[{"data":1,"prerenderedAt":877},["ShallowReactive",2],{"blog-en-lovable-security-scan":3,"blog-index-en":530},{"id":4,"title":5,"body":6,"category":486,"cover":487,"coverAlt":488,"description":489,"draft":490,"extension":491,"faq":492,"image":507,"keywords":508,"meta":518,"navigation":519,"ogTitle":520,"path":521,"published":522,"seo":523,"stem":524,"tldr":525,"updated":522,"__hash__":529},"blog_en\u002Fblog\u002Flovable-security-scan.md","Lovable security scan: the one thing it cannot prove",{"type":7,"value":8,"toc":472},"minimark",[9,13,21,26,29,40,55,61,65,68,83,98,101,105,108,111,114,126,130,133,136,142,149,153,156,159,177,184,189,200,203,211,215,218,237,240,342,349,353,356,384,387,392,403,407,410,413,420,432,436,464],[10,11,12],"p",{},"You click Publish on your Lovable app and a scan runs before it goes out. A few\nseconds later it comes back clean, or it comes back with a list, and either way\nyou are holding a result you have no way to judge. Is that everything? Is it\nenough to put real people on this?",[10,14,15,16,20],{},"Here is the part worth knowing before you decide: ",[17,18,19],"strong",{},"the Lovable security scan\nand a scan of your published app are reading two different objects."," One reads\nthe locks and the wiring. The other walks up and pulls the handle. Both are\nworth doing, and only the second one does what every visitor to your app does\nall day.",[22,23,25],"h2",{"id":24},"does-lovable-scan-my-app-for-security-problems","Does Lovable scan my app for security problems?",[10,27,28],{},"Yes, and there are two of them. Both are free.",[10,30,31,32,35,36,39],{},"The ",[17,33,34],{},"Quick scan"," runs by itself every time you publish and finishes in\nseconds. The ",[17,37,38],{},"Deep scan"," reads all of your application code and you start it\nyourself. Both of them read your project from the inside: your database\nsettings, the access rules on your tables, your dependency tree, your code.",[10,41,42,43,50,51,54],{},"Everything below was read off\n",[44,45,49],"a",{"href":46,"rel":47},"https:\u002F\u002Fdocs.lovable.dev\u002Ffeatures\u002Fsecurity",[48],"nofollow","Lovable's own security documentation","\non ",[17,52,53],{},"24 September 2026",". This feature has changed more than once in a year, so\ncheck the date on any article describing it, including this one.",[56,57],"diagram",{"alt":58,"caption":59,"src":60},"Two panels. In the left one, a box holds a database, a document, a code mark and a stack of lines in a row, with a large magnifying glass standing inside the box below them. In the right one, a published page sends an arrow to a database that sits outside it, three visitors wait on the far side, and a magnifying glass of the same size stands out in the open among them.","Two scans, two places to stand. The one inside the box can open anything in the project. The one in the street can only ask the app what it hands over, which is the same thing the three people beside it are doing.","\u002Fblog\u002Flovable-security-scan\u002Ftwo-vantage-points-1600x700.png",[22,62,64],{"id":63},"what-the-lovable-security-scan-checks","What the Lovable security scan checks",[10,66,67],{},"Three areas, in a fixed set of checks, in seconds, on every publish.",[10,69,70,71,74,75,78,79,82],{},"Lovable's documentation lists them as a ",[17,72,73],{},"database review",", a ",[17,76,77],{},"dependency\naudit"," and an ",[17,80,81],{},"MCP server check",". The database review is the one that matters\nmost to this article, and their wording for it is worth reading closely: it\ncovers \"tables without per-record access control (row-level security), access\nrules that let everyone through, and leaked-password protection turned off\".\nThe dependency audit looks for known vulnerabilities in your npm packages. The\nMCP check looks for an MCP server your app exposes without authentication.",[10,84,85,86,89,90,93,94,97],{},"Findings come back grouped by area and labelled ",[17,87,88],{},"Critical",", ",[17,91,92],{},"Warning"," or\n",[17,95,96],{},"Info",". The scan fires automatically from the publish dialog, and you can also\nstart it from the project Security view.",[10,99,100],{},"Some write-ups call this the Basic scan. The control in the Security view today\nreads Run quick scan, so if an article and your screen disagree on the name,\nyour screen is the current one.",[22,102,104],{"id":103},"what-the-deep-scan-adds","What the Deep scan adds",[10,106,107],{},"It reads all of your application code, and it does not start itself.",[10,109,110],{},"The Deep scan includes everything in the Quick scan and then looks at your own\nlogic, permissions and data. Lovable lists seven areas: access control and\nauthorization, unauthenticated and abusable endpoints, unsafe input and\ninjection, leaked secrets and credentials, payments and billing, authentication\nand account security, and exposed personal and sensitive data. It is free too.",[10,112,113],{},"The sentence in the docs to actually act on is this one: the Deep scan does not\nrun automatically as you work. It runs when you run it. A project that has never\nhad one has never had its code read, no matter how many times it has been\npublished, and the publish dialog will not tell you that. Enterprise workspaces\ncan schedule Deep scans across selected projects from the workspace Security\ncenter, which is the one arrangement where it happens without somebody\nremembering.",[10,115,116,117,120,121,125],{},"Lovable can also attempt fixes, either while you build or through ",[17,118,119],{},"Try to fix\nall"," in the Security view. Read what a fix changed before you accept it. The\nrepair that makes a row-level-security error go away is very often a policy that\npermits everybody, and that policy\n",[44,122,124],{"href":123},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","satisfies the check while leaving the table open",".",[22,127,129],{"id":128},"the-2025-complaint-and-what-changed","The 2025 complaint, and what changed",[10,131,132],{},"The first version of this check told you a policy existed. It did not tell you\nthe policy worked, and the researcher who found the original problem said so at\nthe time.",[10,134,135],{},"In May 2025 Matt Palmer published CVE-2025-48757, covering Lovable apps whose\nSupabase tables had row-level security missing or written too permissively.\nLovable's response was the pre-publish check. Palmer's own write-up described\nits limit in one parenthesis:",[137,138,139],"blockquote",{},[10,140,141],{},"Lovable's Publish feature will help ensure that RLS policies are enabled in\nall tables and notify if they aren't (but doesn't necessarily indicate if they\nare sufficient).",[10,143,144,145,125],{},"That gap has an answer in the current documentation, which names \"access rules\nthat let everyone through\" as something the database review flags. Nothing in\nthis article tests that claim. If you want it tested, add a throwaway table with\na policy that permits everybody and see whether the scan names it. The longer\nversion of the CVE is in ",[44,146,148],{"href":147},"\u002Fblog\u002Fis-lovable-safe","is Lovable safe",[22,150,152],{"id":151},"what-a-scan-from-the-inside-cannot-prove","What a scan from the inside cannot prove",[10,154,155],{},"Whether your live app hands rows to somebody who is not logged in.",[10,157,158],{},"A lock can be fitted, listed and correct on the drawing, and the door still\nopens. A policy is a statement about what should happen; the thing that settles\nwhat does happen is a request. Three ways a rule reads as present and the table\nstill answers:",[160,161,162,171,174],"ul",{},[163,164,165,166,170],"li",{},"The policy permits everybody. Written as ",[167,168,169],"code",{},"using (true)",", it is a valid policy,\nit satisfies the requirement that one exist, and it returns every row to every\ncaller.",[163,172,173],{},"The policy covers reads and nothing else. Selecting is checked, inserting and\nupdating and deleting were never written, so anyone can write to a table\nnobody can fully read.",[163,175,176],{},"The condition matches more people than it was meant for. It was supposed to\nname one customer and it names every signed-in visitor, or every visitor.",[10,178,179,180,183],{},"Now the part that decides how you should read a green result. ",[17,181,182],{},"From outside,\nthose three and a table with no protection at all give the same answer",", which\nis rows. Your users cannot tell them apart. Neither can anybody else who opens\nyour app.",[56,185],{"alt":186,"caption":187,"src":188},"One chain left to right: a person, an arrow to a published page, an arrow to a database, and a red arrow to a panel of three rows of data. No key and no padlock appears anywhere along it. Below the page, drawn faint and joined to nothing, sits a project box holding a database, a document, a code mark and a stack of lines.","The request that settles it, and the rows it came back with. The project sits under the page and touches the line nowhere, which is why nothing inside it can answer for what happened here.","\u002Fblog\u002Flovable-security-scan\u002Fthe-request-that-decides-1600x560.png",[10,190,191,192,195,196,125],{},"Between 12 and 14 August 2026 we ran the same nine external checks over 30,998\nlive apps, and 18,554 of them were published on Lovable. Of the Lovable apps\nthat named a Supabase project, 3,553 answered us clearly enough to judge, and\n",[17,193,194],{},"2,017 of those handed back rows to a request carrying no login at all",". The\nmethod and every denominator are\n",[44,197,199],{"href":198},"\u002Fresearch\u002Fvibe-coded-app-security-2026","in the report",[10,201,202],{},"One honesty rail on that number. We stood on the pavement, and we have no view\ninside any of those projects. We can report what 2,017 published apps answered.\nWe cannot report how many of them had run a scan, or what it told them.",[10,204,205,206,210],{},"Your own app answers the same question in about 20 seconds, and you do not have\nto take our word for which side of the 2,017 it falls on:\n",[44,207,209],{"href":208},"\u002Fsecurity-scanner","scan your app",". It asks each table for a count of the rows a\ncaller with no login would be given, reads the number, and stops there without\nfetching a row.",[22,212,214],{"id":213},"what-an-outside-scan-cannot-see","What an outside scan cannot see",[10,216,217],{},"Pulling the handle tells you nothing about a room with no door onto the street,\nand there are four of those.",[10,219,220,221,224,225,228,229,232,233,236],{},"Your ",[17,222,223],{},"npm dependency tree"," is not in the page a browser downloads. Your\n",[17,226,227],{},"server-side code",", including edge functions and whether a route checks who is\ncalling, runs somewhere we never reach. A ",[17,230,231],{},"table your front end never names","\nis invisible to us, because we find table names in the code your app ships plus\na short list of common ones, so a table nothing in the browser touches and\nnobody would guess does not get asked. And an ",[17,234,235],{},"MCP server"," is not something a\npage request finds.",[10,238,239],{},"Lovable's two scans between them read all four. Ours prints \"Couldn't check\"\nwhen it could not answer a question, rather than a tick.",[241,242,243,259],"table",{},[244,245,246],"thead",{},[247,248,249,253,256],"tr",{},[250,251,252],"th",{},"What it is",[250,254,255],{},"Lovable's scan, inside",[250,257,258],{},"An outside scan",[260,261,262,274,285,296,305,314,323,332],"tbody",{},[247,263,264,268,271],{},[265,266,267],"td",{},"Row-level security switched off on a table",[265,269,270],{},"Yes",[265,272,273],{},"Only by its effect",[247,275,276,279,282],{},[265,277,278],{},"A policy that lets everyone through",[265,280,281],{},"Yes, per its docs",[265,283,284],{},"Yes, by the rows it gets",[247,286,287,290,293],{},[265,288,289],{},"What your published app hands a stranger",[265,291,292],{},"No",[265,294,295],{},"Yes, this is the whole job",[247,297,298,301,303],{},[265,299,300],{},"Your npm dependencies",[265,302,270],{},[265,304,292],{},[247,306,307,310,312],{},[265,308,309],{},"Server-side code and edge function authentication",[265,311,270],{},[265,313,292],{},[247,315,316,319,321],{},[265,317,318],{},"A table your front end never names",[265,320,270],{},[265,322,292],{},[247,324,325,328,330],{},[265,326,327],{},"Which key ended up in the code visitors download",[265,329,270],{},[265,331,270],{},[247,333,334,337,340],{},[265,335,336],{},"Your certificate date, domain date and page headers",[265,338,339],{},"Not in its list",[265,341,270],{},[10,343,344,345,125],{},"The row about what your published app hands a stranger is the reason to run\nboth, and it is the row our scan was built around. The general version of where\nan outside view stops is\n",[44,346,348],{"href":347},"\u002Fblog\u002Fvibe-coding-security-scanner","what a URL scan misses",[22,350,352],{"id":351},"run-both-in-this-order","Run both, in this order",[10,354,355],{},"The inside scan before you publish, the outside one after, because that is the\norder the two things happen in.",[357,358,359,365,371,376],"ol",{},[163,360,361,364],{},[17,362,363],{},"Let the Quick scan run at publish, then read it."," It is a few seconds and\nit is already happening. Clicking past the dialog is the commonest way a\nCritical finding reaches production.",[163,366,367,370],{},[17,368,369],{},"Run a Deep scan before anything real goes live",", and again after you add\nsign-in, payments, or any table that holds people. It will not run itself.",[163,372,373],{},[17,374,375],{},"Publish.",[163,377,378,381,382,125],{},[17,379,380],{},"Scan the published address from outside."," Ours reads your live app the way\na visitor does, takes about 20 seconds, needs no account, and names the\nchecks it could not finish: ",[44,383,209],{"href":208},[10,385,386],{},"There is a gap in that sequence, and it is the one worth planning around. The\nQuick scan runs when you publish. Most of what opens a table does not go through\npublish at all: you change a setting in the Supabase dashboard, you accept a\npolicy an assistant wrote in a chat window at midnight, you add a table this\nmorning and the screen that reads it ships on Thursday. None of that is a\npublish, so none of it starts a scan, and the Deep scan was never going to run\non its own anyway.",[56,388],{"alt":389,"caption":390,"src":391},"A horizontal timeline with three teal dots, each joined upward to a magnifying glass in a circle. Between the second and third dots sits an amber dot joined downward to a settings toggle, and the timeline turns amber from that point to the end, running straight under the third scan.","Every publish starts a scan. A setting changed in the Supabase dashboard is not a publish, and the amber carries on past the next one, because that scan reads the project rather than the table.","\u002Fblog\u002Flovable-security-scan\u002Fwhen-each-one-runs-1600x600.png",[10,393,394,398,399,402],{},[44,395,397],{"href":396},"\u002Fpricing","Reeve Monitor"," runs the outside half on the days you do not think to.\nIt re-runs all nine checks every hour on up to three apps, watches whether your\napp is answering at all, tells you when a result ",[17,400,401],{},"changes"," instead of waiting\nfor you to come and look, and sends a report at the end of each month.",[22,404,406],{"id":405},"reading-a-green-scan","Reading a green scan",[10,408,409],{},"A clean result means every question that scan could ask came back clean on the\nday you ran it. That is worth having and it is not a verdict on your app.",[10,411,412],{},"Lovable puts the same caveat in its own docs: the tools help identify common\nsecurity issues and cannot guarantee complete security. Ours carries it too,\nbecause an automated external check is not an audit and an empty findings list\nis not a guarantee.",[10,414,415,416,419],{},"The one rule to keep for when the two disagree: ",[17,417,418],{},"if the inside scan is clean\nand an outside scan says a table answered a request with no login, act on the\noutside answer."," It is the answer your users get, and it is the answer anybody\nelse gets as well. Go and read the policy on that table.",[10,421,422,423,427,428,125],{},"If your app is on Supabase, the plain-language walkthrough for this platform is\n",[44,424,426],{"href":425},"\u002Fis-your-lovable-app-safe","is your Lovable app safe",", and the checks written\nout as commands you can run yourself are in\n",[44,429,431],{"href":430},"\u002Fblog\u002Fsupabase-security-checker","the Supabase security checker",[22,433,435],{"id":434},"what-to-do-this-week","What to do this week",[437,438,439],"key-takeaways",{},[160,440,441,444,447,450,453,461],{},[163,442,443],{},"Read the Quick scan result at publish instead of clicking past it, and treat a Critical label as something to fix before the app goes out.",[163,445,446],{},"Run a Deep scan by hand. It does not start on its own, so a project that has never had one has never had its code read.",[163,448,449],{},"After publishing, scan the live address from outside. That is the only check that makes the request a stranger makes.",[163,451,452],{},"Read the policy on every table that holds people. One that permits everybody leaves the table open while the dashboard reports it as protected.",[163,454,455,456,460],{},"Check that the key in your app is the publishable one. ",[44,457,459],{"href":458},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend"," is how to tell the two apart.",[163,462,463],{},"When the inside and outside answers disagree, the outside one is what your users get.",[10,465,466,467,471],{},"If your Lovable app uses Supabase, open a private browsing window and go through\nthe list under Authentication and Policies before Friday.\n",[44,468,470],{"href":469},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","Can anyone read your Supabase database","\nis the same test written out as commands you can paste into a terminal.",{"title":473,"searchDepth":474,"depth":474,"links":475},"",3,[476,478,479,480,481,482,483,484,485],{"id":24,"depth":477,"text":25},2,{"id":63,"depth":477,"text":64},{"id":103,"depth":477,"text":104},{"id":128,"depth":477,"text":129},{"id":151,"depth":477,"text":152},{"id":213,"depth":477,"text":214},{"id":351,"depth":477,"text":352},{"id":405,"depth":477,"text":406},{"id":434,"depth":477,"text":435},"Security basics","\u002Fblog\u002Flovable-security-scan\u002Fcover-1200x630.png","A report panel with a column of ticks on it, and behind it, running off the edge of the frame, a database with rows drifting out.","Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.",false,"md",[493,495,498,501,504],{"q":25,"a":494},"Yes, and there are two scans. The Quick scan runs by itself every time you publish and finishes in seconds, covering your database access rules, your npm dependencies and any MCP server your app exposes without authentication. The Deep scan reads all of your application code and you have to start it yourself from the project Security view. Both are free, and both read your project rather than your published app.",{"q":496,"a":497},"What is the difference between the Quick scan and the Deep scan?","Speed and depth. The Quick scan runs a fixed set of checks in seconds, automatically at publish, and covers your database settings, your dependencies and MCP exposure. The Deep scan includes everything in the Quick scan and then reads your application code for problems specific to your own logic and data: access control, unauthenticated endpoints, injection, leaked secrets, payments, account security and exposed personal data. The Deep scan does not run on its own as you work, so a project that has never had one run has never had its code read.",{"q":499,"a":500},"Is Lovable's security scan enough?","It is a real check and it sees things no outside tool can, such as your dependency tree and a table your front end never names. What it cannot do is make the request your visitors make. A policy can exist, read as valid and still return every row, and the only thing that settles which of those you have is asking your published app from outside with no login. Lovable says the same in its own documentation: the tools help identify common security issues and cannot guarantee complete security.",{"q":502,"a":503},"Why does an external scanner find things Lovable's scan passed?","Because the two read different objects. An inside scan reads your project: the schema, the policies, the dependency tree, the code. An outside scan reads what the published app hands a stranger who is not logged in. From outside, a table with no protection at all and a table with a policy that permits everybody give the same answer, which is rows. That answer is the one your users and everybody else actually get, so when the two disagree it is the one to act on.",{"q":505,"a":506},"Do I need both?","They answer different questions, so running one does not stand in for the other. The useful order is the order the two things happen in: let the Quick scan run at publish, run a Deep scan before anything real goes live and after you add sign-in, payments or a table holding people, then scan the published address from outside. An outside scan takes about 20 seconds and needs no account.","\u002Fblog\u002Flovable-security-scan\u002Fcard-800x500.png",[509,510,511,512,513,514,515,516,517],"lovable security scan","lovable deep scan","lovable quick scan","lovable basic scan","does lovable check security","lovable rls lint","lovable pre-publish check","lovable security review","is lovable's security scan enough",{},true,"Lovable security scan: what it cannot prove","\u002Fblog\u002Flovable-security-scan","2026-09-24",{"title":5,"description":489},"blog\u002Flovable-security-scan",[526,527,528],"The Lovable security scan is really two scans, both free: a Quick one that runs by itself every time you publish, and a Deep one you start yourself that reads all your application code.","Both read your project from the inside. Neither makes the request a stranger makes, so neither can prove what your published app hands back.","Of the 3,553 Lovable apps whose Supabase database we could ask from outside, 2,017 answered a request with no login. Run the inside scan before you publish and an outside one after.","O9S7CXEmwfX-vlCeLm_5E8zv4nDDbbbbEZJlxvXbjqo",[531,537,543,549,555,561,567,573,579,585,591,597,603,610,616,622,627,633,634,640,646,651,657,663,669,675,681,687,693,699,705,711,717,723,729,735,740,745,751,757,763,769,775,781,787,793,799,805,811,817,823,829,835,840,845,851,857,862,867,873],{"path":532,"title":533,"description":534,"published":535,"category":486,"image":536,"draft":490},"\u002Fblog\u002Fbase44-security-scan","Base44 security scan: the one thing only it can see","The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.","2026-10-10","\u002Fblog\u002Fbase44-security-scan\u002Fcard-800x500.png",{"path":538,"title":539,"description":540,"published":541,"category":486,"image":542,"draft":490},"\u002Fblog\u002Fapi-key-leaked-what-to-do","Your API key leaked. Here is the order to do things in","An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.","2026-10-09","\u002Fblog\u002Fapi-key-leaked-what-to-do\u002Fcard-800x500.png",{"path":544,"title":545,"description":546,"published":547,"category":486,"image":548,"draft":490},"\u002Fblog\u002Finfinite-recursion-in-policy-for-relation","\"Infinite recursion detected in policy\" without disabling RLS","\"Infinite recursion detected in policy for relation\" means your Supabase policy asked the table it protects. Here is how to break the circle.","2026-10-08","\u002Fblog\u002Finfinite-recursion-in-policy-for-relation\u002Fcard-800x500.png",{"path":550,"title":551,"description":552,"published":553,"category":486,"image":554,"draft":490},"\u002Fblog\u002Fno-api-key-found-in-request","\"No API key found in request\" in Supabase, and the wrong fix","\"No API key found in request\" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.","2026-10-07","\u002Fblog\u002Fno-api-key-found-in-request\u002Fcard-800x500.png",{"path":556,"title":557,"description":558,"published":559,"category":486,"image":560,"draft":490},"\u002Fblog\u002Fis-base44-safe","Is Base44 safe? What 5,442 live Base44 apps showed","Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.","2026-10-06","\u002Fblog\u002Fis-base44-safe\u002Fcard-800x500.png",{"path":562,"title":563,"description":564,"published":565,"category":486,"image":566,"draft":490},"\u002Fblog\u002Fmove-a-secret-to-an-edge-function","Hide an API key: move it to a Supabase Edge Function","Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.","2026-10-05","\u002Fblog\u002Fmove-a-secret-to-an-edge-function\u002Fcard-800x500.png",{"path":568,"title":569,"description":570,"published":571,"category":486,"image":572,"draft":490},"\u002Fblog\u002Fenv-file-exposed-on-your-server","Is your .env file exposed? The twelve paths to check","Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.","2026-10-04","\u002Fblog\u002Fenv-file-exposed-on-your-server\u002Fcard-800x500.png",{"path":574,"title":575,"description":576,"published":577,"category":486,"image":578,"draft":490},"\u002Fblog\u002Fis-v0-safe","v0 security: all 1,790 v0 apps we scanned got an A","v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.","2026-10-03","\u002Fblog\u002Fis-v0-safe\u002Fcard-800x500.png",{"path":580,"title":581,"description":582,"published":583,"category":486,"image":584,"draft":490},"\u002Fblog\u002Fis-bolt-safe","Is Bolt safe? What 1,123 live Bolt apps showed","Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.","2026-10-02","\u002Fblog\u002Fis-bolt-safe\u002Fcard-800x500.png",{"path":586,"title":587,"description":588,"published":589,"category":486,"image":590,"draft":490},"\u002Fblog\u002Fis-supabase-down-or-your-app","Is Supabase down, or is it your app? How to tell","Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.","2026-10-01","\u002Fblog\u002Fis-supabase-down-or-your-app\u002Fcard-800x500.png",{"path":592,"title":593,"description":594,"published":595,"category":486,"image":596,"draft":490},"\u002Fblog\u002Fdoes-supabase-encrypt-my-data","Does Supabase encrypt my data? Yes. Here is what it stops","Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.","2026-09-30","\u002Fblog\u002Fdoes-supabase-encrypt-my-data\u002Fcard-800x500.png",{"path":598,"title":599,"description":600,"published":601,"category":486,"image":602,"draft":490},"\u002Fblog\u002Fsupabase-free-plan-limits","Supabase free plan limits, and what happens at each one","The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.","2026-09-29","\u002Fblog\u002Fsupabase-free-plan-limits\u002Fcard-800x500.png",{"path":604,"title":605,"description":606,"published":607,"category":608,"image":609,"draft":490},"\u002Fblog\u002Ftest-your-supabase-backup","Test your Supabase backup before the day you need it","How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.","2026-09-28","Backups","\u002Fblog\u002Ftest-your-supabase-backup\u002Fcard-800x500.png",{"path":611,"title":612,"description":613,"published":614,"category":608,"image":615,"draft":490},"\u002Fblog\u002Fsupabase-backup-github-action","Free Supabase backup with a GitHub Action, and the catch","A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.","2026-09-27","\u002Fblog\u002Fsupabase-backup-github-action\u002Fcard-800x500.png",{"path":617,"title":618,"description":619,"published":620,"category":608,"image":621,"draft":490},"\u002Fblog\u002Fdownload-your-supabase-backup","Why you can't download your Supabase backup","You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.","2026-09-26","\u002Fblog\u002Fdownload-your-supabase-backup\u002Fcard-800x500.png",{"path":623,"title":624,"description":625,"published":620,"category":486,"image":626,"draft":490},"\u002Fblog\u002Fsupabase-permission-denied-for-table","Supabase \"permission denied for table\": the missing grant","From October 30, a new Supabase table answers \"permission denied for table\" until you grant access. The grant the email shows is half the fix.","\u002Fblog\u002Fsupabase-permission-denied-for-table\u002Fcard-800x500.png",{"path":628,"title":629,"description":630,"published":631,"category":486,"image":632,"draft":490},"\u002Fblog\u002Fopen-api-endpoint-exposed","Is an open API endpoint a security problem? Look at the JSON","Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.","2026-09-25","\u002Fblog\u002Fopen-api-endpoint-exposed\u002Fcard-800x500.png",{"path":521,"title":5,"description":489,"published":522,"category":486,"image":507,"draft":490},{"path":635,"title":636,"description":637,"published":638,"category":608,"image":639,"draft":490},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":641,"title":642,"description":643,"published":644,"category":486,"image":645,"draft":490},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":147,"title":647,"description":648,"published":649,"category":486,"image":650,"draft":490},"Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","2026-09-21","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":652,"title":653,"description":654,"published":655,"category":486,"image":656,"draft":490},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":658,"title":659,"description":660,"published":661,"category":486,"image":662,"draft":490},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":664,"title":665,"description":666,"published":667,"category":486,"image":668,"draft":490},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":670,"title":671,"description":672,"published":673,"category":486,"image":674,"draft":490},"\u002Fblog\u002Fbase44-source-maps","Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":676,"title":677,"description":678,"published":679,"category":486,"image":680,"draft":490},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":682,"title":683,"description":684,"published":685,"category":486,"image":686,"draft":490},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":688,"title":689,"description":690,"published":691,"category":608,"image":692,"draft":490},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":694,"title":695,"description":696,"published":697,"category":608,"image":698,"draft":490},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":700,"title":701,"description":702,"published":703,"category":608,"image":704,"draft":490},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":706,"title":707,"description":708,"published":709,"category":486,"image":710,"draft":490},"\u002Fblog\u002Fsafest-ai-app-builder","Which AI app builder is safest? We scanned 30,998 apps","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.","2026-09-11","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",{"path":712,"title":713,"description":714,"published":715,"category":486,"image":716,"draft":490},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":718,"title":719,"description":720,"published":721,"category":486,"image":722,"draft":490},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":724,"title":725,"description":726,"published":727,"category":486,"image":728,"draft":490},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":730,"title":731,"description":732,"published":733,"category":486,"image":734,"draft":490},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":430,"title":736,"description":737,"published":738,"category":486,"image":739,"draft":490},"Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":347,"title":741,"description":742,"published":743,"category":486,"image":744,"draft":490},"Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":746,"title":747,"description":748,"published":749,"category":486,"image":750,"draft":490},"\u002Fblog\u002Fmissing-security-headers","Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":752,"title":753,"description":754,"published":755,"category":486,"image":756,"draft":490},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":758,"title":759,"description":760,"published":761,"category":486,"image":762,"draft":490},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":608,"image":768,"draft":490},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":773,"category":486,"image":774,"draft":490},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":776,"title":777,"description":778,"published":779,"category":608,"image":780,"draft":490},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":782,"title":783,"description":784,"published":785,"category":486,"image":786,"draft":490},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":788,"title":789,"description":790,"published":791,"category":486,"image":792,"draft":490},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":794,"title":795,"description":796,"published":797,"category":486,"image":798,"draft":490},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":800,"title":801,"description":802,"published":803,"category":486,"image":804,"draft":490},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":806,"title":807,"description":808,"published":809,"category":608,"image":810,"draft":490},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":812,"title":813,"description":814,"published":815,"category":608,"image":816,"draft":490},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":818,"title":819,"description":820,"published":821,"category":486,"image":822,"draft":490},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":824,"title":825,"description":826,"published":827,"category":486,"image":828,"draft":490},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":830,"title":831,"description":832,"published":833,"category":608,"image":834,"draft":490},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":469,"title":836,"description":837,"published":838,"category":486,"image":839,"draft":490},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":841,"title":842,"description":843,"published":838,"category":486,"image":844,"draft":490},"\u002Fblog\u002Fsource-maps-exposed-in-production","Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":846,"title":847,"description":848,"published":849,"category":486,"image":850,"draft":490},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":852,"title":853,"description":854,"published":855,"category":608,"image":856,"draft":490},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":123,"title":858,"description":859,"published":860,"category":486,"image":861,"draft":490},"Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":863,"title":864,"description":865,"published":860,"category":608,"image":866,"draft":490},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":868,"title":869,"description":870,"published":871,"category":608,"image":872,"draft":490},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":458,"title":874,"description":875,"published":871,"category":486,"image":876,"draft":490},"Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1791618966336]