Skip to the card

Card 717 of 10002026-08-25 issue

Observed arrival · 2026-08-25

RowShield’s Supabase hole detector

rowshield.dev Observed source
Editorial interest 84/100 Selection signal · not a rating of the site

A read-only security scanner for AI-built Supabase apps, checking public bundles, RLS policies, exposed keys, storage, and schema drift.

Landing page captured for the 2026-08-25 issue.

Field notes

The audit starts from a deployed app URL and can optionally use an anon or publishable Supabase key; the page explicitly warns against supplying a service_role key. Its stated scan path uses only GET, HEAD, and OPTIONS requests, does not write to the database, and says entered values and rows are not stored. The sample output covers 12 tables, identifies two critical findings, and supplies SQL for enabling RLS on an exposed table.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

LoginAccess appeared gated
$PaidCommerce or pricing visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Thirty-One Wells, Not Four

295,249 arrived 1,000 judged 1000 catalogued Enter the complete issue
rowshield.dev

Landing page observed 2026-08-25. The live site may have changed.