/tools · 7IT Guard · with Lovable

Using Lovable? 7IT Guard checks and watches your Lovable app.

Lovable builds and publishes the app. 7IT Guard checks the published app from the outside, the way a stranger would see it, and tells you what to fix before real users arrive.

7IT is not affiliated with or endorsed by Lovable. Lovable is a trademark of its owner.

Get started now

Install it and run it, from where you work today.

  1. Open Claude Code

    Lovable runs in your browser; Claude Code runs on your computer. Open it in a terminal, in VS Code or Cursor with the Claude Code extension, or in the Claude desktop app. (Cloud sessions in the browser do not load plugins you installed.) Source: code.claude.com

  2. Install 7IT Guard

    Add the marketplace and install the plugin. It needs Node.js 18 or newer and nothing else; no account.

    /plugin marketplace add XLSV777/7it-guard /plugin install 7it-guard@7it-guard
  3. Find your Lovable app’s live address

    In Lovable, click Publish at the top right, then Publish again. The app goes live at an address like your-app.lovable.app (or your own domain on a paid plan). Source: docs.lovable.dev Copy that address. That is what 7IT Guard checks.

  4. Run the check

    Run the command with your address, or ask Claude: "Is my app at your-app.lovable.app ready to ship?" You get a grade, a score per category, a ranked fix list and a link to the visual report.

    /7it-guard:check your-app.lovable.app

Cursor, Codex and ChatGPT plugin listings for 7IT Guard are coming soon. Until then, Claude Code is the way in.

Unlock the deep checks

Show it is your app.

The deep checks (exposed files, keys in the browser code, what anyone can read in your database) run only on an app that carries your ownership token. The simplest way on Lovable is to ask it in the chat. The token is inert: it only proves you can change the app. The report prints it.

  1. Ask Lovable: "Add this meta tag to the head of every page: <meta name="7it-site-verification" content="7it-verify-...">" with the token the report printed, then publish again.

  2. Prefer to do it by hand? Apps Lovable created before May 13, 2026 use React and Vite: the tag goes in the head of index.html, or the token goes in a file at public/7it-verify.txt. Newer apps use TanStack Start: the tag goes in the head() of the root route. Lovable syncs both ways with GitHub on every plan, so you can also make the change in the repository. Source: docs.lovable.dev

  3. Run the check again. Claude adds --owner once you say the app is yours.

<meta name="7it-site-verification" content="7it-verify-...">
On Lovable

What it catches on your stack.

7IT GuardTables anyone can read

Row Level Security left off is the classic Lovable and Supabase gap. CVE-2025-48757 described Lovable sites through April 2025 where unauthenticated visitors could read or write database tables (Lovable disputes the record, saying each customer is responsible for their own data). On your own app, Guard lists the tables and storage buckets an anonymous visitor can read, by name and row count, never contents. Source: nvd.nist.gov

7IT GuardKeys in the code sent to browsers

A service key or an AI key that ended up in the front end, reported by type and file, never the value.

Guard Pro, opening soonOpen sign-ups and AI endpoints that run up a bill

Anyone can create an account, or call an AI feature without signing in. Guard Pro checks this weekly.

Guard Pro, opening soonA Supabase project that went to sleep

Supabase pauses projects on its no-cost plan after a week of inactivity. Guard Pro notices when the project stops answering and Help shows how to restore it. Source: supabase.com

Lovable runs its own security scan before every publish, inside the builder. 7IT Guard is a second look from the outside, at what the published app actually serves, and keeps looking after every change. Source: docs.lovable.dev

After launch

Guard Pro keeps watching your Lovable app.

Checks every 5 minutes from outside, what changed at every publish in plain words, bill blowup checks, provider outage alerts and the control room app on your phone. It opens soon.

Questions

Lovable and 7IT Guard.

Does it replace Lovable’s security scan?

No. Lovable scans inside the builder before you publish. 7IT Guard checks the live app from the outside, the way a visitor or an attacker sees it. They answer different questions; use both.

My Lovable app uses Lovable Cloud, not my own Supabase. Does the database check still work?

The outside checks work on any published app. The database part reads what the app’s own code points at; when that is a Supabase project, it checks it with the app’s public key, read-only, names and counts only.

Do I need to leave Lovable?

No. You keep building in Lovable. You run 7IT Guard from Claude Code on your computer against the published address.