For apps built on Lovable · Bolt · Replit

Find out what your app is leaking — before someone else does.

Most vibe-coded apps ship with a database a stranger can read. We don't just flag it — we prove it, then help you close it.

Free. Passive scan — only what your browser already loads. No account.

Live read visitor · not logged in
profilesreadable
name · city · user_id · passphrase_hash
crowd_reportsreadable
user_badgesreadable
arena_eventsreadable
8 tables answered a stranger — no login, just the app's public key.
We prove it

Anyone could read this. So we did.

Other scanners pattern-match your code and guess. We act like a real visitor and read what's actually exposed — no login, nothing your own front-end couldn't already do.

That's the difference between "might be a problem" and "here's your users' data." (Anonymized from a real app we checked, with the owner's permission.)

We close it

From leaking to proven shut — not a prompt to paste.

Most tools hand you a fix to copy into your AI tool and wish you luck. We take it all the way — and verify.

Step 01

Confirmed open

We read your exposed tables as an anonymous visitor — proof, not a guess.

Step 02

Fix applied

We generate the exact database policy and apply it — with your approval, on your project.

Step 03

Verified closed

We re-scan and only call it fixed when the leak is actually gone. Proven, not promised.

47%

of the public Lovable apps we scanned load their database right in the browser.

Passive scan of 15 apps from a public showcase. Loading the database client-side is fine — until one missing setting makes the whole thing public. Most are one toggle away.

Dead simple

You paste a link. We do the rest.

1

Paste your URL

No code, no install, no account. Just the link to your live app.

2

We run a passive check

Only what a visitor's browser already sees. Nothing intrusive, none of your users' data.

3

You get a plain report

What's exposed, why it matters, and how to fix it — in human language.

What we look for

The mistakes vibe-coded apps make most.

An open database

Supabase tables anyone can read without logging in — the #1 leak in Lovable apps.

Secrets in the browser

API keys and tokens shipped to the front-end, where anyone can grab them.

Forgotten files

Stray .env, .git or database dumps left reachable online.

Missing protections

Security headers and rules that aren't set — the easy stuff attackers count on.

Ship without getting hacked.

Find out what your app is exposing in the next 60 seconds. It's free.