[{"data":1,"prerenderedAt":871},["ShallowReactive",2],{"blog-en-is-base44-safe":3,"blog-index-en":519},{"id":4,"title":5,"body":6,"category":473,"cover":474,"coverAlt":475,"description":476,"draft":477,"extension":478,"faq":479,"image":498,"keywords":499,"meta":508,"navigation":509,"ogTitle":5,"path":510,"published":511,"seo":512,"stem":513,"tldr":514,"updated":511,"__hash__":518},"blog_en\u002Fblog\u002Fis-base44-safe.md","Is Base44 safe? What 5,442 live Base44 apps showed",{"type":7,"value":8,"toc":458},"minimark",[9,13,20,25,28,31,37,41,44,104,113,116,120,123,197,200,203,207,210,218,226,233,237,240,243,249,254,257,264,268,271,274,277,293,300,304,307,310,315,328,343,347,350,358,369,375,381,385,388,391,407,414,418,441],[10,11,12],"p",{},"You built something on Base44, it works, and you are about to put real people on\nit. So you typed \"is base44 safe\" into a search box, and what came back was\nBase44's own blog, Base44's own feature pages, and two guides written from them.\nNone of that is an answer, and your own scan report, if you ran one, probably\nsaid B and left you none the wiser about why.",[10,14,15,16],{},"We can answer part of it. Over the past year we have run the same nine checks\nagainst every live app we could find, and 5,442 of them were Base44 apps. Here\nis the part that guide after guide gets wrong: ",[17,18,19],"strong",{},"a Base44 app and a Lovable app\nfail in opposite places, and the report Base44 gives you is mostly not about\nyou.",[21,22,24],"h2",{"id":23},"is-base44-safe","Is Base44 safe?",[10,26,27],{},"Three different questions are hiding in those four words, and separating them is\nmost of the work.",[10,29,30],{},"The first is whether Base44 the company is safe to trust with your app. The\nsecond is whether the code it writes for you is any good. The third is whether\nthe app you published is safe for strangers to visit. Only the third can be\nmeasured from outside, and on Base44 even that one comes back half answered.",[32,33],"diagram",{"alt":34,"caption":35,"src":36},"Five horizontal bars on one scale, each headed by a small glyph and ending in a numeral: 5,438 for missing headers, 5,417 for a wildcard API header, 3,229 for a published source map, 2,705 for an address that answers without a login, and 95 for a published key. The first four bars are drawn in faint grey and the last in teal.","Numbers of apps out of 5,442, on one scale. The grey bars are decided by Base44. The teal one is the only line on the report that followed from something in the app.","\u002Fblog\u002Fis-base44-safe\u002Fwhat-we-found-1600x680.png",[21,38,40],{"id":39},"what-we-found-in-5442-base44-apps","What we found in 5,442 Base44 apps",[10,42,43],{},"Four findings, in almost every app, and all four belong to the platform.",[45,46,47,60],"table",{},[48,49,50],"thead",{},[51,52,53,57],"tr",{},[54,55,56],"th",{},"What the check found",[54,58,59],{},"Apps",[61,62,63,72,80,88,96],"tbody",{},[51,64,65,69],{},[66,67,68],"td",{},"Security headers missing",[66,70,71],{},"5,438",[51,73,74,77],{},[66,75,76],{},"API answers requests from any website",[66,78,79],{},"5,417",[51,81,82,85],{},[66,83,84],{},"A source map published",[66,86,87],{},"3,229",[51,89,90,93],{},[66,91,92],{},"An address that answers without a login",[66,94,95],{},"2,705",[51,97,98,101],{},[66,99,100],{},"A key published in the page",[66,102,103],{},"95",[10,105,106,107,112],{},"The first two are response headers, and a response header on a Base44 app is set\nby Base44's hosting rather than by anything you wrote. The third and fourth look\nalarming on a report and are not yours either: the only source map that answers\non a Base44 app belongs to Base44's own badge script, and the address that\nanswers is the same one every time. We went back to 30 of the flagged apps in\nSeptember 2026 and\n",[108,109,111],"a",{"href":110},"\u002Fblog\u002Fbase44-source-maps","wrote up what those two lines actually mean",", because\nthey are the two most misread lines on a Base44 report.",[10,114,115],{},"That leaves 103 apps out of 5,442 carrying something in the page that a person\npasted there: 95 of them a Google API key, 11 some other secret-shaped string,\nand one a live Stripe secret key. Those are the lines on a Base44 report that\nsomebody put there, and the only ones somebody can take away.",[21,117,119],{"id":118},"why-nearly-every-base44-app-scores-b","Why nearly every Base44 app scores B",[10,121,122],{},"Because the grade is capped by the worst thing found, and almost every Base44 app\nhas the same medium finding.",[45,124,125,138],{},[48,126,127],{},[51,128,129,132,135],{},[54,130,131],{},"Grade",[54,133,134],{},"Base44 (5,442)",[54,136,137],{},"Lovable (18,563)",[61,139,140,151,164,175,186],{},[51,141,142,145,148],{},[66,143,144],{},"A",[66,146,147],{},"1,205 (22%)",[66,149,150],{},"15,972 (86%)",[51,152,153,156,161],{},[66,154,155],{},"B",[66,157,158],{},[17,159,160],{},"4,231 (78%)",[66,162,163],{},"370 (2%)",[51,165,166,169,172],{},[66,167,168],{},"C",[66,170,171],{},"4",[66,173,174],{},"1,814 (10%)",[51,176,177,180,183],{},[66,178,179],{},"D",[66,181,182],{},"2",[66,184,185],{},"402 (2%)",[51,187,188,191,194],{},[66,189,190],{},"F",[66,192,193],{},"0",[66,195,196],{},"5",[10,198,199],{},"Read the shape rather than the ranking. Base44's report is one tall bar at B with\nalmost nothing under it: six apps out of 5,442 scored below B, and not one\nscored F. Lovable is the other shape entirely, 86% at A with about one in eight\nat C or worse. The same nine checks produced a flat distribution on one platform\nand a split one on the other, and neither picture is a verdict on any individual\napp, including yours.",[10,201,202],{},"So a B on a Base44 app is close to the floor for the platform, and the useful\nreading of your report is not the letter. It is whether the key line and the\nsecret line are empty.",[21,204,206],{"id":205},"the-95-keys-that-were-actually-yours","The 95 keys that were actually yours",[10,208,209],{},"A key in your published page is the one finding on a Base44 report that nobody\nelse put there.",[10,211,212,213,217],{},"95 of the 5,442 apps shipped a Google API key and 11 shipped something else that\nlooked like a secret. One shipped a live Stripe secret key, and one a restricted\nStripe key. A Google API key in a page is usually fine and sometimes a bill,\ndepending entirely on whether it was restricted when it was created, which is\n",[108,214,216],{"href":215},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","a five-minute thing to check and fix",".\nA Stripe secret key in a page is not in that category at all: it reads customers,\nmoves money and issues refunds, and it needs rotating before you finish reading\nthis.",[10,219,220,221,225],{},"If you are unsure which of your keys are supposed to be public, that question has\na short answer and we wrote it down:\n",[108,222,224],{"href":223},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","which keys belong in a browser and which never do",".",[10,227,228,229,225],{},"Our free scan reads your live Base44 app from outside and tells you which keys\nand addresses it can see. It takes about 20 seconds and needs no account:\n",[108,230,232],{"href":231},"\u002Fsecurity-scanner","scan your app",[21,234,236],{"id":235},"the-one-thing-nobody-can-check-from-outside","The one thing nobody can check from outside",[10,238,239],{},"Whether a stranger can read your data. Not us, not any other scanner, and the\nreason is Base44's own design.",[10,241,242],{},"On most builders your app talks to its database directly from the visitor's\nbrowser. That means the database has a public address, your app carries it, and\nanybody can lift it out and ask the database questions. Whether they get answers\ndepends on a per-table setting the owner may never have seen. It is the single\nbiggest cause of leaked data in apps built this way, and on Base44 it is not\navailable to you, because requests go through Base44 instead.",[10,244,245,246,248],{},"The measurement says so plainly. 1,466 of the 5,442 Base44 apps name a Supabase\nproject somewhere in their page. Our row-level-security check could get a usable\nanswer from ",[17,247,182],{}," of them.",[32,250],{"alt":251,"caption":252,"src":253},"Three bars narrowing left to right on one scale: 5,442 Base44 apps, 1,466 that name a Supabase project, and a bar of 2 drawn as a hairline with a ring around it. A dashed outline continues from the hairline to the width of the second bar, holding a question mark, with the numeral 1,464 beneath it.","The third bar is two apps. The dashed part is the 1,464 that gave the check nothing to read, which is what a database with no public address looks like from the street.","\u002Fblog\u002Fis-base44-safe\u002Fwhat-nobody-can-ask-1600x620.png",[10,255,256],{},"Compare that with the builders where the door is on the street. On Lovable, 6,535\napps name a Supabase project, 3,553 gave the check a usable answer, and 2,017 of\nthose handed rows to a request with no login. On Bolt, 35 of 267 answered. On v0,\nnone of 17 did.",[10,258,259,260,263],{},"Two apps is not a rate, and we are not going to print one. ",[17,261,262],{},"The honest summary\nis that your Base44 data is behind a door we cannot reach, which is better than a\ndoor standing open, and is not the same as knowing it is locked."," What decides\nit is on the inside: who can sign up, what a signed-up account can see, and\nwhether any screen was built on the assumption that nobody would look.",[21,265,267],{"id":266},"which-means-the-inside-check-is-the-one-that-matters-here","Which means the inside check is the one that matters here",[10,269,270],{},"Base44 runs one, and on a Base44 app it sees the half we cannot.",[10,272,273],{},"Base44's security page says you can run a security scan from every app's Security\ntab, and that it checks third-party dependencies, insecure code patterns, exposed\nsecrets, missing login checks and weak data access rules. Those last two are the\nexact questions an outside scan cannot reach on a Base44 app. Read on 6 October\n2026.",[10,275,276],{},"The reverse is also true, which is why the 95 is in this article. An inside\nscanner reads your project; it has no particular reason to fetch your published\npage and read what went out in it. So the two answer different halves, and a\nBase44 owner who runs only one of them is blind in a specific way:",[278,279,280,287],"ul",{},[281,282,283,286],"li",{},[17,284,285],{},"Base44's Security tab"," reads the project: your dependencies, your code, your\nlogin checks, your data access rules.",[281,288,289,292],{},[17,290,291],{},"An outside scan"," reads what your visitors receive: the keys in the page, the\naddresses it calls, the headers that come back, whether a map went out with it.",[10,294,295,296,225],{},"Run the inside one before you publish and an outside one afterwards. Base44's\ndocumentation describes that scan in more detail than their security page does,\nand we went through it: ",[108,297,299],{"href":298},"\u002Fblog\u002Fbase44-security-scan","what it checks, and why it can come back clean while\nyour published page still carries a key",[21,301,303],{"id":302},"if-you-attached-your-own-supabase-project","If you attached your own Supabase project",[10,305,306],{},"Then the street door is back, and the per-table setting is yours again.",[10,308,309],{},"Base44 lets you connect your own Supabase project instead of using the database\nit provides. That changes the most important thing in this article: your project\nanswers the internet directly, your page carries its address, and Row Level\nSecurity is now the only thing between a stranger and a table. It is off by\ndefault for any table created by running SQL.",[32,311],{"alt":312,"caption":313,"src":314},"Two panels. On the left, a Base44 app arrows into a Base44 platform panel with a database sealed inside it, and a visitor's separate route to that database is drawn as a dashed line stopping at the panel wall. On the right, the same app arrows out to a database standing on its own, with the visitor's route reaching it directly through a gate.","Left is a Base44 app on Base44's own database. Right is the same app with your Supabase project attached. The gate on the right is Row Level Security, and it is the one you set.","\u002Fblog\u002Fis-base44-safe\u002Fyour-own-supabase-1600x620.png",[10,316,317,318,322,323,327],{},"This is the one path by which the classic open-database problem reaches a Base44\napp, and it is checkable in both directions: our scan can ask your Supabase\nproject the same question it asks on any other builder, and\n",[108,319,321],{"href":320},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","the five-minute version of the check","\nis a page in your own dashboard. If you have tables holding anything about\npeople,\n",[108,324,326],{"href":325},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","turning it on for every table"," is the\nfirst thing to do today.",[10,329,330,331,334,335,338,339,225],{},"A Supabase project you own is also a database you are responsible for keeping a\ncopy of. ",[17,332,333],{},"Care"," keeps a copy of your ",[17,336,337],{},"Supabase"," database on a schedule and\ngives you a one-click restore, and connecting a Storage credential brings your\nuploaded files along too. It covers Supabase, so it is for this branch of the\narticle and not for a Base44 app on Base44's own database:\n",[108,340,342],{"href":341},"\u002Fsupabase-backups","how backups work",[21,344,346],{"id":345},"the-five-minute-check-on-your-own-base44-app","The five-minute check on your own Base44 app",[10,348,349],{},"Four things, in the order they are worth doing.",[10,351,352,355,356,225],{},[17,353,354],{},"Open your published app and look at what went out with it."," Press F12, open\nthe Network tab, reload, and read the requests. You are looking for a key in a\nURL or a response, and for an address you do not recognise. Our scan does this\nfrom outside and lists what it found, which is faster than reading it yourself:\n",[108,357,232],{"href":231},[10,359,360,363,364,368],{},[17,361,362],{},"If you find a key, identify it before you panic."," A Google API key wants\nrestricting rather than rotating. Anything beginning ",[365,366,367],"code",{},"sk_"," wants rotating now.",[10,370,371,374],{},[17,372,373],{},"Open Base44's Security tab and run the scan there too."," It is the only one of\nthe two that can see your login checks and your data access rules.",[10,376,377,380],{},[17,378,379],{},"Then sign up to your own app as a stranger would."," Make a second account, give\nit nothing, and see what it can reach. That is the question the outside scan\ncannot ask, and it costs one signup to answer.",[21,382,384],{"id":383},"your-app-changes-every-time-you-publish","Your app changes every time you publish",[10,386,387],{},"A scan is a reading of one moment, and the moment ends the next time you press\npublish.",[10,389,390],{},"That is not a Base44 problem, it is how any of these builders work: a prompt that\nadds a feature can add a key, a new page, or an address that answers. The 95 apps\nwe found a key in were not built by people who wanted a key in the page. They\nwere built one prompt at a time.",[278,392,393,399],{},[281,394,395,398],{},[17,396,397],{},"Monitor"," re-runs the nine checks on a schedule and tells you when an answer\nchanges.",[281,400,401,403,404,406],{},[17,402,333],{}," adds a copy of your ",[17,405,337],{}," database, kept on a schedule, with a\none-click restore.",[10,408,409,410,225],{},"Both read the same nine checks this article is built on:\n",[108,411,413],{"href":412},"\u002Fpricing","see what each one covers",[21,415,417],{"id":416},"what-to-do-this-week","What to do this week",[419,420,421],"key-takeaways",{},[278,422,423,426,432,435,438],{},[281,424,425],{},"Read your report's key line and secret line, not the letter. A B on a Base44 app is the platform's floor, and 4,231 of the 5,442 apps we graded are sitting on it.",[281,427,428,429,431],{},"If a key is in your published page, identify it first. A Google API key gets restricted; anything beginning ",[365,430,367],{}," gets rotated today.",[281,433,434],{},"Run Base44's own scan from your app's Security tab as well. On a Base44 app it is the only one of the two that can see your login checks and your data access rules.",[281,436,437],{},"Sign up to your own app as a stranger and see what the new account can reach. No outside scan can answer that, on any builder.",[281,439,440],{},"If you attached your own Supabase project, turn on Row Level Security for every table and then check it actually works, because that is the one route by which a stranger reaches your data directly.",[10,442,443,444,448,449,453,454,225],{},"If you would rather work through this as a list, the\n",[108,445,447],{"href":446},"\u002Fchecklist","10-minute security checklist"," covers this and the other things worth\nswitching off in a newly launched app. The plain-language walkthrough for this\nplatform is ",[108,450,452],{"href":451},"\u002Fis-your-base44-app-safe","is your Base44 app safe",", and the\ncross-builder comparison is\n",[108,455,457],{"href":456},"\u002Fblog\u002Fsafest-ai-app-builder","in its own article",{"title":459,"searchDepth":460,"depth":460,"links":461},"",3,[462,464,465,466,467,468,469,470,471,472],{"id":23,"depth":463,"text":24},2,{"id":39,"depth":463,"text":40},{"id":118,"depth":463,"text":119},{"id":205,"depth":463,"text":206},{"id":235,"depth":463,"text":236},{"id":266,"depth":463,"text":267},{"id":302,"depth":463,"text":303},{"id":345,"depth":463,"text":346},{"id":383,"depth":463,"text":384},{"id":416,"depth":463,"text":417},"Security basics","\u002Fblog\u002Fis-base44-safe\u002Fcover-1200x630.png","A Base44 app card in front of a shuttered platform panel with a database sealed inside it, and visitors reaching the app from the right.","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.",false,"md",[480,483,486,489,492,495],{"q":481,"a":482},"Is Base44 safe for a real product?","On the things we can read from outside, Base44 apps are quiet. Of 5,442 we graded, six scored worse than B and none scored F. What stops us answering the question properly is that a Base44 app keeps its data behind Base44 rather than at a public address, so the check that condemned thousands of apps on other builders cannot run at all here. That is genuinely better than a public database left open, and it is not the same as a clean bill of health. The part you can act on today is your own keys: 95 of those 5,442 apps shipped a Google API key in the page.",{"q":484,"a":485},"Why does my Base44 app get a B?","Almost certainly because of two response headers that Base44 sets for every app it hosts, not because of anything you built. 5,438 of the 5,442 apps we graded were missing security headers and 5,417 told any website in the world that it could call their API. Both are decided by the hosting. The source-map line on your report is also the platform rather than you: the only map that answers on a Base44 app belongs to Base44's own badge script.",{"q":487,"a":488},"Can people see my Base44 source code?","They can read the browser half of any app, because a browser cannot draw a page it was not sent. Your original files with their comments and names are a different thing, and on the Base44 apps we re-checked in September 2026 those were not published. 3,229 of 5,442 apps were flagged for a source map, and every one we opened held Base44's own code for its badge script rather than yours. We wrote that up separately.",{"q":490,"a":491},"Is my data safe in a Base44 app?","Nobody outside your app can tell you, us included, and that is a fact about how Base44 is built rather than a gap in our scan. Your app asks Base44 for data and Base44 asks the database, so there is no address a stranger can type. The questions that decide the answer are therefore all on the inside: who can sign up, what a signed-up person can see, and whether any screen was built assuming nobody would look. Base44's own security scan reads that half. An outside scan reads the other one.",{"q":493,"a":494},"Does Base44's own security scan catch this?","It reads the half we cannot. Base44's security page says you can run a scan from every app's Security tab, and that it checks third-party dependencies, insecure code patterns, exposed secrets, missing login checks and weak data access rules. Those last two are exactly what an outside scan structurally cannot see on a Base44 app. What it has no reason to look at is what your published page hands to a visitor, which is where we found the 95 Google API keys. Run both, and read them as two halves of one answer.",{"q":496,"a":497},"Is Base44 safer than Lovable?","Their reports look opposite and the difference is real. 15,972 of 18,563 Lovable apps scored A, and about one in eight scored C or worse, because a Lovable app talks to its database straight from the browser and that database is often left readable. Base44 has almost no serious tail at all: six apps out of 5,442 below B. What you give up for that is the ability to check it yourself from outside. We compare all five builders in a separate article rather than repeating the table here.","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",[500,501,502,503,504,505,506,507],"is base44 safe","base44 security","is base44 secure","base44 app security","are base44 apps safe","base44 data security","base44 supabase security","base44 review",{},true,"\u002Fblog\u002Fis-base44-safe","2026-10-06",{"title":5,"description":476},"blog\u002Fis-base44-safe",[515,516,517],"Is Base44 safe? 4,231 of the 5,442 live Base44 apps we graded scored B, and four findings that belong to Base44 rather than to the app owner account for nearly all of it.","What the owner actually got wrong was rare: 103 of those apps published a key or a secret in the page, 95 of them a Google API key and one a live Stripe secret key.","The question most people mean by \"is it safe\" cannot be answered from outside a Base44 app. 1,466 of them name a Supabase project and only 2 would let us ask whether a stranger can read it.","272cSVuotCByuRFFkntN0U9J_QEwpvfOMvW0NLgvp_o",[520,526,531,537,543,549,550,556,562,568,574,580,586,592,599,605,611,616,622,628,634,640,646,652,658,664,669,675,681,687,693,699,704,709,715,721,727,733,739,745,751,757,763,769,775,781,787,793,799,805,811,817,822,828,833,838,844,850,856,861,867],{"path":521,"title":522,"description":523,"published":524,"category":473,"image":525,"draft":477},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":298,"title":527,"description":528,"published":529,"category":473,"image":530,"draft":477},"Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":532,"title":533,"description":534,"published":535,"category":473,"image":536,"draft":477},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":538,"title":539,"description":540,"published":541,"category":473,"image":542,"draft":477},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":544,"title":545,"description":546,"published":547,"category":473,"image":548,"draft":477},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":510,"title":5,"description":476,"published":511,"category":473,"image":498,"draft":477},{"path":551,"title":552,"description":553,"published":554,"category":473,"image":555,"draft":477},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":557,"title":558,"description":559,"published":560,"category":473,"image":561,"draft":477},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":563,"title":564,"description":565,"published":566,"category":473,"image":567,"draft":477},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":569,"title":570,"description":571,"published":572,"category":473,"image":573,"draft":477},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":575,"title":576,"description":577,"published":578,"category":473,"image":579,"draft":477},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":581,"title":582,"description":583,"published":584,"category":473,"image":585,"draft":477},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":587,"title":588,"description":589,"published":590,"category":473,"image":591,"draft":477},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":593,"title":594,"description":595,"published":596,"category":597,"image":598,"draft":477},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":600,"title":601,"description":602,"published":603,"category":597,"image":604,"draft":477},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":606,"title":607,"description":608,"published":609,"category":597,"image":610,"draft":477},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":612,"title":613,"description":614,"published":609,"category":473,"image":615,"draft":477},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":617,"title":618,"description":619,"published":620,"category":473,"image":621,"draft":477},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":623,"title":624,"description":625,"published":626,"category":473,"image":627,"draft":477},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":629,"title":630,"description":631,"published":632,"category":597,"image":633,"draft":477},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":635,"title":636,"description":637,"published":638,"category":473,"image":639,"draft":477},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":473,"image":645,"draft":477},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":647,"title":648,"description":649,"published":650,"category":473,"image":651,"draft":477},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":653,"title":654,"description":655,"published":656,"category":473,"image":657,"draft":477},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":659,"title":660,"description":661,"published":662,"category":473,"image":663,"draft":477},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":110,"title":665,"description":666,"published":667,"category":473,"image":668,"draft":477},"Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":670,"title":671,"description":672,"published":673,"category":473,"image":674,"draft":477},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":676,"title":677,"description":678,"published":679,"category":473,"image":680,"draft":477},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":682,"title":683,"description":684,"published":685,"category":597,"image":686,"draft":477},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":688,"title":689,"description":690,"published":691,"category":597,"image":692,"draft":477},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":694,"title":695,"description":696,"published":697,"category":597,"image":698,"draft":477},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":456,"title":700,"description":701,"published":702,"category":473,"image":703,"draft":477},"Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":325,"title":705,"description":706,"published":707,"category":473,"image":708,"draft":477},"Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":710,"title":711,"description":712,"published":713,"category":473,"image":714,"draft":477},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":716,"title":717,"description":718,"published":719,"category":473,"image":720,"draft":477},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":722,"title":723,"description":724,"published":725,"category":473,"image":726,"draft":477},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":728,"title":729,"description":730,"published":731,"category":473,"image":732,"draft":477},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":734,"title":735,"description":736,"published":737,"category":473,"image":738,"draft":477},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":740,"title":741,"description":742,"published":743,"category":473,"image":744,"draft":477},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":473,"image":750,"draft":477},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":473,"image":756,"draft":477},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":597,"image":762,"draft":477},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":473,"image":768,"draft":477},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":773,"category":597,"image":774,"draft":477},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":776,"title":777,"description":778,"published":779,"category":473,"image":780,"draft":477},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":473,"image":786,"draft":477},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":788,"title":789,"description":790,"published":791,"category":473,"image":792,"draft":477},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":794,"title":795,"description":796,"published":797,"category":473,"image":798,"draft":477},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":800,"title":801,"description":802,"published":803,"category":597,"image":804,"draft":477},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":806,"title":807,"description":808,"published":809,"category":597,"image":810,"draft":477},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":812,"title":813,"description":814,"published":815,"category":473,"image":816,"draft":477},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":215,"title":818,"description":819,"published":820,"category":473,"image":821,"draft":477},"Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":823,"title":824,"description":825,"published":826,"category":597,"image":827,"draft":477},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":320,"title":829,"description":830,"published":831,"category":473,"image":832,"draft":477},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":834,"title":835,"description":836,"published":831,"category":473,"image":837,"draft":477},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":839,"title":840,"description":841,"published":842,"category":473,"image":843,"draft":477},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":845,"title":846,"description":847,"published":848,"category":597,"image":849,"draft":477},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":851,"title":852,"description":853,"published":854,"category":473,"image":855,"draft":477},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":857,"title":858,"description":859,"published":854,"category":597,"image":860,"draft":477},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":862,"title":863,"description":864,"published":865,"category":597,"image":866,"draft":477},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":223,"title":868,"description":869,"published":865,"category":473,"image":870,"draft":477},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]