[{"data":1,"prerenderedAt":779},["ShallowReactive",2],{"blog-en-is-replit-safe":3,"blog-index-en":539},{"id":4,"title":5,"body":6,"category":497,"cover":498,"coverAlt":499,"description":500,"draft":501,"extension":502,"faq":503,"image":519,"keywords":520,"meta":528,"navigation":529,"ogTitle":5,"path":530,"published":531,"seo":532,"stem":533,"tldr":534,"updated":531,"__hash__":538},"blog_en\u002Fblog\u002Fis-replit-safe.md","Is Replit safe? What we found in 3,042 live Replit apps",{"type":7,"value":8,"toc":482},"minimark",[9,13,21,24,29,32,35,57,60,66,70,83,230,233,238,242,245,253,256,260,263,274,279,285,293,300,304,312,315,330,334,337,345,361,365,368,371,379,383,386,420,424,427,434,438,469],[10,11,12],"p",{},"You built something on Replit, it works, and you are about to put real people\non it. Somewhere in that week you typed \"is replit safe\" into a search box, and\nwhat came back was either a page about Replit's certifications or a page about\nan AI agent that deleted a database. Neither one said a word about the app you\nare about to publish.",[10,14,15,16,20],{},"Here is the part most of those answers get wrong: ",[17,18,19],"strong",{},"\"is Replit safe\" is three\nquestions wearing one sentence",", and the one that decides whether strangers can\nread your users' data is the one almost nobody measures.",[10,22,23],{},"We can measure it. Between 12 and 14 August 2026 we ran the same nine external\nchecks anyone can run free on our homepage over 30,998 live apps, and 3,042 of\nthem were published on Replit. This is what came back for those, and where our\nview stops.",[25,26,28],"h2",{"id":27},"is-replit-safe","Is Replit safe?",[10,30,31],{},"As a host, it was not where the findings were. The two things we can see about\nthe hosting from outside came back clean on every app that answered, and the\nnine apps that graded D or F all got there through something inside the app.",[10,33,34],{},"Think of Replit as a rented shop with a workshop at the back. The landlord owns\nthe building and the lock on the street door. Whoever fitted the shop out\ndecided where the shelves went and how the back room connects to the front. And\nwhat a passer-by can reach from the pavement is decided by you, every time you\nopen. Those are three different questions, and a good answer to the first two\nsays nothing about the third.",[36,37,38,45,51],"ol",{},[39,40,41,44],"li",{},[17,42,43],{},"The platform."," Does Replit host your app properly: a valid certificate, a\ndomain that will not lapse, secrets kept encrypted and out of your files.\nThis is the landlord.",[39,46,47,50],{},[17,48,49],{},"The agent."," Is the code Replit's AI writes safe. This is the fitter, and\nno scan from outside can see the wiring.",[39,52,53,56],{},[17,54,55],{},"The app you published."," What a stranger can reach from the street: a key\nin the code a browser downloads, an API route that answers with no login, a\nfile that should never have had a URL.",[10,58,59],{},"Our checks read the third. On the first, the certificate was valid on all 3,028\napps where we could read one, and no domain out of 3,042 was near expiry. On\nthe second we have nothing to measure, and the section on it below says so.",[61,62],"diagram",{"alt":63,"caption":64,"src":65},"Three panels side by side. The first holds the Replit logo with a padlock and a certificate beside it. The second holds a code glyph with a sparkle over it. The third holds a browser page in front of a server, with three visitors reaching toward it, and a magnifying glass drawn over that panel alone, with the numeral 3,042 beneath it.","Three questions inside one search. A scan from outside reads the third panel and nothing in the other two.","\u002Fblog\u002Fis-replit-safe\u002Fthree-questions-1600x700.png",[25,67,69],{"id":68},"what-we-found-in-3042-replit-apps","What we found in 3,042 Replit apps",[10,71,72,73,76,77,82],{},"Nine checks, run from outside, with no login and no access to anyone's account.\nWe never read a row: where a database answered, we asked how many rows it would\nhand over and stopped there. No app is named here or anywhere else we publish.\nEvery share below is of the apps that check ",[17,74,75],{},"answered"," on, because a check\nthat could not finish is unknown rather than passed, and that rule is why the\ndenominators move. The method and the data are\n",[78,79,81],"a",{"href":80},"\u002Fresearch\u002Fvibe-coded-app-security-2026","in the report",".",[84,85,86,103],"table",{},[87,88,89],"thead",{},[90,91,92,96,100],"tr",{},[93,94,95],"th",{},"What we checked",[93,97,99],{"align":98},"right","Replit apps",[93,101,102],{},"Who decides it",[104,105,106,118,129,139,150,160,170,189,199,209,220],"tbody",{},[90,107,108,112,115],{},[109,110,111],"td",{},"Browser security headers missing",[109,113,114],{"align":98},"2,924 of 3,042 (96%)",[109,116,117],{},"Whatever serves the page",[90,119,120,123,126],{},[109,121,122],{},"An API route that answered a stranger with data",[109,124,125],{"align":98},"1,050 of 3,037 (35%)",[109,127,128],{},"Your app",[90,130,131,134,137],{},[109,132,133],{},"Something key-shaped in the code a visitor downloads",[109,135,136],{"align":98},"219 of 3,042 (7%)",[109,138,128],{},[90,140,141,144,147],{},[109,142,143],{},"Original source code published (source maps)",[109,145,146],{"align":98},"168 of 3,041 (6%)",[109,148,149],{},"A build setting",[90,151,152,155,158],{},[109,153,154],{},"Any website allowed to call your API",[109,156,157],{"align":98},"76 of 3,037",[109,159,128],{},[90,161,162,165,168],{},[109,163,164],{},"Any website allowed to call it with your users' cookies attached",[109,166,167],{"align":98},"56 of 3,037",[109,169,128],{},[90,171,172,184,187],{},[109,173,174,175,179,180,183],{},"A private file such as ",[176,177,178],"code",{},".env"," or ",[176,181,182],{},".git\u002Fconfig"," at a public URL",[109,185,186],{"align":98},"7 of 3,023",[109,188,128],{},[90,190,191,194,197],{},[109,192,193],{},"A database table readable with no login",[109,195,196],{"align":98},"4 of 3,033",[109,198,128],{},[90,200,201,204,207],{},[109,202,203],{},"A storage bucket that lists its files",[109,205,206],{"align":98},"0 of 3,035",[109,208,128],{},[90,210,211,214,217],{},[109,212,213],{},"Certificate expired or untrusted",[109,215,216],{"align":98},"0 of 3,028",[109,218,219],{},"Replit",[90,221,222,225,228],{},[109,223,224],{},"Domain about to lapse",[109,226,227],{"align":98},"0 of 3,042",[109,229,219],{},[10,231,232],{},"The grades: 2,789 A, 183 B, 61 C, 8 D and 1 F. Thirty-one apps had no finding\nat all.",[61,234],{"alt":235,"caption":236,"src":237},"Seven horizontal bars on one scale, each headed by a small glyph and ending in a numeral: 2,924 for headers, 1,050 for open routes, 219 for keys, 168 for source maps, 76 and 56 for the two cross-origin findings, and 7 for private files. The top bar is drawn in a faint grey and the rest in teal, with the 7 drawn as a hairline with a ring around it.","One scale for all seven. The grey bar is decided by the hosting. Every teal bar followed from something in the app.","\u002Fblog\u002Fis-replit-safe\u002Fwhat-we-found-1600x720.png",[25,239,241],{"id":240},"why-99-had-a-finding-means-little-here","Why \"99% had a finding\" means little here",[10,243,244],{},"Because 2,924 of those findings are the same one, and it is the least urgent\nline a report can carry.",[10,246,247,248,252],{},"Browser security headers are sent by whatever serves your page. On a builder's\nown domain that is the builder, which is why the number is 96% here, 99% on\nLovable and 100% on v0, and why every app on the same host gets the same\nanswer. Replit is one of the few places where you can change it: if your app\nruns its own server, that server is the thing sending the headers, and\n",[78,249,251],{"href":250},"\u002Fblog\u002Fmissing-security-headers","adding them is a few lines",". It is worth doing\nand it is not what a D is made of.",[10,254,255],{},"Leave that row out and 1,798 of the 3,042 apps had nothing that followed from\nwhat was built. The other 1,244 are where the rest of this post lives.",[25,257,259],{"id":258},"the-finding-that-is-replit-shaped-an-api-route-of-your-own","The finding that is Replit-shaped: an API route of your own",[10,261,262],{},"The commonest thing we found that an owner had put there was a route on the\napp's own server that answered a stranger with data. 1,050 of 3,037 apps had at\nleast one.",[10,264,265,266,269,270,273],{},"A Lovable app is a front end plus a database that somebody else runs. A Replit\napp is usually the whole shop: the page, and a server behind it that talks to\nthe database, in the same project and often written in the same session. The\nseventh of our nine checks reads the API paths written into your app's\nJavaScript, ",[176,267,268],{},"\u002Fapi\u002Forders",", ",[176,271,272],{},"\u002Fapi\u002Fusers",", whatever it finds, and asks each one,\nwith no login, whether it will answer. On Lovable that fired on 8 apps out of\n18,518, because there is usually no server of the owner's to ask. On Replit it\nfired on 1,050.",[61,275],{"alt":276,"caption":277,"src":278},"Two apps drawn side by side. On the left, a browser page with a dashed arrow leaving the panel to a database cylinder outside it, and the numeral 8 beneath. On the right, a browser page with a server drawn behind it inside the same panel, a visitor at the panel's edge receiving a block of data from that server, and the numeral 1,050 beneath.","The left app has no server of its own to leave open. The right one does, and that is where its findings are.","\u002Fblog\u002Fis-replit-safe\u002Fthe-server-you-own-1600x640.png",[10,280,281,282,284],{},"It is graded medium because sometimes that is exactly right. A route that\nreturns your public list of products should answer everyone. It is wrong when\nthe route is ",[176,283,272],{}," and the answer is your users with their email\naddresses, and the way you find out is that anybody can open that address in a\ntab and read it. A route that should be private needs a login check, and\neveryone without one gets a 401.",[10,286,287,288,292],{},"In the shop, this is the back door that opens from the street. If you have\nused Supabase, it is the same failure you have seen described as\n",[78,289,291],{"href":290},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","a table without Row Level Security",",\nin a different shape. The rows are readable because nothing between the\nstranger and the data asked who they were.",[10,294,295,296,82],{},"Two smaller findings sit beside it. 76 apps told any website in the world it\nmay call their API, and 56 more allowed that with the visitor's login cookies\nattached, which is the version that lets another site act as your user and\n",[78,297,299],{"href":298},"\u002Fblog\u002Fcors-wildcard-security-risk","the one that is rarely right",[25,301,303],{"id":302},"what-7-shipped-a-secret-is-made-of","What \"7% shipped a secret\" is made of",[10,305,306,307,311],{},"Mostly Google keys. 219 of the 3,042 apps had something key-shaped in the code a\nvisitor downloads, and 200 of those were a Google API key, which is usually fine\nonce it has been ",[78,308,310],{"href":309},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","restricted to your own domain",".\nThirty-two carried a key-shaped value we could not attribute to a provider.\nThree apps held a key that bills an account directly: an OpenAI, an Anthropic or\nan AWS key.",[10,313,314],{},"Three out of 3,042 is rare. It is also the finding that costs money on its own,\nthe till key left on the counter, and it tends to surface as a usage bill\narriving before anyone has noticed. A\nscanner that matches shapes would print all 219 as problems; we read what each\nkey can do, because the alternative is teaching you to ignore the warning on the\nday it matters.",[10,316,317,318,322,323,179,326,329],{},"On Replit the route a key takes into the bundle is specific enough to have\n",[78,319,321],{"href":320},"\u002Fblog\u002Freplit-secrets-explained","its own article",". The Secrets tool keeps a\nvalue out of your files, which it does well. It cannot keep the value out of the\nbrowser if browser code is what reads it, and the way people make that work is\nto rename the variable ",[176,324,325],{},"VITE_",[176,327,328],{},"NEXT_PUBLIC_",", which is an instruction to\nthe build tool to publish it.",[25,331,333],{"id":332},"the-two-you-can-fix-in-a-setting","The two you can fix in a setting",[10,335,336],{},"Source maps and a stray private file. Both are decided by how the project is\nbuilt, and both are a setting rather than a rewrite.",[10,338,339,340,344],{},"168 apps published source maps, which means the original files behind the app,\ncomments included, are readable from any browser's developer tools. On Replit\nthe build configuration is in your project, so the switch is yours;\n",[78,341,343],{"href":342},"\u002Fblog\u002Fsource-maps-exposed-in-production","what a published map does and does not expose","\nis worth reading before you decide it does not matter.",[10,346,347,348,350,351,353,354,356,357,360],{},"Seven apps served a private file from a plain URL: a ",[176,349,178],{},", a ",[176,352,182],{},".\nFive of the nine apps graded D or F had this finding, and it is the shortest\npath to a bad day on the list, because a ",[176,355,178],{}," at a URL is every key in it in\none request. In a private window, open your published address with ",[176,358,359],{},"\u002F.env"," on\nthe end. It should fail. If it shows text, rotate every key in that file today,\nthen take the file out of what you deploy.",[25,362,364],{"id":363},"is-the-code-replits-agent-writes-safe","Is the code Replit's agent writes safe?",[10,366,367],{},"We did not measure it, and no scan from outside can. What a scan sees is the\nresult: the 1,050 open routes and the three billing keys were written by\nsomebody, an agent or a person, and published.",[10,369,370],{},"What is on the record is one event. In July 2025 Replit's agent deleted a\nproduction database in the middle of a session where it had been told to change\nnothing, and Replit's CEO acknowledged it publicly; separating development\ndatabases from production ones was part of the company's response. What follows\nfor you is the same on every builder with an agent in it: keep the agent away\nfrom the live database, and keep a copy of your data somewhere the agent cannot\nreach.",[10,372,373,374,378],{},"Where that copy lives depends on where your data is. If your Replit app keeps\nit in Supabase, that is ",[78,375,377],{"href":376},"\u002Fsupabase-backups","what Care holds",". If it is in\nReplit's own database, we cannot back it up, and the thing to read before you\nneed it is what Replit's database tool offers for a restore. Only 14 of the\n3,042 Replit apps we scanned named a Supabase project, so for most of them the\nsecond case is the one that applies.",[25,380,382],{"id":381},"the-five-minute-check-on-your-own-replit-app","The five-minute check on your own Replit app",[10,384,385],{},"Each one is a URL you open or a search you run. Use a private window so your own\nlogin does not answer for a stranger.",[36,387,388,398,401,410,413],{},[39,389,390,391,393,394,397],{},"Open your published address with ",[176,392,359],{}," on the end, then ",[176,395,396],{},"\u002F.git\u002Fconfig",".\nBoth should fail. If either shows text, rotate every key in it today.",[39,399,400],{},"Open one of your own API routes the same way, one you would not want a\nstranger reading. If it answers, that route needs a login check.",[39,402,403,404,406,407,409],{},"Search your project for ",[176,405,325],{}," and ",[176,408,328],{},". Each match is a value\nyour build tool publishes on purpose, and each one has to be a key that was\nsafe to publish.",[39,411,412],{},"Open your live app, then the Sources tab of your browser's developer tools.\nIf you can read your original files with their comments, source maps are on.",[39,414,415,416,82],{},"Or let the scan do it. It runs these four and five more from outside, takes\nabout 20 seconds, needs no account, and prints \"Couldn't check\" for anything\nit could not answer rather than a tick: ",[78,417,419],{"href":418},"\u002Fsecurity-scanner","scan your app",[25,421,423],{"id":422},"what-changes-after-you-publish-again","What changes after you publish again?",[10,425,426],{},"Anything. Publishing on Replit is one motion, so a change is live the moment you\nmake it, and there is no deploy step between you and the internet to catch a\nroute that lost its login check or a key pasted in to get past a failing build\nat midnight. A scan you ran last month describes last month's app.",[10,428,429,433],{},[78,430,432],{"href":431},"\u002Fpricing","Reeve Monitor"," is built for this shape of app: somebody who walks\npast the shop every hour and tries the doors. It re-runs all nine checks every\nhour on up to three apps, watches uptime every 60 seconds, tells you when a\nresult changes rather than waiting for you to look, and sends a monthly\nreport. It is $12 a month at list, with seven days free before it\ncharges you; the pricing page is sometimes below the figure here and never\nabove it. Monitor watches and nothing more, which for a Replit app is usually\nthe right half: Care, our backup plan, holds a copy of a Supabase database only,\nand most Replit apps keep their data somewhere else.",[25,435,437],{"id":436},"what-to-do-this-week","What to do this week",[439,440,441],"key-takeaways",{},[442,443,444,452,455,463,466],"ul",{},[39,445,446,447,406,449,451],{},"Open ",[176,448,359],{},[176,450,396],{}," on your published address in a private window. Both should fail.",[39,453,454],{},"Open your own API routes with no login. Any route that answers with private data needs a login check, and a 401 for everyone else.",[39,456,457,458,406,460,462],{},"Search the project for ",[176,459,325],{},[176,461,328],{},". Every match is published on purpose and has to be a key that was safe to publish.",[39,464,465],{},"Turn source maps off in your build configuration unless you want your original files readable from the browser.",[39,467,468],{},"Keep the agent away from the live database, and keep a copy of your data somewhere it cannot reach.",[10,470,471,472,476,477,481],{},"The plain-language walkthrough for this platform is\n",[78,473,475],{"href":474},"\u002Fis-your-replit-app-safe","is your Replit app safe",", and the\n",[78,478,480],{"href":479},"\u002Fchecklist","10-minute security checklist"," covers what is worth confirming on\nany newly launched app.",{"title":483,"searchDepth":484,"depth":484,"links":485},"",3,[486,488,489,490,491,492,493,494,495,496],{"id":27,"depth":487,"text":28},2,{"id":68,"depth":487,"text":69},{"id":240,"depth":487,"text":241},{"id":258,"depth":487,"text":259},{"id":302,"depth":487,"text":303},{"id":332,"depth":487,"text":333},{"id":363,"depth":487,"text":364},{"id":381,"depth":487,"text":382},{"id":422,"depth":487,"text":423},{"id":436,"depth":487,"text":437},"Security basics","\u002Fblog\u002Fis-replit-safe\u002Fcover-1200x630.png","The Replit logo on a white tile, an arrow to a published app drawn as a page with a server behind it, and an arrow on to three visitors.","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.",false,"md",[504,507,510,513,516],{"q":505,"a":506},"Is Replit safe to use for a real product?","As a host, nothing in the 3,042 live Replit apps we scanned pointed at the hosting: every certificate we could read was valid and no domain was close to lapsing. The findings that decided a grade were all inside the app each owner published, and they are the same shape on every builder we have measured. Whether your product is safe to run there depends on what your app hands to a visitor, which is a thing you can check in about five minutes.",{"q":508,"a":509},"Are Replit Secrets actually secret?","For the job they do, yes. The value is encrypted and kept out of your project files, so sharing or forking the project does not hand it over. What the tool cannot decide is where your app carries the value afterwards. A key read by code that runs on Replit's machine stays there. A key read by code that runs in the visitor's browser is built into what you publish, however it was stored, and a variable named VITE_ or NEXT_PUBLIC_ is exactly that.",{"q":511,"a":512},"Can people see my Replit source code?","The browser half, always, because a browser cannot draw a page it was not sent. Whether they see it as the original files you wrote or as compressed output depends on source maps, which 168 of 3,041 Replit apps we checked were publishing. Your server code stays on Replit unless a private file such as .env or .git\u002Fconfig has been given a public URL, which 7 of 3,023 apps had done.",{"q":514,"a":515},"Is a deployed Replit app secure by default?","There is no default that makes it secure and none that makes it unsafe. 2,789 of the 3,042 apps we scanned graded A. The ones that did not had a finding that followed from what was built: a route on their own server that answered without a login, a key in the downloaded code, or a private file at a public address. Nothing about the hosting produced a D or an F.",{"q":517,"a":518},"What is the most common security problem in Replit apps?","Leaving headers aside, which almost every app on every builder is missing, it is an API route that answers a stranger with data. 1,050 of the 3,037 Replit apps that check answered on had at least one. A Replit app usually carries its own server, so it has routes of its own to leave open, where a Lovable app mostly does not.","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",[521,522,523,524,525,526,527],"is replit safe","is replit secure","replit security","is replit app safe","replit app security","are replit apps secure","replit deployment security",{},true,"\u002Fblog\u002Fis-replit-safe","2026-09-15",{"title":5,"description":500},"blog\u002Fis-replit-safe",[535,536,537],"Is Replit safe? As a host, it was not where the findings were. Every one of the nine apps out of 3,042 that graded D or F got there through something inside the app itself.","The Replit-shaped finding is an API of your own: 1,050 of 3,037 apps had a route that handed data to a stranger with no login, because a Replit app usually ships with its own server.","Of 219 apps with something key-shaped in the downloaded code, three held a key that bills an account. 2,789 of the 3,042 graded A.","k_NzAzMFMKk1U4Fkn9SmqLHf9s93x1drJQhOqBDM2gs",[540,547,553,559,565,571,577,583,589,590,596,602,608,614,620,626,632,638,644,650,655,661,667,673,678,684,690,696,702,707,713,719,725,730,736,741,745,751,757,763,768,774],{"path":541,"title":542,"description":543,"published":544,"category":545,"image":546,"draft":501},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","Backups","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":548,"title":549,"description":550,"published":551,"category":497,"image":552,"draft":501},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":554,"title":555,"description":556,"published":557,"category":497,"image":558,"draft":501},"\u002Fblog\u002Fis-lovable-safe","Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":560,"title":561,"description":562,"published":563,"category":497,"image":564,"draft":501},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":566,"title":567,"description":568,"published":569,"category":497,"image":570,"draft":501},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":572,"title":573,"description":574,"published":575,"category":497,"image":576,"draft":501},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":578,"title":579,"description":580,"published":581,"category":497,"image":582,"draft":501},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":584,"title":585,"description":586,"published":587,"category":497,"image":588,"draft":501},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":530,"title":5,"description":500,"published":531,"category":497,"image":519,"draft":501},{"path":591,"title":592,"description":593,"published":594,"category":545,"image":595,"draft":501},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":597,"title":598,"description":599,"published":600,"category":545,"image":601,"draft":501},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":603,"title":604,"description":605,"published":606,"category":545,"image":607,"draft":501},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":609,"title":610,"description":611,"published":612,"category":497,"image":613,"draft":501},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":615,"title":616,"description":617,"published":618,"category":497,"image":619,"draft":501},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":621,"title":622,"description":623,"published":624,"category":497,"image":625,"draft":501},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":627,"title":628,"description":629,"published":630,"category":497,"image":631,"draft":501},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":633,"title":634,"description":635,"published":636,"category":497,"image":637,"draft":501},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":639,"title":640,"description":641,"published":642,"category":497,"image":643,"draft":501},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":645,"title":646,"description":647,"published":648,"category":497,"image":649,"draft":501},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":250,"title":651,"description":652,"published":653,"category":497,"image":654,"draft":501},"Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":656,"title":657,"description":658,"published":659,"category":497,"image":660,"draft":501},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":662,"title":663,"description":664,"published":665,"category":497,"image":666,"draft":501},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":668,"title":669,"description":670,"published":671,"category":545,"image":672,"draft":501},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":320,"title":674,"description":675,"published":676,"category":497,"image":677,"draft":501},"How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":679,"title":680,"description":681,"published":682,"category":545,"image":683,"draft":501},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":685,"title":686,"description":687,"published":688,"category":497,"image":689,"draft":501},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":691,"title":692,"description":693,"published":694,"category":497,"image":695,"draft":501},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":697,"title":698,"description":699,"published":700,"category":497,"image":701,"draft":501},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":298,"title":703,"description":704,"published":705,"category":497,"image":706,"draft":501},"Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":708,"title":709,"description":710,"published":711,"category":545,"image":712,"draft":501},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":714,"title":715,"description":716,"published":717,"category":545,"image":718,"draft":501},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":720,"title":721,"description":722,"published":723,"category":497,"image":724,"draft":501},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":309,"title":726,"description":727,"published":728,"category":497,"image":729,"draft":501},"Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":731,"title":732,"description":733,"published":734,"category":545,"image":735,"draft":501},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":290,"title":737,"description":738,"published":739,"category":497,"image":740,"draft":501},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":342,"title":742,"description":743,"published":739,"category":497,"image":744,"draft":501},"Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":497,"image":750,"draft":501},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":545,"image":756,"draft":501},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":497,"image":762,"draft":501},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":761,"category":545,"image":767,"draft":501},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":769,"title":770,"description":771,"published":772,"category":545,"image":773,"draft":501},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":775,"title":776,"description":777,"published":772,"category":497,"image":778,"draft":501},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1790150951364]