In 2025, a single missing security setting exposed live user data across more than 170 Lovable apps (tracked as CVE-2025-48757). A second incident in April 2026 let any free account browse other users' project source code and database credentials. Paste your Supabase URL below to check your own app right now — free, read-only, no signup.
Check your Supabase project
We try the table names most common in real apps — the same starting point anyone with your public URL would have.
Using the same public key already sitting in your browser's code — nothing a normal visitor couldn't also do.
If something responds, it goes through our sensitive-data classifier to tell you whether it's noise or a real problem.
2026 security research found hundreds of apps built with these tools exposing full user records because of a single security policy left off. The pattern keeps repeating because AI tools generate the connection to the database, but don't always turn on the permission layer.
Lovable itself is a legitimate, widely used platform. The risk isn't the platform — it's that apps it generates connect to a Supabase database, and Supabase requires you to turn security rules on explicitly. When that step is skipped, anyone can read the data through the app's own public connection.
A documented vulnerability where more than 170 live Lovable apps — about one in ten scanned at the time — had inadequate Row Level Security on their Supabase backend, letting unauthenticated visitors read data like names, emails, and in some cases financial details. It was assigned a CVSS score of 9.3, in the critical range.
A separate issue let any free Lovable account read other users' project source code, database credentials, and chat history for projects created before November 2025. It was patched, but it's a reminder that this class of issue keeps recurring across AI app builders, not just Lovable.
Use the free scanner above. Paste your Supabase project URL and its public anon key (both are already visible in your app's own browser code, in Project Settings → API on Supabase). The scan checks, read-only, whether common tables and storage buckets are readable without logging in.
No. The scan only reads what's already publicly reachable from any visitor's browser, never writes or modifies anything, and doesn't store the data values it finds — only whether a table responded and how sensitive the response looked.
This scanner performs read-only checks against publicly reachable Supabase endpoints, using the anonymous key already exposed in your app's client-side code.
You may only scan a project you own, or one you have explicit permission to test. Scanning a third party's project without authorization is not permitted, and access attempts are logged.
If you purchase a fix, we will never ask for your service_role key as a first step. You'll receive the exact SQL to run yourself in your own Supabase SQL editor, with guidance, and we re-verify the result using the same read-only scan. Hands-on access, if ever needed, is granted temporarily and only with your explicit approval.
Results are best-effort and based on common table names and default configurations. A clean scan does not guarantee your application has no security issues — it is not a substitute for a full professional security audit.
Paid reports and fixes are processed by a third-party payment provider. We do not receive or store your card details.
We may keep anonymized, aggregate figures (for example, "X% of scanned tables lacked a security policy") for research and public write-ups. These never identify your project or organization.
You can request deletion of any contact information we hold about you at any time by reaching out through the contact details provided at checkout.
TrustBoost provides an automated, best-effort security scan for Supabase-backed applications, plus optional paid detailed reports and remediation.
The scan and any report are provided "as is," without warranty of completeness or accuracy. They do not constitute a professional security audit or legal compliance certification.
To the maximum extent permitted by law, TrustBoost is not liable for indirect, incidental, or consequential damages arising from use of this tool or reliance on its results.
Paid reports and fixes are one-time purchases. Refund terms are shown at checkout before payment.
These terms are governed by the laws of Colombia, without regard to conflict-of-law principles.