[{"data":1,"prerenderedAt":905},["ShallowReactive",2],{"blog-en-is-v0-safe":3,"blog-index-en":554},{"id":4,"title":5,"body":6,"category":508,"cover":509,"coverAlt":510,"description":511,"draft":512,"extension":513,"faq":514,"image":532,"keywords":533,"meta":543,"navigation":544,"ogTitle":5,"path":545,"published":546,"seo":547,"stem":548,"tldr":549,"updated":546,"__hash__":553},"blog_en\u002Fblog\u002Fis-v0-safe.md","v0 security: all 1,790 v0 apps we scanned got an A",{"type":7,"value":8,"toc":494},"minimark",[9,18,21,29,34,37,40,63,66,91,95,98,122,134,147,153,164,168,171,174,186,190,193,206,212,224,228,231,240,243,248,265,272,276,279,291,294,318,326,330,333,374,381,385,391,400,418,421,431,448,451,459,463,486],[10,11,12,13,17],"p",{},"You described an app to v0, watched it build one, and got back a link ending in\n",[14,15,16],"code",{},"vusercontent.net",". It works, it looks finished, and you may already have sent\nit to somebody. Before real customers type their details into it, you searched\nfor v0 security, and part of what came back was a story about attackers using\nv0 to build fake sign-in pages.",[10,19,20],{},"That story is about what other people make with the tool. This post is about\nthe app you made with it, and for that we have a measurement. Between 12 and 14\nAugust 2026 we ran the same nine external checks anyone can run free on our\nhomepage over 30,998 live apps, and 1,790 of them were v0 apps. Every one of\nthe 1,790 graded A.",[10,22,23,24,28],{},"Here is the part a league table gets wrong: ",[25,26,27],"strong",{},"that A says more about what was\nthere to check than about v0."," As a ranking it makes v0 the safest builder we\nmeasured. Read with its denominators, it describes front ends with nothing\nbehind them, and it stops describing yours the day you connect a database.",[30,31,33],"h2",{"id":32},"is-v0-safe","Is v0 safe?",[10,35,36],{},"On everything we could measure about v0 itself, yes. Its one finding belongs to\nthe domain v0 serves your app from, and nothing else turned up on any of the\n1,790, on any of the nine checks. What that cannot tell you is how your app\nbehaves once it holds data, because almost none of these held any.",[10,38,39],{},"Think of a v0 preview as a filing cabinet on a showroom floor. The drawers\nslide, the labels are on, anyone walking past can pull one open, and every\ndrawer is empty. Our checks tried every drawer and found nothing in any of\nthem, which is an accurate report on an empty cabinet.",[10,41,42,43,45,46,53,54,57,58,62],{},"How empty is in the numbers. Only 17 of the 1,790 named a Supabase project\nanywhere in the code they ship, and on all 17 our database check could not get\nan answer it could judge, so the count of readable tables on v0 is zero out of\nzero. Every one of the 1,790 was served from ",[14,44,16],{},", which Vercel\ndescribes in its\n",[47,48,52],"a",{"href":49,"rel":50},"https:\u002F\u002Fgithub.com\u002Fpublicsuffix\u002Flist\u002Fpull\u002F2121",[51],"nofollow","request to the Public Suffix List","\nas \"where we host the user-submitted content\" for v0. An app you publish goes to\na ",[14,55,56],{},"vercel.app"," address or a domain of yours, where nothing marks it as v0 from\noutside, so those are not in the count. The method and the full data are\n",[47,59,61],{"href":60},"\u002Fresearch\u002Fvibe-coded-app-security-2026","in the report",".",[10,64,65],{},"So \"is v0 safe\" is three questions:",[67,68,69,76,85],"ol",{},[70,71,72,75],"li",{},[25,73,74],{},"The tool."," What v0 checks in the code it writes, and what it refuses to\npublish. That part is Vercel's, and it is documented.",[70,77,78,81,82,84],{},[25,79,80],{},"The preview."," The cabinet on the showroom floor, at its ",[14,83,16],{},"\naddress. Every app we measured was at this stage.",[70,86,87,90],{},[25,88,89],{},"The app you fill."," The same code once it holds your customers' records,\nor runs on a domain of your own. Almost nothing we measured had got this far.",[30,92,94],{"id":93},"what-v0-security-covers-before-you-publish","What v0 security covers before you publish",[10,96,97],{},"Three things, and v0's own documentation names each of them.",[10,99,100,103,104,109,110,113,114,116,117,121],{},[25,101,102],{},"It reads the code it wrote."," v0's\n",[47,105,108],{"href":106,"rel":107},"https:\u002F\u002Fv0.app\u002Fdocs\u002Fsecurity",[51],"security page"," says all generated code\n\"undergoes security analysis before execution\", and that v0 \"analyzes\n",[14,111,112],{},"NEXT_PUBLIC_"," usage and warns users about potential security risks\".\n",[14,115,112],{}," is the prefix that tells Next.js, the framework v0 writes in, to\nput a value into the code every visitor downloads.\n",[47,118,120],{"href":119},"\u002Fblog\u002Fvite-and-next-public-env-vars","What that prefix does to a key"," is a post\nof its own.",[10,123,124,127,128,133],{},[25,125,126],{},"It refuses some deployments."," In\n",[47,129,132],{"href":130,"rel":131},"https:\u002F\u002Fvercel.com\u002Fblog\u002Fv0-vibe-coding-securely",[51],"August 2025"," Vercel wrote that\nv0 had blocked over 17,000 deployments in the previous 30 days because of\nexposed secrets alone, and over 100,000 insecure deployments since launch.\nThose are Vercel's figures about Vercel's block, which applies to deployments on\nVercel. Some of our zero may be that block's work. From outside we cannot tell\nhow much.",[10,135,136,139,140,142,143,146],{},[25,137,138],{},"The Supabase integration puts the prefix in the right place."," Connected\nthrough the Vercel Marketplace, it adds a dozen environment variables, and only\ntwo of them carry ",[14,141,112],{},": the project address and the publishable key,\nwhich are both meant to be public. ",[14,144,145],{},"SUPABASE_SECRET_KEY"," and the database\npassword are left without it, on the server.",[148,149],"diagram",{"alt":150,"caption":151,"src":152},"Twelve rows of settings inside a box. Ten have masked values and stay in the box. Two carry the tag NEXT_PUBLIC_ and readable values, and arrows carry those two across a dashed wall to a visitor outside.","The Supabase integration adds twelve variables. Two of them reach every visitor, and both are meant to: the project address and the publishable key.","\u002Fblog\u002Fis-v0-safe\u002Ftwo-of-twelve-1600x720.png",[154,155,157],"callout",{"type":156},"note",[10,158,159,160,62],{},"Free, no account, about 20 seconds: the scan on our homepage runs all nine of\nthese checks against your live app and prints \"Couldn't check\" for anything it\ncould not answer rather than a tick. ",[47,161,163],{"href":162},"\u002Fsecurity-scanner","Scan your app",[30,165,167],{"id":166},"why-a-v0-preview-is-missing-security-headers","Why a v0 preview is missing security headers",[10,169,170],{},"Because v0's preview domain sets them, every app on it gets the same answer,\nand you cannot change that from inside a preview.",[10,172,173],{},"Security headers are instructions a site sends with every page: always use\nHTTPS, do not let another site show this page inside its own, do not guess what\nkind of file this is. Whoever serves the page sends them. The previews we opened\non 3 October 2026 sent one of the five our check looks for, the one that forces\nHTTPS, and none of the other four. That is the finding on all 1,790 v0 apps, and\nit is the only one.",[10,175,176,177,180,181,185],{},"The showroom sets its own doors and alarms, and you cannot rewire them for one\ncabinet on its floor. Once you publish, the cabinet is in your office, and the\nheaders are a setting in ",[14,178,179],{},"vercel.json"," or in your Next.js config.\n",[47,182,184],{"href":183},"\u002Fblog\u002Fmissing-security-headers","What each header does, and the two that cost nothing to add",",\nis a separate article.",[30,187,189],{"id":188},"is-a-vusercontentnet-preview-public","Is a vusercontent.net preview public?",[10,191,192],{},"Treat it as public. Anyone who has the address can open it, and addresses\ntravel.",[10,194,195,196,201,202,205],{},"Every one of the 1,790 opened for us with no login, and we did not have to guess\nat any of them: their addresses came out of a public web archive that had\nalready saved a copy of each. v0's ",[47,197,200],{"href":198,"rel":199},"https:\u002F\u002Fv0.app\u002Fdocs\u002Fsharing",[51],"sharing settings","\ndecide who can see your ",[25,203,204],{},"chat",": private by default, then your team, anyone with\nthe link, or anyone on the web. The documentation does not say that those\nsettings reach the preview.",[10,207,208,209,211],{},"So a preview is the cabinet on the showroom floor. That is fine for showing\nsomebody the design and wrong for anybody's real records. Vercel did put\n",[14,210,16],{}," on the Public Suffix List in September 2024, which makes\nbrowsers treat every preview as a separate site, so one preview cannot set\ncookies for all the others. That keeps previews apart from each other, and it\ndoes nothing to keep yours private.",[10,213,214,215,217,218,223],{},"If you are here because somebody sent you a ",[14,216,16],{}," link: the domain\nis Vercel's, and the page on it was made by whoever prompted it. On 1 July 2025\n",[47,219,222],{"href":220,"rel":221},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fokta-observes-v0-ai-tool-used-to-build-phishing-sites\u002F",[51],"Okta reported","\nattackers using v0 to build copies of real sign-in pages, and Vercel restricted\naccess to the ones it found. Do not type a password into a sign-in form at an\naddress like that unless you were expecting it.",[30,225,227],{"id":226},"what-changes-when-you-connect-supabase-to-v0","What changes when you connect Supabase to v0",[10,229,230],{},"You start filling the drawers, and the checks that came back empty on v0 start\nhaving something to check.",[10,232,233,234,239],{},"v0 adds Supabase in a click and, in\n",[47,235,238],{"href":236,"rel":237},"https:\u002F\u002Fv0.app\u002Fdocs\u002Fdatabases",[51],"its own documentation's words",", \"can generate\nand execute SQL. This lets you create, update, and drop tables.\" Each table is a\ndrawer, and row-level security is the lock on it: a per-table setting that\ndecides which rows the publishable key in your page may read. That key is meant\nto be public, so the lock is the only thing deciding what a stranger gets back.",[10,241,242],{},"Supabase fits that lock by default on tables created in its Table Editor, and\nleaves it off on tables created by running SQL, which is how v0 makes them.",[148,244],{"alt":245,"caption":246,"src":247},"Two lanes. In the upper one, a grid icon makes three tables, each with a closed lock beside it. In the lower one, a terminal icon with the v0 logo beside it makes three tables, each with its lock hanging open and drawn in red.","A table made in Supabase's Table Editor arrives locked. A table made by running SQL, which is how v0 makes them, arrives with the lock open.","\u002Fblog\u002Fis-v0-safe\u002Ftwo-ways-to-make-a-table-1600x620.png",[10,249,250,251,255,256,259,260,264],{},"That is where the serious findings on every other builder landed. Of the 3,553\nLovable apps whose database we could ask, 2,017 handed rows to a request with no\nlogin, and ",[47,252,254],{"href":253},"\u002Fblog\u002Fis-lovable-safe","the Lovable numbers"," are what a builder's\nresults look like once there are records in the drawers. A lock that any key\nopens is no lock either: a policy that reads ",[14,257,258],{},"using (true)"," lets everybody\nthrough while the dashboard reports the table as protected.\n",[47,261,263],{"href":262},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","RLS is on and your table is still public","\nis that whole story.",[10,266,267,268,62],{},"If your data sits behind routes your own server code answers instead, the same\nquestion gets asked of those routes:\n",[47,269,271],{"href":270},"\u002Fblog\u002Fopen-api-endpoint-exposed","what an open API endpoint means",[30,273,275],{"id":274},"what-changes-when-you-publish-or-deploy-it-yourself","What changes when you publish or deploy it yourself",[10,277,278],{},"The cabinet leaves the showroom for your office, and the decisions v0's domain\nwas making become yours.",[10,280,281,282,287,288,290],{},"Publishing from v0 creates a Vercel project and asks three things, according to\n",[47,283,286],{"href":284,"rel":285},"https:\u002F\u002Fv0.app\u002Fdocs\u002Fdeployments",[51],"v0's deployment docs",": the project name, who\ncan access the deployed app, and the domain, either a ",[14,289,56],{}," address or\none of your own. Slow down on the second. Which options you see depends on your\nplan, and keeping the app to your team or behind a password until you have\nchecked it keeps strangers out while you look.",[10,292,293],{},"Three things move to you when you publish:",[295,296,297,303,312],"ul",{},[70,298,299,302],{},[25,300,301],{},"The headers."," The office's doors and alarms are yours to set now.",[70,304,305,308,309,311],{},[25,306,307],{},"The environment variables."," They live in your project's settings, and that\nlist is where a key either gets the ",[14,310,112],{}," prefix or does not.",[70,313,314,317],{},[25,315,316],{},"The check on your deploy, if you leave Vercel."," Vercel describes its block\nas stopping deployments on Vercel, so code you download and host somewhere\nelse goes out without that check.",[10,319,320,321,325],{},"Either way you have left the sample we measured. A v0 app on its own domain with\na database behind it has more in common with the\n",[47,322,324],{"href":323},"\u002Fblog\u002Fis-bolt-safe","Bolt apps we measured"," than with these 1,790 previews.",[30,327,329],{"id":328},"how-to-check-your-own-v0-app","How to check your own v0 app",[10,331,332],{},"Five things, and the first three only start to matter once you have connected a\ndatabase or published. Use a private window, so your own login does not answer\nfor a stranger.",[67,334,335,347,353,359,365],{},[70,336,337,340,341,343,344,346],{},[25,338,339],{},"Read your environment variables."," In v0 they are under the project menu,\nSettings, Environment Variables. Anything starting ",[14,342,112],{}," is in the\ncode every visitor downloads. A project address and a publishable key belong\nthere. A key that bills you, ",[14,345,145],{}," and anything holding a\npassword never do. If one ever carried the prefix, rotate it with the\nprovider first, because the old value keeps working until you do.",[70,348,349,352],{},[25,350,351],{},"Read the lock on every table."," In Supabase, open Authentication → Policies\nand go down the list. A table with row-level security disabled is readable\nby anyone who has your project address, and that address is in your page. A\npolicy that permits everybody counts as disabled.",[70,354,355,358],{},[25,356,357],{},"Choose who can see it when you publish."," Team only, or a password, until\nthe first two are done.",[70,360,361,364],{},[25,362,363],{},"Set your headers once the domain is yours."," Two of them are one line each.",[70,366,367,370,371,62],{},[25,368,369],{},"Then look from outside."," Our scan runs all nine checks against the\npublished address the way a stranger would, takes about 20 seconds and needs\nno account: ",[47,372,373],{"href":162},"scan your app free",[10,375,376,377,62],{},"An outside scan cannot see the code v0 wrote, the chat you wrote it in, or a\ntable your pages never mention. v0's checks see the code from the inside and\ncannot see what a stranger gets from the address. Run v0's while you build, look\nfrom outside after you publish, and if the two ever disagree about whether a\ntable is readable, go with the outside answer, because that is the one a\nstranger gets. The plain-language version for this platform is\n",[47,378,380],{"href":379},"\u002Fis-your-v0-app-safe","is your v0 app safe",[30,382,384],{"id":383},"keeping-it-that-way-after-you-publish","Keeping it that way after you publish",[10,386,387,390],{},[25,388,389],{},"An A on a preview describes a preview."," The day you connect a database or\npublish to your own domain, your grade can change, and nothing on your screen\ntells you it has.",[10,392,393],{},[25,394,395,399],{},[47,396,398],{"href":397},"\u002Fpricing","Reeve Monitor"," runs the nine checks again for you:",[295,401,402,405,408,415],{},[70,403,404],{},"all nine checks every hour, on up to three apps",[70,406,407],{},"whether the app is up, every 60 seconds",[70,409,410,411,414],{},"a message when a result ",[25,412,413],{},"changes",", so a new table or key does not wait for you to look",[70,416,417],{},"a monthly report of what it saw",[10,419,420],{},"Monitor is $12 a month at list, with seven days free before it charges you. The\npricing page is sometimes below the figure here and never above it.",[10,422,423],{},[25,424,425,426,430],{},"If your v0 app keeps its data in Supabase, ",[47,427,429],{"href":428},"\u002Fsupabase-backups","Reeve Care","\nkeeps a copy of your Supabase database.",[295,432,433,436,439,442,445],{},[70,434,435],{},"an encrypted copy every night, kept where your project cannot reach it",[70,437,438],{},"each copy verified before it counts, by counting the rows in every table",[70,440,441],{},"a one-click restore when you need one",[70,443,444],{},"your uploaded files as well, once you connect a Storage credential",[70,446,447],{},"everything Monitor does",[10,449,450],{},"Care is $49 a month at list for one app, with the same seven days free.",[10,452,453,454,458],{},"v0's documentation says it can drop tables as well as create them, and none of\nthe nine checks above would bring back the rows in one.\n",[47,455,457],{"href":456},"\u002Fblog\u002Fai-agent-deleted-my-database","The day an AI agent deleted a production database","\nis what that looks like from the inside.",[30,460,462],{"id":461},"what-to-do-this-week","What to do this week",[464,465,466],"key-takeaways",{},[295,467,468,471,477,480,483],{},[70,469,470],{},"If your v0 app is still a preview, treat its address as public and keep real people's details out of it.",[70,472,473,474,476],{},"Before you connect a database, decide where each key lives: ",[14,475,112],{}," for the project address and the publishable key, and nowhere near the browser for anything else.",[70,478,479],{},"After you connect Supabase, read the policy on every table v0 created, and treat one that permits everybody as switched off.",[70,481,482],{},"Publish to your team or behind a password until those are done, then check the published address from outside.",[70,484,485],{},"Keep a copy of your database somewhere v0 and your project cannot reach, and check that the copy restores.",[10,487,488,489,493],{},"Start with the environment variables, because they decide what every visitor\ndownloads. If you are still choosing a builder,\n",[47,490,492],{"href":491},"\u002Fblog\u002Fsafest-ai-app-builder","which AI app builder is safest"," puts all five side\nby side.",{"title":495,"searchDepth":496,"depth":496,"links":497},"",3,[498,500,501,502,503,504,505,506,507],{"id":32,"depth":499,"text":33},2,{"id":93,"depth":499,"text":94},{"id":166,"depth":499,"text":167},{"id":188,"depth":499,"text":189},{"id":226,"depth":499,"text":227},{"id":274,"depth":499,"text":275},{"id":328,"depth":499,"text":329},{"id":383,"depth":499,"text":384},{"id":461,"depth":499,"text":462},"Security basics","\u002Fblog\u002Fis-v0-safe\u002Fcover-1200x630.png","A filing cabinet with the v0 logo and one empty drawer pulled open, beside a cabinet with every drawer locked.","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.",false,"md",[515,517,520,523,526,529],{"q":33,"a":516},"On what we could measure, v0 came out cleaner than any other builder we scanned. All 1,790 live v0 apps graded A, and the only finding they shared was a browser header setting on the domain v0 serves previews from. Only 17 of them named a database, though, and none of those 17 gave our database check an answer, so the A mostly describes front ends with nothing behind them. Once you connect Supabase or publish to your own domain, the checks that decide a serious grade start applying to you.",{"q":518,"a":519},"Are v0 apps secure by default?","The parts v0 controls are in good shape. Its documentation says generated code goes through a security analysis before it runs and that it warns about risky use of the NEXT_PUBLIC_ prefix, and in August 2025 Vercel said v0 had blocked over 17,000 deployments in 30 days for exposed secrets. What no default decides is the lock on your database tables. Supabase does not switch on row-level security for tables created by running SQL, which is how v0 creates them, so read the policy on each table after you connect a database.",{"q":521,"a":522},"Is a vusercontent.net preview URL public?","Treat it as public. Every one of the 1,790 v0 previews we scanned opened with no login, and we found their addresses in a public web archive. The sharing settings in v0 control who can see your chat, and its documentation does not say they reach the preview. Keep real people out of a preview, and when you publish, choose team-only or password visibility until the app is ready for strangers.",{"q":524,"a":525},"Is vusercontent.net safe?","The domain is real and belongs to Vercel, which uses it to host what people generate with v0. The page at any one address was made by whoever prompted it, though, and in July 2025 Okta reported attackers using v0 to build copies of sign-in pages. Vercel restricted access to the ones it found. If a link you were not expecting opens a sign-in form at a vusercontent.net address, do not type a password into it.",{"q":527,"a":528},"What changes when I connect Supabase to v0?","There is now data behind your front end, so the checks that came back empty on v0 apps start having something to check. v0 can run SQL to create tables, and Supabase does not switch on row-level security for tables made that way. Your publishable key is meant to be in the page, so the policy on each table is the only thing deciding what a stranger can read. Of the 3,553 Lovable apps whose database we could ask, 2,017 handed rows to a request with no login.",{"q":530,"a":531},"What changes when I deploy v0 code myself?","Three things become yours. The security headers that the v0 preview domain was choosing become a setting in vercel.json or your Next.js config. Your environment variables, and which of them carry the NEXT_PUBLIC_ prefix, live in your own project. And code you download and host somewhere other than Vercel no longer passes through the deployment check Vercel describes for v0. Look at the published address from outside once it is live.","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",[534,535,536,537,538,539,540,541,542],"v0 security","is v0 safe","v0.dev security","is v0 safe to use","vercel v0 security","are v0 apps secure","v0 app security","v0 deployment security","vusercontent.net safe",{},true,"\u002Fblog\u002Fis-v0-safe","2026-10-03",{"title":5,"description":511},"blog\u002Fis-v0-safe",[550,551,552],"v0 security came out cleaner than any other builder we measured: all 1,790 live v0 apps we scanned graded A, and the one finding they shared is a header setting on the domain v0 serves them from.","That is mostly a fact about what those apps are. Only 17 of the 1,790 named a database, and none of those 17 gave our database check an answer it could judge.","Connect Supabase, or publish to a domain of your own, and the checks that came back empty start having something to check.","YnFM3CutCqoVNWT9a7Dk6qACtFg_L0rxG5FeznIj4og",[555,561,567,573,579,585,591,597,603,604,609,615,621,627,634,640,646,651,656,662,668,674,679,685,691,696,702,708,714,720,726,732,737,743,749,755,761,767,773,778,784,790,796,802,808,814,820,826,832,838,844,850,856,861,867,872,878,884,889,894,900],{"path":556,"title":557,"description":558,"published":559,"category":508,"image":560,"draft":512},"\u002Fblog\u002Fstorage-upload-violates-row-level-security","\"Row-level security policy for table objects\" on upload","\"New row violates row-level security policy for table objects\" means your upload has no insert rule. Making the bucket public does not add one.","2026-10-11","\u002Fblog\u002Fstorage-upload-violates-row-level-security\u002Fcard-800x500.png",{"path":562,"title":563,"description":564,"published":565,"category":508,"image":566,"draft":512},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":568,"title":569,"description":570,"published":571,"category":508,"image":572,"draft":512},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":574,"title":575,"description":576,"published":577,"category":508,"image":578,"draft":512},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":580,"title":581,"description":582,"published":583,"category":508,"image":584,"draft":512},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":586,"title":587,"description":588,"published":589,"category":508,"image":590,"draft":512},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":592,"title":593,"description":594,"published":595,"category":508,"image":596,"draft":512},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":598,"title":599,"description":600,"published":601,"category":508,"image":602,"draft":512},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":545,"title":5,"description":511,"published":546,"category":508,"image":532,"draft":512},{"path":323,"title":605,"description":606,"published":607,"category":508,"image":608,"draft":512},"Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":610,"title":611,"description":612,"published":613,"category":508,"image":614,"draft":512},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":616,"title":617,"description":618,"published":619,"category":508,"image":620,"draft":512},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":622,"title":623,"description":624,"published":625,"category":508,"image":626,"draft":512},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":628,"title":629,"description":630,"published":631,"category":632,"image":633,"draft":512},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":635,"title":636,"description":637,"published":638,"category":632,"image":639,"draft":512},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":632,"image":645,"draft":512},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":647,"title":648,"description":649,"published":644,"category":508,"image":650,"draft":512},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":270,"title":652,"description":653,"published":654,"category":508,"image":655,"draft":512},"Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":657,"title":658,"description":659,"published":660,"category":508,"image":661,"draft":512},"\u002Fblog\u002Flovable-security-scan","Lovable security scan: the one thing it cannot prove","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.","2026-09-24","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",{"path":663,"title":664,"description":665,"published":666,"category":632,"image":667,"draft":512},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":669,"title":670,"description":671,"published":672,"category":508,"image":673,"draft":512},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":253,"title":675,"description":676,"published":677,"category":508,"image":678,"draft":512},"Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":680,"title":681,"description":682,"published":683,"category":508,"image":684,"draft":512},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":686,"title":687,"description":688,"published":689,"category":508,"image":690,"draft":512},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":119,"title":692,"description":693,"published":694,"category":508,"image":695,"draft":512},"Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":697,"title":698,"description":699,"published":700,"category":508,"image":701,"draft":512},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":703,"title":704,"description":705,"published":706,"category":508,"image":707,"draft":512},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":709,"title":710,"description":711,"published":712,"category":508,"image":713,"draft":512},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":715,"title":716,"description":717,"published":718,"category":632,"image":719,"draft":512},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":721,"title":722,"description":723,"published":724,"category":632,"image":725,"draft":512},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":727,"title":728,"description":729,"published":730,"category":632,"image":731,"draft":512},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":491,"title":733,"description":734,"published":735,"category":508,"image":736,"draft":512},"Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":738,"title":739,"description":740,"published":741,"category":508,"image":742,"draft":512},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":744,"title":745,"description":746,"published":747,"category":508,"image":748,"draft":512},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":750,"title":751,"description":752,"published":753,"category":508,"image":754,"draft":512},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":756,"title":757,"description":758,"published":759,"category":508,"image":760,"draft":512},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":762,"title":763,"description":764,"published":765,"category":508,"image":766,"draft":512},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":768,"title":769,"description":770,"published":771,"category":508,"image":772,"draft":512},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":183,"title":774,"description":775,"published":776,"category":508,"image":777,"draft":512},"Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":779,"title":780,"description":781,"published":782,"category":508,"image":783,"draft":512},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":785,"title":786,"description":787,"published":788,"category":508,"image":789,"draft":512},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":791,"title":792,"description":793,"published":794,"category":632,"image":795,"draft":512},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":797,"title":798,"description":799,"published":800,"category":508,"image":801,"draft":512},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":803,"title":804,"description":805,"published":806,"category":632,"image":807,"draft":512},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":809,"title":810,"description":811,"published":812,"category":508,"image":813,"draft":512},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":815,"title":816,"description":817,"published":818,"category":508,"image":819,"draft":512},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":821,"title":822,"description":823,"published":824,"category":508,"image":825,"draft":512},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":827,"title":828,"description":829,"published":830,"category":508,"image":831,"draft":512},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":833,"title":834,"description":835,"published":836,"category":632,"image":837,"draft":512},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":839,"title":840,"description":841,"published":842,"category":632,"image":843,"draft":512},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":845,"title":846,"description":847,"published":848,"category":508,"image":849,"draft":512},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":851,"title":852,"description":853,"published":854,"category":508,"image":855,"draft":512},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":456,"title":857,"description":858,"published":859,"category":632,"image":860,"draft":512},"An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":862,"title":863,"description":864,"published":865,"category":508,"image":866,"draft":512},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":868,"title":869,"description":870,"published":865,"category":508,"image":871,"draft":512},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":873,"title":874,"description":875,"published":876,"category":508,"image":877,"draft":512},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":879,"title":880,"description":881,"published":882,"category":632,"image":883,"draft":512},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":262,"title":885,"description":886,"published":887,"category":508,"image":888,"draft":512},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":890,"title":891,"description":892,"published":887,"category":632,"image":893,"draft":512},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":895,"title":896,"description":897,"published":898,"category":632,"image":899,"draft":512},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":901,"title":902,"description":903,"published":898,"category":508,"image":904,"draft":512},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791705957970]