[{"data":1,"prerenderedAt":1001},["ShallowReactive",2],{"blog-en-env-file-exposed-on-your-server":3,"blog-index-en":648},{"id":4,"title":5,"body":6,"category":603,"cover":604,"coverAlt":605,"description":606,"draft":607,"extension":608,"faq":609,"image":625,"keywords":626,"meta":635,"navigation":636,"ogTitle":637,"path":638,"published":639,"seo":640,"stem":641,"tldr":642,"updated":646,"__hash__":647},"blog_en\u002Fblog\u002Fenv-file-exposed-on-your-server.md","Is your .env file exposed? The twelve paths to check",{"type":7,"value":8,"toc":589},"minimark",[9,18,36,42,47,54,57,63,69,83,100,104,107,166,175,181,185,188,197,200,207,215,219,222,393,400,404,407,410,438,446,450,456,462,471,478,482,491,494,507,511,514,517,522,525,547,554,558,581],[10,11,12,13,17],"p",{},"Somebody has told you your ",[14,15,16],"code",{},".env"," file is exposed, and you cannot tell from the\nsentence whether that is serious. The phrase covers two completely different\nsituations. One of them is the tool working as designed. The other means a file\nyou believed was private has been downloadable from your live site, by anyone,\nfor as long as it has been there.",[10,19,20,21,31,32,35],{},"Here is the part guide after guide runs together: ",[22,23,24,25,27,28,30],"strong",{},"a value from your ",[14,26,16],{},"\nending up inside your JavaScript is not the same event as the ",[14,29,16],{}," file itself\nbeing served by your web server."," The first is the build doing what you asked\nit to do when you named the variable ",[14,33,34],{},"VITE_SOMETHING",". The second is a filing\nmistake, and it is the one to check first, because you can check it yourself from\noutside in about a minute.",[10,37,38,39,41],{},"Think of your live site as a shop counter. Everything on the counter is there to\nbe taken: the page, the images, the JavaScript, the logo. The back office behind\nit holds the things that run the shop, and a visitor has no route to it. A value\ncompiled into your JavaScript is a line printed in the leaflet on the counter.\nThe ",[14,40,16],{}," file answering at a public address is the folder from the back office,\nleft out on the counter with everything else.",[43,44,46],"h2",{"id":45},"is-my-env-file-exposed","Is my .env file exposed?",[10,48,49,50,53],{},"Open your live site in a browser, put ",[14,51,52],{},"\u002F.env"," on the end of the address, and\npress enter.",[10,55,56],{},"Three things can come back, and only one of them is a problem.",[10,58,59,62],{},[22,60,61],{},"A page from your app."," Most front ends answer every unknown address with their\nown index page, because that is how a single-page app routes. You get your\nhomepage, or your \"not found\" screen. Nothing is being served at that path.",[10,64,65,68],{},[22,66,67],{},"An error."," A 403 or a 404 means the server was asked and declined. That is the\nanswer you want.",[10,70,71,74,75,78,79,82],{},[22,72,73],{},"Plain text, with lines in it."," Something like ",[14,76,77],{},"SUPABASE_URL=https:\u002F\u002F…"," and\n",[14,80,81],{},"SUPABASE_SERVICE_ROLE_KEY=eyJ…",", in a monospaced wall with no styling. The file\nis being handed to anyone who asks for it, and it has been since the day it was\nfirst served.",[84,85,87],"callout",{"type":86},"note",[10,88,89,92,93,96,97,99],{},[22,90,91],{},"Look at what came back, not at the status code."," A server can answer ",[14,94,95],{},"200 OK","\nwith your index page, which is the normal result and means nothing is wrong.\nBrowsers also render a downloaded ",[14,98,16],{}," as bare text, so the window looks\nbroken when the finding is real. The test is whether you are reading your own\nsettings.",[43,101,103],{"id":102},"two-different-things-get-called-an-exposed-env-file","Two different things get called an exposed .env file",[10,105,106],{},"One is about your bundle. The other is about your server.",[108,109,110,126],"table",{},[111,112,113],"thead",{},[114,115,116,120,123],"tr",{},[117,118,119],"th",{},"What happened",[117,121,122],{},"Where the value is",[117,124,125],{},"What it takes to fix",[127,128,129,152],"tbody",{},[114,130,131,146,149],{},[132,133,134,135,138,139,142,143],"td",{},"You named a variable ",[14,136,137],{},"VITE_",", ",[14,140,141],{},"NEXT_PUBLIC_"," or ",[14,144,145],{},"EXPO_PUBLIC_",[132,147,148],{},"Compiled into the JavaScript every visitor downloads",[132,150,151],{},"Move the work to a server, then rotate the key. The file was never served.",[114,153,154,157,163],{},[132,155,156],{},"Your web server publishes your project directory",[132,158,159,160],{},"In the file, at ",[14,161,162],{},"https:\u002F\u002Fyoursite\u002F.env",[132,164,165],{},"Move the file out of what the server publishes, then rotate everything in it.",[10,167,168,169,174],{},"The first row is the common one and it has ",[170,171,173],"a",{"href":172},"\u002Fblog\u002Fvite-and-next-public-env-vars","its own\narticle",": the prefix is an instruction to\npublish, and the build followed it. Everything below is the second row.",[176,177],"diagram",{"alt":178,"caption":179,"src":180},"Two routes out of the same .env file. On the left the build copies one prefixed value into the JavaScript bundle a visitor downloads. On the right the web server hands over the whole file at the address \u002F.env.","Left: the build copied one value into your JavaScript, because the prefix told it to. Right: the server is handing over the file, and the prefixes make no difference at all.","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Ftwo-meanings-1600x840.png",[43,182,184],{"id":183},"why-a-lovable-app-cannot-do-this-and-a-replit-app-can","Why a Lovable app cannot do this and a Replit app can",[10,186,187],{},"Because the two hosts publish different things.",[10,189,190,191,193,194,196],{},"A builder that deploys a static front end hands its host a folder of built files:\nsome HTML, some JavaScript, some images. Your ",[14,192,16],{}," was read during the build\nand is not in that folder, so there is nothing at ",[14,195,52],{}," for anyone to fetch.\nThe host could not serve the file if it wanted to.",[10,198,199],{},"A Replit app usually runs its own server, in its own project directory, with your\nfiles beside your code. A server told to serve its directory serves every file in\nit, and it has no way to know that one of them holds your keys. The same is true\nof anything you deployed to a box of your own.",[10,201,202,203,206],{},"The numbers follow the architecture. Of 30,761 live apps where this check got an\nanswer, 8 were handing out at least one private file. ",[22,204,205],{},"Seven of the eight were\nReplit apps",", and Replit apps were 3,025 of the 30,761. The eighth was on a\ndomain of its own, which says the same thing a different way: somebody was\nrunning their own server.",[10,208,209,210,214],{},"That is the rarest finding we print, and the only one of the nine with no\ninnocent explanation. If you want the wider reading of what Replit apps actually\nship, ",[170,211,213],{"href":212},"\u002Fblog\u002Fis-replit-safe","we scanned 3,042 of them",".",[43,216,218],{"id":217},"the-twelve-paths-to-check","The twelve paths to check",[10,220,221],{},"Twelve addresses, in the order worth typing. Put each one after your domain.",[108,223,224,237],{},[111,225,226],{},[114,227,228,231,234],{},[117,229,230],{},"Address",[117,232,233],{},"What it holds",[117,235,236],{},"If it answers with text",[127,238,239,251,264,276,293,306,319,332,343,354,367,380],{},[114,240,241,245,248],{},[132,242,243],{},[14,244,52],{},[132,246,247],{},"Every key your app was built with",[132,249,250],{},"Treat all of it as public and rotate",[114,252,253,258,261],{},[132,254,255],{},[14,256,257],{},"\u002F.env.local",[132,259,260],{},"The same, from a local run",[132,262,263],{},"Same",[114,265,266,271,274],{},[132,267,268],{},[14,269,270],{},"\u002F.env.production",[132,272,273],{},"The same, from your live deploy",[132,275,263],{},[114,277,278,283,286],{},[132,279,280],{},[14,281,282],{},"\u002F.git\u002Fconfig",[132,284,285],{},"Your repository's remote address",[132,287,288,289,292],{},"The whole ",[14,290,291],{},".git"," directory is usually readable",[114,294,295,300,303],{},[132,296,297],{},[14,298,299],{},"\u002F.git\u002FHEAD",[132,301,302],{},"Which branch you are on",[132,304,305],{},"Same, and it is the quietest of the twelve",[114,307,308,313,316],{},[132,309,310],{},[14,311,312],{},"\u002F.aws\u002Fcredentials",[132,314,315],{},"Long-lived Amazon keys",[132,317,318],{},"Rotate at Amazon, then check the bill",[114,320,321,326,329],{},[132,322,323],{},[14,324,325],{},"\u002Fdatabase.sql",[132,327,328],{},"Schema and rows",[132,330,331],{},"Every row of every table is public",[114,333,334,339,341],{},[132,335,336],{},[14,337,338],{},"\u002Fdump.sql",[132,340,263],{},[132,342,263],{},[114,344,345,350,352],{},[132,346,347],{},[14,348,349],{},"\u002Fbackup.sql",[132,351,263],{},[132,353,263],{},[114,355,356,361,364],{},[132,357,358],{},[14,359,360],{},"\u002Fconfig.json",[132,362,363],{},"Whatever you put in it",[132,365,366],{},"Read it and see; tokens live here more often than people expect",[114,368,369,374,377],{},[132,370,371],{},[14,372,373],{},"\u002Fdocker-compose.yml",[132,375,376],{},"Service definitions, often with passwords in them",[132,378,379],{},"Rotate anything written into it",[114,381,382,387,390],{},[132,383,384],{},[14,385,386],{},"\u002F.npmrc",[132,388,389],{},"A registry token",[132,391,392],{},"Revoke the token",[10,394,395,396,214],{},"Our own scan reads all twelve from outside and names the ones that answered. It\ntakes about 20 seconds and needs no account: ",[170,397,399],{"href":398},"\u002Fsecurity-scanner","scan your\napp",[43,401,403],{"id":402},"what-a-hit-actually-means","What a hit actually means",[10,405,406],{},"Everything in that file is public right now, and has been since the day it was\nfirst served.",[10,408,409],{},"You will not find out who read it. A builder gives you no log of a file being\nfetched that you can go and read, and the request looks like any other request\nfor any other file. What you can be sure of is that somebody tried: automated\ncrawlers walk exactly these twelve paths across the whole internet, all the time,\nand they do not need to know who you are to find yours.",[10,411,412,413,415,416,418,419,422,423,426,427,138,430,433,434,437],{},"Five of the eight apps we found were handing out one of the four that are\nimmediately costly: ",[14,414,16],{},", a ",[14,417,291],{}," directory, ",[14,420,421],{},".aws\u002Fcredentials",", or a ",[14,424,425],{},".sql","\ndump. The other three were handing out ",[14,428,429],{},"config.json",[14,431,432],{},"docker-compose.yml"," or\n",[14,435,436],{},".npmrc",". Those three are the ones people assume are harmless, which is exactly\nwhy tokens and database passwords end up written into them.",[10,439,440,441,445],{},"What this is not is a verdict on your app. An external check reads what your site\nhands to a stranger, and twelve paths answering with nothing is twelve paths\nanswering with nothing. ",[170,442,444],{"href":443},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","What else leaks out of a vibe-coded\napp"," is the longer list.",[43,447,449],{"id":448},"the-one-that-ruins-a-week-a-git-directory","The one that ruins a week: a .git directory",[10,451,452,453,455],{},"A ",[14,454,291],{}," directory is not one file. It is your whole history.",[10,457,458,459,461],{},"Every commit is in there, including the one where you pasted a key in and the\nlater one where you took it out. That is the part people get wrong about a\n",[14,460,291],{}," leak: deleting a secret from the code you have today does nothing about\nthe version where it was still there, and the version where it was still there is\nin the same directory your server is publishing.",[10,463,464,465,467,468,470],{},"The check reads ",[14,466,282],{}," and ",[14,469,299],{}," because those two are small,\ntheir contents are unmistakable, and either one answering means the directory\nitself is being served. From there a reader does not need any special tool. The\nformat is documented and ordinary software clones it.",[10,472,473,474,214],{},"If a key was ever in a commit, rotating it is the only thing that helps. Which\nto do first depends on whether the copy is already out, and ",[170,475,477],{"href":476},"\u002Fblog\u002Frotate-supabase-service-role-key","that order is worth\ngetting right",[43,479,481],{"id":480},"the-dump-somebody-left-in-the-folder","The dump somebody left in the folder",[10,483,484,485,138,487,78,489,214],{},"Three of the twelve paths are database dumps: ",[14,486,325],{},[14,488,338],{},[14,490,349],{},[10,492,493],{},"A dump is every row of every table in one file, with the schema above it. Email\naddresses, hashed passwords, orders, messages, whatever your app holds. It\nanswers at a public address for the dullest reason in this whole article:\nsomebody did the responsible thing, took a copy of their database, and saved it\nin the project folder they happened to be standing in.",[10,495,496,497,501,502,506],{},"So the file made to protect the data became the fastest way to read all of it.\nWhere a copy lives is as much of the decision as whether you take one. ",[170,498,500],{"href":499},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three\nways to back up a Supabase\ndatabase"," covers the options,\nand ",[170,503,505],{"href":504},"\u002Fsupabase-backups","Reeve Care"," keeps a copy of your Supabase database off\nyour own server, verified before it counts as a backup.",[43,508,510],{"id":509},"how-to-fix-it-and-why-the-order-matters","How to fix it, and why the order matters",[10,512,513],{},"Move the file out of what your server publishes. Then rotate every secret that\nwas in it. In that order.",[10,515,516],{},"Rotating first feels like the urgent half, and it is the half that wastes the\nwork. Your new keys go into the same file, the file is still answering at the\nsame address, and you have rotated straight back into the leak. Nothing is safer\nthan it was ten minutes ago.",[176,518],{"alt":519,"caption":520,"src":521},"Two sequences. Rotating before the file is moved puts the new key back into the file the server is still serving. Moving the file first means the rotated key lands somewhere nothing can reach.","Rotate first and the new key lands in the file that is still being handed out. Move first and there is nothing left to hand out.","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Ffix-order-1600x760.png",[10,523,524],{},"Where to put it instead, depending on what you are running:",[526,527,528,535,541],"ul",{},[529,530,531,534],"li",{},[22,532,533],{},"A host with its own secrets store."," Replit Secrets, a platform's environment\nvariables, your hosting dashboard. The value is read by your server at run time\nand never sits in a file under the published directory.",[529,536,537,540],{},[22,538,539],{},"Outside the served directory."," If you control the server config, point it at\na build output folder rather than at the project root. Then a file in the\nproject root has no address at all.",[529,542,543,546],{},[22,544,545],{},"Not in the repository either",", which is a separate habit and a good one. It\ndoes nothing about today's problem.",[10,548,549,550,553],{},"That last point is worth saying plainly, because ",[14,551,552],{},".gitignore"," is the answer\neveryone reaches for. It keeps the file out of your repository. The file on your\nserver got there because the server is sitting in your project directory, and git\nhas no opinion about that.",[43,555,557],{"id":556},"what-to-do-right-now","What to do right now",[559,560,561],"key-takeaways",{},[526,562,563,566,569,572,575],{},[529,564,565],{},"Type all twelve addresses after your own domain, or run the free scan and let it do the typing. Read what comes back rather than the status code.",[529,567,568],{},"If one answers with your own settings, move the file out of the directory your server publishes, and redeploy. That is the step that stops it.",[529,570,571],{},"Then rotate every key, password and token the file held, at each provider. Rotating before the file moves puts the new values back where the old ones were.",[529,573,574],{},"Check billing and provider logs afterwards. Rotation stops what happens next and does nothing about what already happened.",[529,576,577,578,580],{},"If a ",[14,579,291],{}," directory was readable, rotate anything that was ever in a commit, not only what is in the code today.",[10,582,583,584,588],{},"If you would rather work through your app as a list, the\n",[170,585,587],{"href":586},"\u002Fchecklist","10-minute security checklist"," covers this alongside the other\nthings worth closing in a newly launched app.",{"title":590,"searchDepth":591,"depth":591,"links":592},"",3,[593,595,596,597,598,599,600,601,602],{"id":45,"depth":594,"text":46},2,{"id":102,"depth":594,"text":103},{"id":183,"depth":594,"text":184},{"id":217,"depth":594,"text":218},{"id":402,"depth":594,"text":403},{"id":448,"depth":594,"text":449},{"id":480,"depth":594,"text":481},{"id":509,"depth":594,"text":510},{"id":556,"depth":594,"text":557},"Security basics","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcover-1200x630.png","Four sealed folders behind a wall, and one open folder in front of it with its lines of text visible, sitting under an amber band.","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.",false,"md",[610,613,616,619,622],{"q":611,"a":612},"How do I know if my .env file is public?","Open your live site in a browser, put \u002F.env on the end of the address, and press enter. If what comes back is a page from your app, nothing is being served at that path. If what comes back is plain text with lines like SUPABASE_URL=https:\u002F\u002Fabcdefghij.supabase.co, the file is being handed to anyone who asks. Do the same for \u002F.env.local and \u002F.env.production, because a server that publishes one usually publishes all three.",{"q":614,"a":615},"Is a .env file in my bundle the same thing?","No, and the fix is different. A value that ends up inside your JavaScript got there because the build was told to put it there, by a variable named VITE_ or NEXT_PUBLIC_ or EXPO_PUBLIC_. The file never left your machine; the value did. That is a separate problem with its own article. This one is about the file itself being served by your web server, which means every value in it is public, prefixed or not.",{"q":617,"a":618},"Why can someone download my .git folder?","Because your server was pointed at your project directory, and .git is a directory inside it like any other. A server has no idea that one of them is your version history. If \u002F.git\u002Fconfig or \u002F.git\u002FHEAD answers with text, the whole directory is usually readable, and that includes every commit you ever made rather than only the code you have now.",{"q":620,"a":621},"I found a backup.sql on my own site, what now?","Move it out of the directory your server publishes before you do anything else, because the file is being handed out while you read this. Then treat every password, key and personal record in it as public: a dump holds the schema and every row of every table. Then work out how the file got there, which is usually that somebody took a backup in the project folder and never moved it.",{"q":623,"a":624},"Do I rotate keys or delete the file first?","Move the file first, then rotate. Rotating while the file is still being served writes the new values into something anyone can download, so you spend the effort and end up where you started. Once nothing answers at that path, rotate every secret the file held, at each provider, and check billing and logs afterwards.","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",[627,628,629,630,631,632,633,634],".env file exposed","env file publicly accessible",".env exposed on server","download .env from website",".git folder exposed","is my .env file public","backup.sql exposed","config.json exposed",{},true,"Is your .env file exposed? Twelve paths to check","\u002Fblog\u002Fenv-file-exposed-on-your-server","2026-10-04",{"title":5,"description":606},"blog\u002Fenv-file-exposed-on-your-server",[643,644,645],"Two different problems get called a .env file exposed. This one is the file itself sitting on your web server, downloadable by anyone who types the address.","A host that only serves your built front end cannot do this. A real server can, which is why seven of the eight apps we found were Replit apps.","Of 30,761 live apps where our check got an answer, 8 were handing out a private file. Twelve addresses tell you whether you are the ninth.","2026-10-05","AkUBG5_iM2Aor_sQ4KWhgzyKNCeXmqSDh1CKdyoEHbA",[649,655,661,667,673,679,685,690,691,697,703,709,715,721,728,734,740,745,751,757,763,769,775,781,787,792,798,804,809,815,821,827,833,839,845,850,856,862,868,874,880,885,891,897,903,909,915,921,927,933,939,945,951,957,963,968,974,980,986,991,996],{"path":650,"title":651,"description":652,"published":653,"category":603,"image":654,"draft":607},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":656,"title":657,"description":658,"published":659,"category":603,"image":660,"draft":607},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":662,"title":663,"description":664,"published":665,"category":603,"image":666,"draft":607},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":668,"title":669,"description":670,"published":671,"category":603,"image":672,"draft":607},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":674,"title":675,"description":676,"published":677,"category":603,"image":678,"draft":607},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":680,"title":681,"description":682,"published":683,"category":603,"image":684,"draft":607},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":686,"title":687,"description":688,"published":646,"category":603,"image":689,"draft":607},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":638,"title":5,"description":606,"published":639,"category":603,"image":625,"draft":607},{"path":692,"title":693,"description":694,"published":695,"category":603,"image":696,"draft":607},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":698,"title":699,"description":700,"published":701,"category":603,"image":702,"draft":607},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":704,"title":705,"description":706,"published":707,"category":603,"image":708,"draft":607},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":710,"title":711,"description":712,"published":713,"category":603,"image":714,"draft":607},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":716,"title":717,"description":718,"published":719,"category":603,"image":720,"draft":607},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":722,"title":723,"description":724,"published":725,"category":726,"image":727,"draft":607},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":729,"title":730,"description":731,"published":732,"category":726,"image":733,"draft":607},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":735,"title":736,"description":737,"published":738,"category":726,"image":739,"draft":607},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":741,"title":742,"description":743,"published":738,"category":603,"image":744,"draft":607},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":603,"image":750,"draft":607},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":603,"image":756,"draft":607},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":726,"image":762,"draft":607},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":603,"image":768,"draft":607},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":773,"category":603,"image":774,"draft":607},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":776,"title":777,"description":778,"published":779,"category":603,"image":780,"draft":607},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":603,"image":786,"draft":607},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":172,"title":788,"description":789,"published":790,"category":603,"image":791,"draft":607},"Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":793,"title":794,"description":795,"published":796,"category":603,"image":797,"draft":607},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":799,"title":800,"description":801,"published":802,"category":603,"image":803,"draft":607},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":212,"title":805,"description":806,"published":807,"category":603,"image":808,"draft":607},"Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":810,"title":811,"description":812,"published":813,"category":726,"image":814,"draft":607},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":816,"title":817,"description":818,"published":819,"category":726,"image":820,"draft":607},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":822,"title":823,"description":824,"published":825,"category":726,"image":826,"draft":607},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":828,"title":829,"description":830,"published":831,"category":603,"image":832,"draft":607},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":834,"title":835,"description":836,"published":837,"category":603,"image":838,"draft":607},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":840,"title":841,"description":842,"published":843,"category":603,"image":844,"draft":607},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":476,"title":846,"description":847,"published":848,"category":603,"image":849,"draft":607},"How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":851,"title":852,"description":853,"published":854,"category":603,"image":855,"draft":607},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":857,"title":858,"description":859,"published":860,"category":603,"image":861,"draft":607},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":863,"title":864,"description":865,"published":866,"category":603,"image":867,"draft":607},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":869,"title":870,"description":871,"published":872,"category":603,"image":873,"draft":607},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":875,"title":876,"description":877,"published":878,"category":603,"image":879,"draft":607},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":443,"title":881,"description":882,"published":883,"category":603,"image":884,"draft":607},"An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":886,"title":887,"description":888,"published":889,"category":726,"image":890,"draft":607},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":892,"title":893,"description":894,"published":895,"category":603,"image":896,"draft":607},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":898,"title":899,"description":900,"published":901,"category":726,"image":902,"draft":607},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":904,"title":905,"description":906,"published":907,"category":603,"image":908,"draft":607},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":910,"title":911,"description":912,"published":913,"category":603,"image":914,"draft":607},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":916,"title":917,"description":918,"published":919,"category":603,"image":920,"draft":607},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":922,"title":923,"description":924,"published":925,"category":603,"image":926,"draft":607},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":928,"title":929,"description":930,"published":931,"category":726,"image":932,"draft":607},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":934,"title":935,"description":936,"published":937,"category":726,"image":938,"draft":607},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":940,"title":941,"description":942,"published":943,"category":603,"image":944,"draft":607},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":946,"title":947,"description":948,"published":949,"category":603,"image":950,"draft":607},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":952,"title":953,"description":954,"published":955,"category":726,"image":956,"draft":607},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":958,"title":959,"description":960,"published":961,"category":603,"image":962,"draft":607},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":964,"title":965,"description":966,"published":961,"category":603,"image":967,"draft":607},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":969,"title":970,"description":971,"published":972,"category":603,"image":973,"draft":607},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":975,"title":976,"description":977,"published":978,"category":726,"image":979,"draft":607},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":981,"title":982,"description":983,"published":984,"category":603,"image":985,"draft":607},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":987,"title":988,"description":989,"published":984,"category":726,"image":990,"draft":607},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":499,"title":992,"description":993,"published":994,"category":726,"image":995,"draft":607},"Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":997,"title":998,"description":999,"published":994,"category":603,"image":1000,"draft":607},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]