GuardCue

Is my Lovable app safe to launch?

Paste your address. We check your live Lovable app the way a stranger would, then tell you in plain English what could cost you money, and how to fix it.

Free. No sign-up. We only look at what any visitor can already see.

Could end your business

Anyone on the internet can read your customer list.

what we didasked your site for its customer list, without signing in
what it showedthe whole table, with names, emails and phone numbers
What it means for youNo login, no password, no attacker needed. Someone who finds the address copies the whole table. This is the kind of leak you may have to tell every customer about.
This is how every finding is written. No jargon, ever.
About Lovable

Working is not the same as safe.

Lovable turns a description into a working web app, and it is one of the most popular tools for founders who do not write code. It is genuinely good at producing an app that looks and works right, which is the problem: nothing about a working app tells you which doors are open.

Where your data livesLovable apps keep their data in Supabase, and ship a public key to every visitor. That key is meant to be public and is safe on its own. Everything depends on whether each table has a rule about who may read it.
What we find

The faults we find in Lovable apps.

Written the way your own report would write them. These live in the app Lovable built for you, not in Lovable’s own service, which is why only a check of your app answers it.

Could end your business

Anyone on the internet can read your customer list.

What it means for youNo login, no password, no attacker needed. Someone who finds the address copies the whole table. This is the kind of leak you may have to tell every customer about.
what we didasked your site for its customer list, without signing in
what it showedthe whole table, with names, emails and phone numbers
Could end your business

Every customer can read every other customer's records.

What it means for youOne curious user is enough. You never notice, because you only ever look at your own account, and from the inside the app looks exactly right.
what we didmade a new account that owned nothing, then opened the dashboard
what it showedfour records that were not ours
Could end your business

Your master key is in the code every visitor downloads.

What it means for youThat key ignores every rule you set about who may see what. Anyone who looks can read, change or delete everything you hold, including every customer record.
what we didread the code your site hands to every browser
what it showeda master key, in a file any visitor can open
The honest part

What this check cannot see.

Every scanner looks cleaner if it stays quiet about what it missed. We would rather tell you.

Could not checkFrom outside we cannot see tables that are only reachable once someone is signed in. To check those we sign in as a test user, which needs you to prove the site is yours first. If a check could not run, your report says so in those words instead of showing a clean result you did not earn.
What has happened before

A real case, on the record.

In May 2025 researchers reported a pattern, tracked as CVE-2025-48757, in which 170 of 1,645 Lovable apps they scanned had databases a stranger could read or write, because of missing table rules. Lovable added warnings and checks in response. The fault was in the apps, not in Lovable’s own servers, which is exactly why a check of your own app is the only thing that tells you whether yours is one of them.

Source: CVE-2025-48757, reported by Matt Palmer and Matan Getz, May 2025