Vigavo for Bolt

Built with Bolt?We stay awake.

Bolt apps often go live with keys in the frontend and an open database. Find out in a minute, for free.

Free. No signup. Read-only checks from the outside.

What we check on Bolt

We check the deployed app, wherever Bolt published it, and the Supabase or Firebase backend behind it.

  1. Keys in the frontend

    API keys for OpenAI, Stripe and others in the bundle are found and redacted in the report.

  2. Backend rules

    Supabase RLS and Firebase rules are tested with the public config only.

  3. Headers and TLS

    Missing security headers, weak TLS and mixed content.

Everything a small team forgets to check

Findings ranked by what an attacker would try first, with the fix right next to each one.

Scan like an attacker, safely

Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.

Watch for changes

Scheduled scans compare against the last result, so you hear about a new leak once, not every day.

Backups that restore

Encrypted database snapshots, verified by an actual restore and row counts.

Fix prompts

Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.

Alerts without noise

Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.

Questions

Do you need my Bolt account?

No. Only the public URL.

Can you back up the database?

Yes, if it is a Supabase or PostgreSQL database you can connect with a read-only user.

Is the scan safe for a live app?

Yes. A handful of read-only requests, rate limited.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

What do you store?

The scan result. Free scans are deleted after 30 days.

Feedback
Type