Scan like an attacker, safely
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Vigavo for Supabase
We check whether your anon key can read or write tables it should not, list your public buckets, and back up your Postgres database every day.
Free. No signup. Read-only checks from the outside.
Most Supabase leaks are a missing or too-open Row Level Security policy. We test it the way an attacker would, with your public anon key only.
Tables readable or writable with the anon key are flagged with the exact table name and a policy skeleton.
Public buckets that list their files are reported, with what can be listed.
Connect in one click with a read-only role. Each snapshot is restored on our side to prove it works.
Findings ranked by what an attacker would try first, with the fix right next to each one.
Exposed .env and .git files, secrets in JavaScript bundles, Supabase and Firebase rules, TLS, headers, email spoofing and more.
Scheduled scans compare against the last result, so you hear about a new leak once, not every day.
Encrypted database snapshots, verified by an actual restore and row counts.
Each critical finding comes with a prompt you can paste into Cursor, Claude Code, Lovable or Bolt.
Deduplicated alerts, daily or weekly digests, and a clear grade from A to F.
No. Read probes only. The write probe is off unless you authorize it for your own project, and it cleans up after itself.
Only the public anon key your site already ships to every visitor. Never your service role key.
The database backup includes the public, auth and storage schemas. File backups of Storage buckets are on the roadmap.
Yes. We only make the same read-only requests any visitor's browser could make. Nothing is changed and nothing is exploited.
The scan result. Free scans are deleted after 30 days.