Observed arrival · 2026-08-25
RowShield’s Supabase hole detector
A read-only security scanner for AI-built Supabase apps, checking public bundles, RLS policies, exposed keys, storage, and schema drift.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
Field notes
The audit starts from a deployed app URL and can optionally use an anon or publishable Supabase key; the page explicitly warns against supplying a service_role key. Its stated scan path uses only GET, HEAD, and OPTIONS requests, does not write to the database, and says entered values and rows are not stored. The sample output covers 12 tables, identifies two critical findings, and supplies SQL for enabling RLS on an exposed table.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
⊠LoginAccess appeared gated
$PaidCommerce or pricing visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue