[{"data":1,"prerenderedAt":774},["ShallowReactive",2],{"blog-en-safest-ai-app-builder":3,"blog-index-en":534},{"id":4,"title":5,"body":6,"category":492,"cover":493,"coverAlt":494,"description":495,"draft":496,"extension":497,"faq":498,"image":514,"keywords":515,"meta":521,"navigation":522,"ogTitle":523,"path":524,"published":525,"seo":526,"stem":527,"tldr":528,"updated":532,"__hash__":533},"blog_en\u002Fblog\u002Fsafest-ai-app-builder.md","Which AI app builder is safest? We scanned 30,998 apps",{"type":7,"value":8,"toc":480},"minimark",[9,13,16,24,29,32,35,38,42,45,58,61,65,68,71,79,83,86,235,248,256,259,280,287,291,294,297,300,306,314,322,326,329,332,421,426,429,439,443,465,472],[10,11,12],"p",{},"You picked a builder before you knew anything about any of them. Maybe a thread\nrecommended one, maybe you liked the demo, maybe it was the one your friend used.\nAnd somewhere since then you have seen someone claim that the one you picked is\nthe insecure one, and wondered whether the safest AI app builder was one of the\nothers all along.",[10,14,15],{},"So we measured it. In August 2026 we scanned 30,998 live apps published from\nLovable, Base44, Replit, v0 and Bolt, and ran the same nine external checks on\nevery one of them.",[10,17,18,19,23],{},"Here is the part the comparison posts get wrong: ",[20,21,22],"strong",{},"the builder you chose is\nalmost never what decides whether your app is exposed."," All five came back\nbetween 99% and 100% for at least one finding. The real differences between them\nare wide, and they are differences in defaults rather than in safety.",[25,26,28],"h2",{"id":27},"which-ai-app-builder-is-safest","Which AI app builder is safest?",[10,30,31],{},"None of them, and the ranking you are looking for does not exist.",[10,33,34],{},"Every builder in this scan produced apps with findings, at close to the same\nrate, because the commonest finding is set by the hosting rather than by the\nperson who built the app. Below that headline the builders diverge sharply, but\nthey diverge on things like whether your source code gets published alongside\nyour app, not on whether strangers can read your users.",[10,36,37],{},"The thing that separates an A from a D is something you did after you picked a\nbuilder. Usually it is one decision: you connected a database.",[25,39,41],{"id":40},"what-we-measured","What we measured",[10,43,44],{},"The same nine checks we would run on your app, read from outside, with no login\nand no access to anyone's account.",[10,46,47,48,51,52,57],{},"We scanned every app between 12 and 14 August 2026, and 30,998 of them produced a\nresult we could classify. Every percentage below is a share of the apps that\ncheck actually ",[20,49,50],{},"answered"," on, never a share of everything we scanned. A check\nthat could not complete is recorded as unknown, not as a pass, which is why the\ndenominators in the tables move around. The full method and the underlying data\nare ",[53,54,56],"a",{"href":55},"\u002Fresearch\u002Fvibe-coded-app-security-2026","in the report",".",[10,59,60],{},"Two things we did not do. We never logged in anywhere, and we never read anyone's\nrows: where a table answered, we asked the database how many rows it would hand\nover and stopped there. No app is named here or anywhere else we publish.",[25,62,64],{"id":63},"every-builder-is-at-99-and-that-number-says-less-than-it-looks","Every builder is at 99%, and that number says less than it looks",[10,66,67],{},"Because nearly all of it is one finding, and that finding belongs to the platform.",[10,69,70],{},"Missing browser security headers turned up on 18,539 of 18,554 Lovable apps, all\n5,438 Base44 apps, 1,790 of 1,790 v0 apps, 1,121 of 1,123 Bolt apps and 2,924 of\n3,042 Replit apps. Headers are sent by whatever serves your app, so on a\nbuilder's own domain they are a property of that domain and identical across\nevery app sitting on it.",[10,72,73,74,78],{},"It is a real finding and it is worth closing when you move to your own domain.\nBut it is the ",[53,75,77],{"href":76},"\u002Fblog\u002Fmissing-security-headers","least urgent line on a report",",\nand it is most of what \"99% of apps have a problem\" is counting.",[25,80,82],{"id":81},"the-real-difference-between-builders-is-defaults","The real difference between builders is defaults",[10,84,85],{},"Each builder ships a different set of defaults, and those show up in nearly every\napp it makes.",[87,88,89,118],"table",{},[90,91,92],"thead",{},[93,94,95,99,103,106,109,112,115],"tr",{},[96,97,98],"th",{},"Builder",[96,100,102],{"align":101},"right","Apps scanned",[96,104,105],{"align":101},"At least one finding",[96,107,108],{"align":101},"Served a source map",[96,110,111],{"align":101},"Cross-origin finding",[96,113,114],{"align":101},"Shipped a secret key",[96,116,117],{"align":101},"Graded D or F",[119,120,121,145,170,192,213],"tbody",{},[93,122,123,127,130,133,136,139,142],{},[124,125,126],"td",{},"Lovable",[124,128,129],{"align":101},"18,554",[124,131,132],{"align":101},"99%",[124,134,135],{"align":101},"225 of 18,553",[124,137,138],{"align":101},"8 of 18,518",[124,140,141],{"align":101},"822 (4%)",[124,143,144],{"align":101},"407",[93,146,147,150,153,156,159,164,167],{},[124,148,149],{},"Base44",[124,151,152],{"align":101},"5,438",[124,154,155],{"align":101},"100%",[124,157,158],{"align":101},"3,229 of 5,434 (59%)",[124,160,161],{"align":101},[20,162,163],{},"5,418 of 5,419 (99%)",[124,165,166],{"align":101},"103 (2%)",[124,168,169],{"align":101},"2",[93,171,172,175,178,180,183,186,189],{},[124,173,174],{},"Replit",[124,176,177],{"align":101},"3,042",[124,179,132],{"align":101},[124,181,182],{"align":101},"168 of 3,041 (6%)",[124,184,185],{"align":101},"1,129 of 3,037 (37%)",[124,187,188],{"align":101},"219 (7%)",[124,190,191],{"align":101},"9",[93,193,194,197,200,202,205,208,211],{},[124,195,196],{},"v0",[124,198,199],{"align":101},"1,790",[124,201,155],{"align":101},[124,203,204],{"align":101},"0 of 1,790",[124,206,207],{"align":101},"0 of 1,786",[124,209,210],{"align":101},"0",[124,212,210],{"align":101},[93,214,215,218,221,223,226,229,232],{},[124,216,217],{},"Bolt",[124,219,220],{"align":101},"1,123",[124,222,155],{"align":101},[124,224,225],{"align":101},"13 of 1,123",[124,227,228],{"align":101},"5 of 1,120",[124,230,231],{"align":101},"75 (7%)",[124,233,234],{"align":101},"15",[10,236,237,238,242,243,247],{},"The source-map column is the one to read carefully, because on Base44 it is not\nmeasuring the same thing as it is on the other four. We re-opened 30 flagged\nBase44 apps in September: on 27 the only map answering was\n",[239,240,241],"code",{},"\u002Fstatic\u002Fjs\u002Fbadge.js.map",", which belongs to Base44's own badge script, and on\nnone of the 30 did a map cover the owner's files. So that 59% is a platform\npublishing one of its own files on every app it hosts, not 3,229 owners leaking\ntheir code. On Lovable, Replit and Bolt the same column does mean the owner's\ncode, which is why 1% and 6% and 59% cannot be read down the page as a ranking.\n",[53,244,246],{"href":245},"\u002Fblog\u002Fbase44-source-maps","What we found inside those Base44 maps"," is the full\naccount.",[10,249,250,251,255],{},"The 99% cross-origin column is the real one, and it is also Base44's own doing:\nthe platform sets CORS for every app it hosts and offers no per-app setting.\nPublished source code, where it is yours, means the original files behind your\napp are readable from the browser's developer tools.\n",[53,252,254],{"href":253},"\u002Fblog\u002Fsource-maps-exposed-in-production","What that does and does not expose"," is\nworth reading if you are on one of the other four.",[10,257,258],{},"The secret-key column is the one people expect to dominate, and it does not. A\nkey worth naming turned up in 4% to 7% of apps on three of the five builders and\nin none of the v0 apps at all.",[10,260,261,262,265,266,269,270,265,273,276,277,57],{},"If you want the plain-language version for the builder you actually use, each has\nits own page: ",[53,263,126],{"href":264},"\u002Fis-your-lovable-app-safe",",\n",[53,267,149],{"href":268},"\u002Fis-your-base44-app-safe",", ",[53,271,174],{"href":272},"\u002Fis-your-replit-app-safe",[53,274,196],{"href":275},"\u002Fis-your-v0-app-safe"," and ",[53,278,217],{"href":279},"\u002Fis-your-bolt-app-safe",[10,281,282,283,57],{},"Or skip the reading: our free scan runs these same checks against your live site\nand tells you which of them your app trips. About 20 seconds, no account:\n",[53,284,286],{"href":285},"\u002F#scan","scan your app",[25,288,290],{"id":289},"what-actually-decides-a-d-or-an-f","What actually decides a D or an F",[10,292,293],{},"A database, and what you did to it.",[10,295,296],{},"Lovable produced 407 apps graded D or F out of 18,554. v0 produced none out of\n1,790. That looks like a verdict on the two builders until you look at what the\napps are: 35% of Lovable apps name a database project, against roughly 1% of v0\napps.",[10,298,299],{},"The checks that can produce a D or an F are almost all database checks. An app\nwith no database has less that can go wrong and less for us to look at. So the\nLovable row is not measuring a worse builder, it is measuring a builder whose\nusers connect databases, which is most of why people choose it.",[301,302],"diagram",{"alt":303,"caption":304,"src":305},"Two apps drawn side by side as identical panels. The left one holds a single blank block with three green check marks beneath it and the letter A in its top corner. The right one holds the same block and the same three check marks, with a dashed line running down to a red database cylinder and a red cross, and the letter D in its top corner.","The outer checks come out the same on both. Everything that can produce a serious grade lives in the part you attached yourself.","\u002Fblog\u002Fsafest-ai-app-builder\u002Fwhere-a-grade-comes-from-1600x700.png",[10,307,308,309,313],{},"Of the 3,553 Lovable apps whose database answered us, 2,017 had at least one\ntable a stranger could read with no login. That is\n",[53,310,312],{"href":311},"\u002Fblog\u002Fcan-anyone-read-your-supabase-database","the finding worth fixing first",",\nand it has nothing to do with which builder generated your front end.",[10,315,316,317,321],{},"Lovable is where that number is big enough to be worth its own article: ",[53,318,320],{"href":319},"\u002Fblog\u002Fis-lovable-safe","what\n18,554 live Lovable apps showed"," takes the same nine\nchecks through the largest cohort we have.",[25,323,325],{"id":324},"why-we-are-not-going-to-rank-them","Why we are not going to rank them",[10,327,328],{},"Because for three of the five, we could not check enough databases to say\nanything at all.",[10,330,331],{},"Here is the part of the data that every league table leaves out:",[87,333,334,349],{},[90,335,336],{},[93,337,338,340,343,346],{},[96,339,98],{},[96,341,342],{"align":101},"Names a database project",[96,344,345],{"align":101},"Databases that answered us",[96,347,348],{},"Had a readable table",[119,350,351,364,378,393,408],{},[93,352,353,355,358,361],{},[124,354,126],{},[124,356,357],{"align":101},"35%",[124,359,360],{"align":101},"3,553",[124,362,363],{},"2,017, or 57%",[93,365,366,368,371,375],{},[124,367,149],{},[124,369,370],{"align":101},"27%",[124,372,373],{"align":101},[20,374,169],{},[124,376,377],{},"2 of the 2 we reached",[93,379,380,382,385,390],{},[124,381,217],{},[124,383,384],{"align":101},"24%",[124,386,387],{"align":101},[20,388,389],{},"35",[124,391,392],{},"27 of the 35 we reached",[93,394,395,397,400,405],{},[124,396,174],{},[124,398,399],{"align":101},"1%",[124,401,402],{"align":101},[20,403,404],{},"5",[124,406,407],{},"4 of the 5 we reached",[93,409,410,412,414,418],{},[124,411,196],{},[124,413,399],{"align":101},[124,415,416],{"align":101},[20,417,210],{},[124,419,420],{},"nothing to check",[301,422],{"alt":423,"caption":424,"src":425},"Five rows, each headed by a builder's logo and the number of its apps we scanned. Each row draws those apps as a pale bar with the databases that answered us filled in solid. Lovable's solid section is a wide block reading 3,553; Base44, Replit and Bolt are hairlines reading 2, 5 and 35, and v0's is a dashed empty circle reading 0.","The solid part of each bar is what we could actually check. Four of the five are too thin to carry a percentage.","\u002Fblog\u002Fsafest-ai-app-builder\u002Fwhat-we-could-check-1600x620.png",[10,427,428],{},"Look at the Base44 row. More than a quarter of its apps name a database project,\nand exactly two of those databases ever answered us. We are not going to turn two\napps into a rate and print it next to a number built on 3,553. Nor is anyone else\nwho has scanned from outside, whether or not their comparison table says so.",[430,431,433],"callout",{"type":432},"warn",[10,434,435,438],{},[20,436,437],{},"A check that could not complete is not a check that passed."," This is the rule\nthat decides most of what is above, and it is the one that gets quietly dropped\nwhen a scan gets turned into a league table. An app we could not reach is\nunknown. A database that never answered is unknown. Counting either as clean\nproduces a tidier chart and a false one, and it is the single worst thing a\nsecurity report can do to somebody who then stops worrying.",[25,440,442],{"id":441},"what-to-check-on-your-own-app","What to check on your own app",[444,445,446],"key-takeaways",{},[447,448,449,453,456,459,462],"ul",{},[450,451,452],"li",{},"Stop shopping for a safer builder. Nothing in this data supports moving, and a move rebuilds your whole app to change a row you were never graded on.",[450,454,455],{},"Start with your database tables, whichever builder you used. A table a stranger can read is the finding that empties an app, and it is the one thing here you can only fix yourself.",[450,457,458],{},"Find out whether your builder publishes your source code, then turn it off if it does. It is one build setting on four of the five platforms above. On Base44 the map that answers is the platform's own and there is nothing on your side to switch.",[450,460,461],{},"Treat the headers finding as housekeeping. It is real, it applies to almost every app on a builder's own domain, and it is not what anyone is going to use against you.",[450,463,464],{},"Check any key in your published code before you worry about anything on this page, because that is the one finding that is already costing money while you read.",[10,466,467,468,57],{},"All of this is checkable by hand. Keeping the answer true next month is the part\nthat does not stay done, and it is why Reeve Care exists: it re-runs these\nsame checks on a schedule and tells you when an answer gets worse, then keeps\nverified copies of your database outside your database provider's account so\nthere is something to put back. That second half matters because we only ever\ncheck reading, and the same permissive rule that lets a stranger read a table\nusually lets them write to it. ",[53,469,471],{"href":470},"\u002Fpricing","What it watches and what it costs",[10,473,474,475,479],{},"If you would rather work through this as a list, the\n",[53,476,478],{"href":477},"\u002Fchecklist","10-minute security checklist"," covers the whole set in plain\nlanguage.",{"title":481,"searchDepth":482,"depth":482,"links":483},"",3,[484,486,487,488,489,490,491],{"id":27,"depth":485,"text":28},2,{"id":40,"depth":485,"text":41},{"id":63,"depth":485,"text":64},{"id":81,"depth":485,"text":82},{"id":289,"depth":485,"text":290},{"id":324,"depth":485,"text":325},{"id":441,"depth":485,"text":442},"Security basics","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcover-1200x630.png","Five identical white tiles in a row on a dark panel, evenly spaced and the same size, each carrying one app builder's logo.","Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.",false,"md",[499,502,505,508,511],{"q":500,"a":501},"Which AI app builder makes the safest apps?","None of them measurably. Across 30,998 live apps, every builder we scanned came in between 99% and 100% for at least one finding, and the bulk of that is missing browser security headers, which the hosting sets rather than you. The differences between builders are differences in defaults: what gets published alongside your app, and how the connection to your API is configured. None of those defaults is what produces a serious grade.",{"q":503,"a":504},"Does it matter at all which builder I picked?","It matters for what you inherit on day one, and not much for what happens afterwards. Some builders publish your original source code with every app; others do not. Some set a wide-open cross-origin rule by default; others do not. Those are worth knowing about and mostly worth changing. But the finding that actually costs people their data is a readable database table, and you get that by connecting a database and writing a permissive rule, which you can do on any builder.",{"q":506,"a":507},"Every app from my builder failed the security headers check. Is that my fault?","No, and usually you cannot fix it from inside the builder either. Security headers are sent by whatever serves your app, so on a builder-hosted domain they are the platform default and identical across every app on it. That is why the figure is 99% or 100% for all five. It is the least urgent line on a report for exactly this reason: it is real, it is worth fixing when you move to your own domain, and it says nothing about whether anyone can reach your data.",{"q":509,"a":510},"v0 had zero apps graded D or F. Does that make it the safest?","It makes it the one with the fewest databases attached. Only about 1% of the v0 apps we scanned named a database project at all, against 35% of Lovable apps, and the checks that produce a D or an F are database checks. An app with no database has less that can go wrong and less that we can check. Read that row as a statement about what those apps are, not about how well the builder protects them.",{"q":512,"a":513},"Should I move my app to a different builder to make it safer?","No. Moving means rebuilding everything you have, and it changes almost nothing on this list, because the findings that matter live in the services you connected rather than in the builder that generated your code. The two worth doing are the rules on your database tables and any secret key sitting in your published code. Both follow you to whatever builder you move to, and both are fixable where you are.","\u002Fblog\u002Fsafest-ai-app-builder\u002Fcard-800x500.png",[516,517,518,519,520],"safest ai app builder","which ai app builder is most secure","ai app builder security comparison","lovable vs bolt security","are ai built apps secure",{},true,"Which AI app builder is safest? 30,998 apps scanned","\u002Fblog\u002Fsafest-ai-app-builder","2026-09-11",{"title":5,"description":495},"blog\u002Fsafest-ai-app-builder",[529,530,531],"There is no safest AI app builder. All five we scanned came in between 99% and 100% for at least one finding, and nearly all of that is a browser header their hosting sets for you.","What differs between builders is defaults, and the gaps are wide. Base44's 3,229 source maps in 5,434 are the platform's own badge script rather than anybody's app; Lovable's 225 in 18,553 are the owner's code.","What decides a serious grade is not the builder. It is whether you attached a database and left a table readable.","2026-09-21","uqh1It5qJYFFeSdMoyLqR6pbErdgskLcnQEVhah7d04",[535,542,548,552,558,564,570,575,581,587,593,599,605,606,612,618,624,630,636,642,647,653,659,665,671,677,683,689,695,701,707,713,719,725,731,736,740,746,752,758,763,769],{"path":536,"title":537,"description":538,"published":539,"category":540,"image":541,"draft":496},"\u002Fblog\u002Fsupabase-backup-auth-users","Why your Supabase dump has no users in it","Run supabase db dump on its own and you get the shape of your database and none of its rows, with the auth schema your users live in left out entirely.","2026-09-23","Backups","\u002Fblog\u002Fsupabase-backup-auth-users\u002Fcard-800x500.png",{"path":543,"title":544,"description":545,"published":546,"category":492,"image":547,"draft":496},"\u002Fblog\u002Fdomain-and-certificate-expiry","Domain expired, website down: what actually happens next","Your domain expired and your website is down. Here is the clock you are on, why a lapsed certificate is the easier of the two, and how to check both.","2026-09-22","\u002Fblog\u002Fdomain-and-certificate-expiry\u002Fcard-800x500.png",{"path":319,"title":549,"description":550,"published":532,"category":492,"image":551,"draft":496},"Is Lovable safe? What 18,554 live Lovable apps showed","Is Lovable safe? We ran nine checks on 18,554 live Lovable apps. The platform was the cleanest of five builders. Every finding was inside the app itself.","\u002Fblog\u002Fis-lovable-safe\u002Fcard-800x500.png",{"path":553,"title":554,"description":555,"published":556,"category":492,"image":557,"draft":496},"\u002Fblog\u002Fvibe-coded-app-security-checklist","The vibe coding security checklist, in nine checks","A vibe coding security checklist with nine items, each one something anyone can verify about your live app from outside, and each with a one-line test.","2026-09-20","\u002Fblog\u002Fvibe-coded-app-security-checklist\u002Fcard-800x500.png",{"path":559,"title":560,"description":561,"published":562,"category":492,"image":563,"draft":496},"\u002Fblog\u002Fstripe-secret-key-in-frontend","A Stripe secret key exposed in your frontend can move money","A Stripe secret key exposed in your frontend can refund, charge and read every customer record you hold. Your pk_live_ key is meant to be there.","2026-09-19","\u002Fblog\u002Fstripe-secret-key-in-frontend\u002Fcard-800x500.png",{"path":565,"title":566,"description":567,"published":568,"category":492,"image":569,"draft":496},"\u002Fblog\u002Fvite-and-next-public-env-vars","Vite env variables exposed: VITE_ and NEXT_PUBLIC_ mean publish this","Vite env variables exposed in your app did what the prefix asked. VITE_ and NEXT_PUBLIC_ mean publish this, and the AI that added one never knew the cost.","2026-09-18","\u002Fblog\u002Fvite-and-next-public-env-vars\u002Fcard-800x500.png",{"path":245,"title":571,"description":572,"published":573,"category":492,"image":574,"draft":496},"Base44 security: what a scan flags, and what is yours to fix","Base44 security on 5,438 scanned apps: three findings on nearly every one are the platform's, the source map is Base44's badge, and what is yours is short.","2026-09-17","\u002Fblog\u002Fbase44-source-maps\u002Fcard-800x500.png",{"path":576,"title":577,"description":578,"published":579,"category":492,"image":580,"draft":496},"\u002Fblog\u002Fis-cursor-ai-safe","Is Cursor AI safe? The editor, the code, and the app you shipped","Is Cursor AI safe? Three questions in one search: what Cursor keeps, what the code it writes gets wrong, and whether the app you shipped is open.","2026-09-16","\u002Fblog\u002Fis-cursor-ai-safe\u002Fcard-800x500.png",{"path":582,"title":583,"description":584,"published":585,"category":492,"image":586,"draft":496},"\u002Fblog\u002Fis-replit-safe","Is Replit safe? What we found in 3,042 live Replit apps","Is Replit safe? We ran nine external checks on 3,042 live Replit apps. The host was not where the findings were. The app each owner published was.","2026-09-15","\u002Fblog\u002Fis-replit-safe\u002Fcard-800x500.png",{"path":588,"title":589,"description":590,"published":591,"category":540,"image":592,"draft":496},"\u002Fblog\u002Fsupabase-storage-backup","Supabase storage backup: why your database copy has no files","A Supabase storage backup is a separate job. Database backups keep the list of your files and none of the files, so a restore leaves every upload broken.","2026-09-14","\u002Fblog\u002Fsupabase-storage-backup\u002Fcard-800x500.png",{"path":594,"title":595,"description":596,"published":597,"category":540,"image":598,"draft":496},"\u002Fblog\u002Fsupabase-point-in-time-recovery","Supabase point-in-time recovery: what it costs, what it misses","Supabase point-in-time recovery rewinds your database to any second in the last week. It costs $100 a month on top of Pro, and it covers your database only.","2026-09-13","\u002Fblog\u002Fsupabase-point-in-time-recovery\u002Fcard-800x500.png",{"path":600,"title":601,"description":602,"published":603,"category":540,"image":604,"draft":496},"\u002Fblog\u002Fsupabase-project-paused-recover","Supabase project paused? Your data is still there","Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.","2026-09-12","\u002Fblog\u002Fsupabase-project-paused-recover\u002Fcard-800x500.png",{"path":524,"title":5,"description":495,"published":525,"category":492,"image":514,"draft":496},{"path":607,"title":608,"description":609,"published":610,"category":492,"image":611,"draft":496},"\u002Fblog\u002Fenable-rls-on-every-supabase-table","Enable Row Level Security on every Supabase table, then prove it","Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.","2026-09-10","\u002Fblog\u002Fenable-rls-on-every-supabase-table\u002Fcard-800x500.png",{"path":613,"title":614,"description":615,"published":616,"category":492,"image":617,"draft":496},"\u002Fblog\u002Fsupabase-rls-disabled-in-public","Supabase \"RLS disabled in public\": what the warning misses","Supabase reports \"RLS disabled in public\" as an error. It says nothing about the read policy that leaves your table just as open to strangers.","2026-09-09","\u002Fblog\u002Fsupabase-rls-disabled-in-public\u002Fcard-800x500.png",{"path":619,"title":620,"description":621,"published":622,"category":492,"image":623,"draft":496},"\u002Fblog\u002Frotate-supabase-service-role-key","How to rotate a leaked Supabase service_role key","Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.","2026-09-08","\u002Fblog\u002Frotate-supabase-service-role-key\u002Fcard-800x500.png",{"path":625,"title":626,"description":627,"published":628,"category":492,"image":629,"draft":496},"\u002Fblog\u002Fvibe-coding-security-scanners-compared","Vibe coding security scanners compared, including ours","The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.","2026-09-07","\u002Fblog\u002Fvibe-coding-security-scanners-compared\u002Fcard-800x500.png",{"path":631,"title":632,"description":633,"published":634,"category":492,"image":635,"draft":496},"\u002Fblog\u002Fsupabase-security-checker","Supabase security checker: run the five checks yourself","A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.","2026-09-06","\u002Fblog\u002Fsupabase-security-checker\u002Fcard-800x500.png",{"path":637,"title":638,"description":639,"published":640,"category":492,"image":641,"draft":496},"\u002Fblog\u002Fvibe-coding-security-scanner","Vibe coding security scanner: what a URL scan misses","A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.","2026-09-05","\u002Fblog\u002Fvibe-coding-security-scanner\u002Fcard-800x500.png",{"path":76,"title":643,"description":644,"published":645,"category":492,"image":646,"draft":496},"Missing security headers: when it actually matters","Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.","2026-09-04","\u002Fblog\u002Fmissing-security-headers\u002Fcard-800x500.png",{"path":648,"title":649,"description":650,"published":651,"category":492,"image":652,"draft":496},"\u002Fblog\u002Fopenai-api-key-exposed-in-frontend","Your OpenAI API key is exposed in your frontend. Rotate it.","An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.","2026-09-03","\u002Fblog\u002Fopenai-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":654,"title":655,"description":656,"published":657,"category":492,"image":658,"draft":496},"\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps","An API key exposed in your frontend: what 30,998 apps shipped","An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.","2026-09-02","\u002Fblog\u002Fwhat-secrets-leak-from-vibe-coded-apps\u002Fcard-800x500.png",{"path":660,"title":661,"description":662,"published":663,"category":540,"image":664,"draft":496},"\u002Fblog\u002Fsupabase-backup-tools-compared","Supabase backup tools compared, including ours","Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.","2026-09-01","\u002Fblog\u002Fsupabase-backup-tools-compared\u002Fcard-800x500.png",{"path":666,"title":667,"description":668,"published":669,"category":492,"image":670,"draft":496},"\u002Fblog\u002Freplit-secrets-explained","How to use secrets in Replit, and what still gets published","How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.","2026-08-31","\u002Fblog\u002Freplit-secrets-explained\u002Fcard-800x500.png",{"path":672,"title":673,"description":674,"published":675,"category":540,"image":676,"draft":496},"\u002Fblog\u002Fback-up-supabase-free-tier","Supabase free tier backups: how to make one without a terminal","There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.","2026-08-30","\u002Fblog\u002Fback-up-supabase-free-tier\u002Fcard-800x500.png",{"path":678,"title":679,"description":680,"published":681,"category":492,"image":682,"draft":496},"\u002Fblog\u002Fis-supabase-secure","Is Supabase secure? Yes. Your project is a separate question","Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.","2026-08-29","\u002Fblog\u002Fis-supabase-secure\u002Fcard-800x500.png",{"path":684,"title":685,"description":686,"published":687,"category":492,"image":688,"draft":496},"\u002Fblog\u002Fwhere-to-find-supabase-api-keys","Where to find your Supabase API keys: anon, service_role and the URL","Your Supabase project URL, anon key and service_role key are on one dashboard page. Here is where that page is, and which of the four belongs in your app.","2026-08-28","\u002Fblog\u002Fwhere-to-find-supabase-api-keys\u002Fcard-800x500.png",{"path":690,"title":691,"description":692,"published":693,"category":492,"image":694,"draft":496},"\u002Fblog\u002Fnew-row-violates-row-level-security-policy","New row violates row-level security policy in Supabase. Now what?","\"New row violates row-level security policy\" means Supabase refused a write. The fix that clears it in ten seconds also reopens the table to everyone.","2026-08-27","\u002Fblog\u002Fnew-row-violates-row-level-security-policy\u002Fcard-800x500.png",{"path":696,"title":697,"description":698,"published":699,"category":492,"image":700,"draft":496},"\u002Fblog\u002Fcors-wildcard-security-risk","Is a CORS wildcard a security risk? Usually not.","Is a CORS wildcard a security risk? Usually it is your builder default, and it gives away nothing your server was not already handing to anyone who asked.","2026-08-26","\u002Fblog\u002Fcors-wildcard-security-risk\u002Fcard-800x500.png",{"path":702,"title":703,"description":704,"published":705,"category":540,"image":706,"draft":496},"\u002Fblog\u002Fsupabase-branching-is-not-a-backup","Supabase branching is not a backup. It only goes forwards.","Supabase branching is not a backup: a branch starts with none of your data, and merging only moves schema. What it is for, and what to use instead.","2026-08-25","\u002Fblog\u002Fsupabase-branching-is-not-a-backup\u002Fcard-800x500.png",{"path":708,"title":709,"description":710,"published":711,"category":540,"image":712,"draft":496},"\u002Fblog\u002Fhow-to-restore-a-supabase-backup","How to restore a Supabase backup, and what breaks after","How to restore a Supabase backup from the dashboard or from a dump file, what the restore replaces, and why your app can still be broken when it finishes.","2026-08-24","\u002Fblog\u002Fhow-to-restore-a-supabase-backup\u002Fcard-800x500.png",{"path":714,"title":715,"description":716,"published":717,"category":492,"image":718,"draft":496},"\u002Fblog\u002Fsupabase-storage-bucket-public","Your Supabase storage bucket is public. Is that a problem?","A public Supabase storage bucket means anyone with a file URL can open it. It does not mean anyone can list what is in there. Two different settings.","2026-08-23","\u002Fblog\u002Fsupabase-storage-bucket-public\u002Fcard-800x500.png",{"path":720,"title":721,"description":722,"published":723,"category":492,"image":724,"draft":496},"\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend","Is a Google API key exposed in your frontend a problem?","A Google API key exposed in your frontend is the key our scanner finds most often, and usually it is fine. One free setting decides which it is.","2026-08-22","\u002Fblog\u002Fgoogle-api-key-exposed-in-frontend\u002Fcard-800x500.png",{"path":726,"title":727,"description":728,"published":729,"category":540,"image":730,"draft":496},"\u002Fblog\u002Fai-agent-deleted-my-database","An AI agent deleted my Supabase data. What can I recover?","An AI agent deleted your database data. What you can recover was decided before it ran, and the next few minutes decide how much of it survives.","2026-08-21","\u002Fblog\u002Fai-agent-deleted-my-database\u002Fcard-800x500.png",{"path":311,"title":732,"description":733,"published":734,"category":492,"image":735,"draft":496},"Can anyone read your Supabase database? We checked 3,680 apps","Can anyone read your Supabase database without logging in? We scanned 30,998 live apps built with AI builders and measured how often the answer is yes.","2026-08-18","\u002Fblog\u002Fcan-anyone-read-your-supabase-database\u002Fcard-800x500.png",{"path":253,"title":737,"description":738,"published":734,"category":492,"image":739,"draft":496},"Source maps exposed: your app is publishing its original code","An exposed source map lets anyone read your app's original code, comments included. The 30-second check, and what actually matters if yours are public.","\u002Fblog\u002Fsource-maps-exposed-in-production\u002Fcard-800x500.png",{"path":741,"title":742,"description":743,"published":744,"category":492,"image":745,"draft":496},"\u002Fblog\u002Fsupabase-new-api-keys","Supabase's new API keys: which one is safe in your app?","Supabase replaced anon and service_role with publishable and secret keys. Which one belongs in your app, and which never does?","2026-08-12","\u002Fblog\u002Fsupabase-new-api-keys\u002Fcard-800x500.png",{"path":747,"title":748,"description":749,"published":750,"category":540,"image":751,"draft":496},"\u002Fblog\u002Fdoes-supabase-back-up-my-database","Does Supabase back up my database? It depends on your plan.","Does Supabase back up your database? Daily on paid plans, and not at all on the free one. How to check which you have, and what that copy cannot survive.","2026-08-11","\u002Fblog\u002Fdoes-supabase-back-up-my-database\u002Fcard-800x500.png",{"path":753,"title":754,"description":755,"published":756,"category":492,"image":757,"draft":496},"\u002Fblog\u002Fsupabase-rls-on-but-table-still-public","Supabase Row Level Security is on. Your table is still public.","Turning on Supabase Row Level Security does not protect a table. Your policies do, and the policy that fixed your broken app may let everyone in.","2026-08-10","\u002Fblog\u002Fsupabase-rls-on-but-table-still-public\u002Fcard-800x500.png",{"path":759,"title":760,"description":761,"published":756,"category":540,"image":762,"draft":496},"\u002Fblog\u002Fversion-history-is-not-a-backup","Version history is not a backup. It cannot undo a deleted table.","Lovable and Bolt keep version history for your code. Your database is a separate service, so rolling back to this morning does not bring your data back.","\u002Fblog\u002Fversion-history-is-not-a-backup\u002Fcard-800x500.png",{"path":764,"title":765,"description":766,"published":767,"category":540,"image":768,"draft":496},"\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database","Three ways to back up a Supabase database, and what each misses","The dashboard, pg_dump, and a managed service. What each one actually saves, what it quietly leaves out, and which one survives losing the account.","2026-08-09","\u002Fblog\u002Fthree-ways-to-back-up-a-supabase-database\u002Fcard-800x500.png",{"path":770,"title":771,"description":772,"published":767,"category":492,"image":773,"draft":496},"\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend","Which API keys are safe in your frontend, and which aren't","Your Supabase anon key is supposed to be public. Your service_role key is not, and it ignores every rule you set. Here is how to tell them apart.","\u002Fblog\u002Fwhich-api-keys-are-safe-in-your-frontend\u002Fcard-800x500.png",1790150951364]