vibecode/auditOWASP LCNC Top 10
free · read-only · no signup

You shipped the app.
Did you ship it wide open?

Bubble, Glide, Webflow and Supabase make shipping easy — and leaking your whole database just as easy. Run an instant, attacker's-eye scan. No code knowledge required.

scan targetread-only
01
02# paste a public URL, hit run — surface scan is instant & read-only

Only scan apps you own or are authorized to test.

commonly caught:sk_live_… leaked in client bundle
detectsBubbleGlideWebflowSoftrSupabaseFirebase