/fix · base44

Is my Base44 app secure?

Base44 gives an app its hosting, its data tables and its sign-in in one place. Who may read, create, change or delete each record is a rule you set per table, and it is the part to check before launch.

What Base44 handles.

  • ✓Hosting, user sign-in and a built-in database
  • ✓Permission rules per data table, at record level and field level
  • ✓A security scan in the dashboard covering seven issue types, from data permissions to exposed secrets and security headers
  • ✓One-click fixes from the scan, with a checkpoint before each change

From the platform’s own documentation: Base44 docs: Running a security scan · Base44 docs: Managing data permissions

What stays yours.

  • →The permission rule on every table: who can create, read, update and delete
  • →Which tables are open to people who have not signed in
  • →Backend functions that check who is calling before returning data
  • →Keys for paid services kept out of what visitors can load
  • →Whether the app itself is public or requires sign-in

Documented.

Public reports that involve Base44 or apps built on it, dated and linked. Each line says what its source says, and nothing more.

  1. July 29, 2025An authentication bypass on private Base44 apps

    Wiz Research found that the public app_id alone let anyone register a verified account on a private Base44 app through two undocumented endpoints. Reported on 2025-07-09, fixed by Wix within 24 hours, with no evidence of exploitation; disclosed 2025-07-29.

    Source: Wiz Research, July 29, 2025
  2. May 7, 2026About 380,000 public assets built with AI coding tools

    eWeek reports that Red Access found about 380,000 publicly accessible assets created with AI coding tools, on platforms including Lovable, Replit, Netlify and Base44, and that around 5,000 of them exposed potentially sensitive information such as medical and financial records.

    Source: eWeek, May 7, 2026

A five minute check.

In your own Base44 dashboard, in this order.

  1. Run the security scanIn the app editor, open Dashboard, then Security, then Run Security Scan. Read data permission findings first.
  2. Open each table’s permissionsSelect a data table and click Permissions. Read the rule for Read, Update and Delete, not only Create.
  3. Look for All Users on private dataAll Users means anyone, even without signing in. Orders, messages and profiles should be Creator Only or matched to a user field.
  4. Check backend functionsAny function that returns data should confirm who is asking. The scan flags functions that answer without a signed-in user.
  5. Confirm who can open the appIn the app’s access settings, check whether it is public or limited to invited people, and that this matches the data inside.

Questions.

Was the 2025 Base44 issue fixed?

Yes. Wiz Research reported it on 2025-07-09; Wix fixed it within 24 hours and found no evidence of exploitation. It was a platform issue, separate from the permission rules each app owner sets.

What does Creator Only actually mean?

Per Base44’s docs, a person can only access the records they created. It suits personal data such as orders or submissions. Shared records need a field-based rule instead.

Can the scan fix everything for me?

It fixes what it can recognize. It cannot know that a table holding customer notes should never be visible to other customers unless the rule says so. Reading the rules against the business is the human part.

Check the public side now.

Ten seconds. We read only what any visitor’s browser already sees, and store nothing.

Opens the app security check on this site with your address filled in.