Scan Lovable, Bolt, v0 & Replit apps for security issues

How to scan apps made with Lovable, Bolt.new, v0, Replit, Base44, Retool, UI Bakery and Bubble.

What it is

SafeWeave checks apps made with AI and no-code builders in two ways:

  • The code, through the GitHub repository your builder syncs to. Every push is scanned, including the checks for mistakes these builders often make with Supabase, Firebase, Next.js and AI features.
  • The live app, through an App URL scan of the address it's deployed at.

You don't connect the builder itself. If your builder can put your project on GitHub, use both; if it can't, scan the live app.

For what to watch for in each builder's apps, see Lovable, Bolt.new, v0 and Replit security, or the vibe coding security checklist.

Who gets it

Every plan. Free connects one repository and shows the grade and finding counts; Cloud and Cloud Plus show every finding with its fix, and run the live app checks for open databases, storage and keys. See Choosing a plan.

How to use it

For a builder that syncs to GitHub:

  1. In your builder, turn on its GitHub sync so your project lives in a GitHub repository you own.
  2. In SafeWeave, connect GitHub if you haven't, then go to Repositories, click Connect repository and pick that repository.
  3. Click Scan now, or wait for your next change: each sync is a push, and every push is scanned.
  4. Go to App URLs, click Scan an app URL and enter the address your app is deployed at. See App URLs.

The builders are listed under Apps built with AI builders on the Integrations page, with buttons for each step.

Lovable

In Lovable, open Project settings → Git, and on the GitHub card click Connect. Lovable creates a repository and keeps it in sync with your project. Connect that repository in SafeWeave. Lovable apps often use Supabase: the code checks and the live app checks both look for tables without Row Level Security and keys exposed to the browser. On Cloud and Cloud Plus, also connect Supabase to check the database itself.

Bolt.new

In Bolt.new, click the GitHub icon at the top right, click Log in to GitHub and choose which repositories Bolt can use. Bolt keeps the repository in sync with your project. Connect that repository in SafeWeave, and scan the URL your app is published at too.

v0

Push your v0 project to GitHub, then connect that repository. v0 apps usually deploy to Vercel: scan the Vercel URL as an App URL.

Replit

Connect your Repl to a GitHub repository from Replit's Git tools, then connect that repository in SafeWeave. Scan the URL your Repl is deployed at.

Base44

In Base44, click the GitHub icon at the top right of the editor, click Connect to GitHub, authorize Base44 and create a repository. Connect that repository in SafeWeave, and scan your app's live URL.

Retool

If your Retool apps are kept in a GitHub repository with Retool's source control, connect that repository. Scan any public URL your app is served at.

UI Bakery

If you keep your UI Bakery app in GitHub with UI Bakery's Git integration, connect that repository. Scan the URL of your live app too.

Bubble

Bubble doesn't export code. Scan the URL of your live Bubble app as an App URL.

What you'll see

Your builder's repository appears on Repositories with its grade, and your app appears under App URLs and on the Overview under Your apps.

Limits

  • SafeWeave scans the code on your default branch. If your builder pushes to another branch, change the repository's default branch on GitHub or merge into it.
  • Free includes one connected repository.

If something goes wrong

  • The repository isn't in the list: check that your builder's GitHub sync finished and that your GitHub account can open the repository. See Connect GitHub and add repositories.
  • No new scans after a change: check the change reached GitHub. A scan runs on each push.
  • The App URL scan didn't finish: check the address opens in your browser, then click Try again.