Vigavo for Bubble

Your Bubble app, checked.We stay awake.

Bubble runs the servers and the database. We check what you control: email DNS, your domain, plugins and the keys your app exposes.

Free. No signup. Read-only checks from the outside.

What Vigavo checks on your Bubble site

Plugins and API Connector calls marked as client-side send their keys to every visitor's browser. We look for exactly that.

  1. Security check

    Exposed keys in your custom code and embeds, email spoofing protection, domain expiry, risky subdomains, blacklists and mixed content.

  2. Change alerts

    We re-check on a schedule and tell you when something new appears, by email, Telegram, Slack or webhook.

  3. An honest grade

    Settings that Bubble controls are shown separately and never lower your grade.

Managed by Bubble

Bubble runs the servers: security headers, TLS certificates, server software and compression are set by Bubble for every site. Your report lists them under "Managed by Bubble" so you know what they are, without asking you to fix them.

What you can fix

  • ✓ Email DNS: SPF, DKIM and DMARC so nobody can send mail as you
  • ✓ Your domain: renewal date, transfer lock, subdomains
  • ✓ Content: search visibility, link previews, broken links
  • ✓ Third-party apps, scripts and embeds you added

Tip: privacy rules decide who can read your data types; review them whenever you add a new type.

Questions

Why don't missing security headers lower my grade on Bubble?

Bubble sets them for every site it hosts and gives you no way to change them. We show them under "Managed by Bubble" and grade only what you can influence.

Do I need to install anything on Bubble?

No. Paste your address and the check runs from the outside, like a visitor's browser. Nothing is added to your Bubble site.

What happens when something changes?

We compare every scan with the previous one and alert you about new issues. If Bubble changes a security setting on its side, you get one short notice.

Is the scan safe for my site?

Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.

Feedback
Type