When you scan an App URL, SafeWeave checks your deployed app from the outside, the way anyone on the internet can see it.
Live checks only read, they never change anything. They use only the keys your app already ships publicly, never write, update or delete anything, and keep none of the data they read: findings name tables, buckets and files, never their contents.
The checks for open databases, storage, exposed keys and AI routes run on Cloud and Cloud Plus. See App URLs for how to scan.
AI route answers without sign-in
Severity: High
How to fix: Require sign-in on the route, add a per-user rate limit, and cap how much each request can use.
API documentation is public
Severity: Medium
How to fix: Only publish API documentation in development, or put it behind sign-in.
API routes return personal data without sign-in
Severity: Critical
How to fix: Require sign-in on these routes and return only the signed-in user's own records.
Anthropic API key visible in your website code
Severity: Critical
How to fix: Rotate the Anthropic API key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
AWS access key visible in your website code
Severity: Critical
How to fix: Rotate the AWS access key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Google service account key visible in your website code
Severity: Critical
How to fix: Rotate the Google service account key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
GitHub token visible in your website code
Severity: Critical
How to fix: Rotate the GitHub token now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Mapbox secret token visible in your website code
Severity: Critical
How to fix: Rotate the Mapbox secret token now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
OpenAI API key visible in your website code
Severity: Critical
How to fix: Rotate the OpenAI API key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Private key visible in your website code
Severity: Critical
How to fix: Rotate the private key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Resend API key visible in your website code
Severity: Critical
How to fix: Rotate the Resend API key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
SendGrid API key visible in your website code
Severity: Critical
How to fix: Rotate the SendGrid API key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Slack token or webhook visible in your website code
Severity: Critical
How to fix: Rotate the Slack token or webhook now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Stripe secret key visible in your website code
Severity: Critical
How to fix: Rotate the Stripe secret key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Supabase service key visible in your website code
Severity: Critical
How to fix: Rotate the Supabase service key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Twilio API key visible in your website code
Severity: Critical
How to fix: Rotate the Twilio API key now, remove it from your front-end code and public environment variables, and use it only from your server or an edge function.
Any website can read signed-in responses (CORS)
Severity: High
How to fix: Allow only your own website addresses in your CORS settings when cookies or credentials are allowed.
Debug or admin pages answer without sign-in
Severity: High
How to fix: Remove debug pages from production and require an admin sign-in, checked on the server, for admin pages.
Secret settings embedded in the page
Severity: High
How to fix: Stop sending server settings to the browser; send only public values, and change the secrets that were exposed.
Database or site backups can be downloaded
Severity: Critical
How to fix: Delete the backup files from your website, treat their contents as leaked, and change any passwords or keys they held.
/.env can be downloaded
Severity: High
How to fix: Remove /.env from what you deploy (or block it on your host) and change any secrets it contained.
/.env.local can be downloaded
Severity: High
How to fix: Remove /.env.local from what you deploy (or block it on your host) and change any secrets it contained.
/.env.production can be downloaded
Severity: High
How to fix: Remove /.env.production from what you deploy (or block it on your host) and change any secrets it contained.
/firebase.json can be downloaded
Severity: High
How to fix: Remove /firebase.json from what you deploy (or block it on your host) and change any secrets it contained.
/supabase/config.toml can be downloaded
Severity: High
How to fix: Remove /supabase/config.toml from what you deploy (or block it on your host) and change any secrets it contained.
/.vercel/project.json can be downloaded
Severity: High
How to fix: Remove /.vercel/project.json from what you deploy (or block it on your host) and change any secrets it contained.
The .git folder can be downloaded
Severity: High
How to fix: Block the .git folder on your host or remove it from what you deploy, and change any secret that was ever committed.
Firestore collections are readable by anyone
Severity: Critical
How to fix: Update your Firestore rules so each collection needs a signed-in owner, then publish the rules.
Realtime Database is readable by anyone
Severity: Critical
How to fix: Replace the open rules in your Realtime Database with rules that only let each user read their own data.
Storage bucket lists its files to anyone
Severity: Critical
How to fix: Update your Firebase Storage rules so files can only be read by their owner, then publish the rules.
GraphQL schema is public
Severity: Medium
How to fix: Turn off GraphQL introspection in production and require sign-in on the endpoint.
Links on your site can redirect to any website
Severity: Medium
How to fix: Only redirect to pages on your own site; reject full web addresses in redirect parameters.
Source maps are public
Severity: Medium
How to fix: Stop publishing source map files in production builds, or upload them only to your error tracker.
Public storage buckets
Severity: High
How to fix: Make the bucket private unless every file in it is meant to be public, and serve private files with signed links.
Database functions anyone can call
Severity: Medium
How to fix: Remove access to these functions for signed-out users, and check who is calling inside each function that changes or reveals data.
Anyone can sign up without confirming an email
Severity: Medium
How to fix: Turn on email confirmation in your Supabase Auth settings and add a CAPTCHA to sign-up.
Database tables are readable by anyone
Severity: Critical
How to fix: Turn on Row Level Security for these tables in Supabase and add policies that only let people read their own rows.