Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for Lovable
Lovable makes building fast. We check what it published: exposed keys, open Supabase tables, missing headers, with fix prompts you paste back into Lovable.
Free. No signup. Read-only checks from the outside.
Lovable apps usually run on Supabase. Scanning works for every Lovable app, whatever the backend.
We search the JavaScript Lovable generated for keys that should never be public.
If the app uses your own Supabase project, we test its Row Level Security with the public key.
Every critical finding has a prompt written for Lovable's chat.
Lovable Cloud databases live inside Lovable's own account, so Vigavo cannot connect to them for backups. Scanning and monitoring still work fully. To get backups, connect the app to your own Supabase project (or export your data from Lovable), then connect that project to Vigavo.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No. Lovable Cloud gives no outside database access. Scans and monitoring work; backups need your own Supabase project.
No. Enter the published URL and scan.
Yes, they are plain English instructions with the exact table, file or header to change.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.