published":635,"category":629,"image":636,"draft":513},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":638,"title":639,"description":640,"published":641,"category":629,"image":642,"draft":513},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":644,"title":645,"description":646,"published":641,"category":509,"image":647,"draft":513},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":649,"title":650,"description":651,"published":652,"category":509,"image":653,"draft":513},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":655,"title":656,"description":657,"published":658,"category":509,"image":659,"draft":513},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":661,"title":662,"description":663,"published":664,"category":629,"image":665,"draft":513},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":541,"title":5,"description":512,"published":542,"category":509,"image":528,"draft":513},{"path":668,"title":669,"description":670,"published":671,"category":509,"image":672,"draft":513},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":674,"title":675,"description":676,"published":677,"category":509,"image":678,"draft":513},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":680,"title":681,"description":682,"published":683,"category":509,"image":684,"draft":513},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":686,"title":687,"description":688,"published":689,"category":509,"image":690,"draft":513},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":692,"title":693,"description":694,"published":695,"category":509,"image":696,"draft":513},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":698,"title":699,"description":700,"published":701,"category":509,"image":702,"draft":513},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":704,"title":705,"description":706,"published":707,"category":509,"image":708,"draft":513},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":710,"title":711,"description":712,"published":713,"category":629,"image":714,"draft":513},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":716,"title":717,"description":718,"published":719,"category":629,"image":720,"draft":513},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":722,"title":723,"description":724,"published":725,"category":629,"image":726,"draft":513},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":728,"title":729,"description":730,"published":731,"category":509,"image":732,"draft":513},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":734,"title":735,"description":736,"published":737,"category":509,"image":738,"draft":513},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":740,"title":741,"description":742,"published":743,"category":509,"image":744,"draft":513},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":509,"image":750,"draft":513},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":509,"image":756,"draft":513},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":509,"image":762,"draft":513},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":509,"image":768,"draft":513},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":773,"category":509,"image":774,"draft":513},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":776,"title":777,"description":778,"published":779,"category":509,"image":780,"draft":513},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":509,"image":786,"draft":513},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":788,"title":789,"description":790,"published":791,"category":629,"image":792,"draft":513},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":794,"title":795,"description":796,"published":797,"category":509,"image":798,"draft":513},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":800,"title":801,"description":802,"published":803,"category":629,"image":804,"draft":513},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":806,"title":807,"description":808,"published":809,"category":509,"image":810,"draft":513},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":812,"title":813,"description":814,"published":815,"category":509,"image":816,"draft":513},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":818,"title":819,"description":820,"published":821,"category":509,"image":822,"draft":513},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":824,"title":825,"description":826,"published":827,"category":509,"image":828,"draft":513},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":830,"title":831,"description":832,"published":833,"category":629,"image":834,"draft":513},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":836,"title":837,"description":838,"published":839,"category":629,"image":840,"draft":513},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":842,"title":843,"description":844,"published":845,"category":509,"image":846,"draft":513},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":848,"title":849,"description":850,"published":851,"category":509,"image":852,"draft":513},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":854,"title":855,"description":856,"published":857,"category":629,"image":858,"draft":513},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":860,"title":861,"description":862,"published":863,"category":509,"image":864,"draft":513},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":866,"title":867,"description":868,"published":863,"category":509,"image":869,"draft":513},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":871,"title":872,"description":873,"published":874,"category":509,"image":875,"draft":513},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":877,"title":878,"description":879,"published":880,"category":629,"image":881,"draft":513},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":883,"title":884,"description":885,"published":886,"category":509,"image":887,"draft":513},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":889,"title":890,"description":891,"published":886,"category":629,"image":892,"draft":513},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":894,"title":895,"description":896,"published":897,"category":629,"image":898,"draft":513},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":900,"title":901,"description":902,"published":897,"category":509,"image":903,"draft":513},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]