Skip to content

Security, in plain language

Short write-ups about what actually goes wrong in AI-built apps, and what to do about it.

Page 2 of 5

Backups

Why you can't download your Supabase backup

You can't download your Supabase backup on a current project, because the daily copy is a physical snapshot. How to tell, and how to hold a copy of your own.

Security basics

Supabase "permission denied for table": the missing grant

From October 30, a new Supabase table answers "permission denied for table" until you grant access. The grant the email shows is half the fix.

Security basics

Is an open API endpoint a security problem? Look at the JSON

Your scan flagged an open API endpoint. Whether it matters depends on what came back, and most of the ones we found were the platform's own.

Security basics

Lovable security scan: the one thing it cannot prove

Lovable security scan: what the Quick and Deep scans check, when each one runs, and the one thing no scan from inside your project can prove.

Backups

Why your Supabase dump has no users in it

Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.

Security basics

Domain expired, website down: what actually happens next

Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.

Security basics

Is Lovable safe? What 18,554 live Lovable apps showed

Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.

Security basics

The vibe coding security checklist, in nine checks

A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.

Security basics

A Stripe secret key exposed in your frontend can move money

A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.

Security basics

Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this

Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.

Security basics

Base44 security: what a scan flags, and what is yours to fix

Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.

Security basics

Is Cursor AI safe? The editor, the code, and the app you shipped

Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.

Security basics

Is Replit safe? What we found in 3,042 live Replit apps

Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.

Backups

Supabase storage backup: why your database copy has no files

A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.

Backups

Supabase point-in-time recovery: what it costs, what it misses

Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.

Everything here is written by a security expert, and aimed at whoever pressed deploy.

Vlad Tkachenko