Study: 1,072 Supabase-backed apps built with AI tools scanned
Source: Symbiotic Security, June 2, 2026. Written by Lior Aharonov, updated October 3, 2026.
What happened.
Symbiotic Security scanned 1,072 apps that use Supabase, built with Lovable, v0, Bolt.new, Replit and Windsurf.
It reports that 98% had at least one security vulnerability.
308 sites exposed the Supabase anon key in JavaScript, 172 allowed data to be changed or deleted without signing in, and 197 had a CORS misconfiguration on the Supabase API.
This is a study of deployed apps, not a single breach.
Why it happens.
Each builder produces a working app quickly, and the database rules are the part that works in a demo either way. An open table still loads, and a missing policy shows no error. The gap appears only when someone outside the app sends a request the interface never would.
How to check yours in five minutes.
- Confirm RLS is on for every table, and read each policy for insert, update and delete as well as select.
- Try a write while signed out, from the browser console, against a table that should refuse it.
- Check the CORS settings on any API you control.
- Search the published scripts for any key other than the public one.
- Run the public scan on your app.
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
Symbiotic Security ↗
Published June 2, 2026. Read it in full; this page summarizes only what it reports.
How it works, in four steps.
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →