What people actually found in Lovable apps
This is not hypothetical. A study of 170+ Lovable apps found recurring Supabase misconfigurations, and a developer who queried 50 Lovable-built databases directly found most with no Row Level Security. r/vibecoding threads describe real apps shipping with Supabase keys in the client bundle. Lovable itself has shipped fixes (CVE-2025-48757 affected 170+ apps) — the platform improves, but your app's database policy is still your problem.
The five patterns that decide it
- 1. Your database trusts the anonymous key. Supabase creates tables with RLS off. If nobody enabled it and wrote policies, anyone with your public anon key reads every row. → the RLS check, permissive-policy check
- 2. A server key rode along into the browser. The service-role key bypasses all policies; it must never appear in client code or bundles. → service-role-key check, bundle-secrets check
- 3. Routes that work for everyone. API routes and admin pages that demo fine because you were logged in — but never check. → authless-route check, open-admin check
- 4. Secrets committed along the way. The
.envthat made it work, committed "temporarily". → committed-env check, git-history check - 5. No rate limits anywhere. Auth and paid endpoints open to unlimited attempts. → auth rate-limit check
The two-minute version
You do not need to read all twelve of those pages — that is what the scan is for. Point DevMeth at your repo or live URL and it runs the Critical checks deterministically, masks everything, and hands you a fix prompt you can paste straight back into Lovable. Then re-scan to confirm the fix landed.