Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for Bolt
Bolt apps often go live with keys in the frontend and an open database. Find out in a minute, for free.
Free. No signup. Read-only checks from the outside.
We check the deployed app, wherever Bolt published it, and the Supabase or Firebase backend behind it.
API keys for OpenAI, Stripe and others in the bundle are found and redacted in the report.
Supabase RLS and Firebase rules are tested with the public config only.
Missing security headers, weak TLS and mixed content.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No. Only the public URL.
Yes, if it is a Supabase or PostgreSQL database you can connect with a read-only user.
Yes. A handful of read-only requests, rate limited.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.