Supabase RLS & security checks

Supabase RLS checker: find tables anyone can read

Connect Supabase and SafeWeave reads its security checks for the projects you choose: tables without Row Level Security, policies that are ignored, views that bypass RLS and more. Read-only, checked once a day.

Supabase connection on Cloud and Cloud Plus · read-only · checked daily

Why it matters

Your Supabase key is public. Row Level Security is what protects your data.

Apps built on Supabase ship a public key in the browser. That’s by design, as long as Row Level Security is on and its policies only allow the rows each user should see. When RLS is off on a table, anyone with that key can read and write every row. Tables anyone can read are one of the mistakes AI app builders make again and again, and nothing in the app looks wrong.

How SafeWeave Solves It

What you get

  • A grade for each Supabase project, with each finding’s fix and a link to Supabase’s guide.

  • A check straight away, then once a day, with an email when a new critical issue appears.

  • Critical and high findings in Fix first on your Overview, and each project in your weekly security email.

  • Read-only: SafeWeave never changes your project and never reads the data in your tables.

What it checks

Supabase’s security advisors, as findings you can fix

Tables without Row Level Security

Tables in the public schema with RLS off, so anyone with your public key can read and write every row. Marked critical.

Policies that are ignored

Tables that have policies while RLS is off, so the policies do nothing. Marked critical.

auth.users and sensitive columns exposed

auth.users reachable through a view or function, and sensitive columns in tables the API exposes. Marked critical.

Views that bypass RLS

Views created as security definer, which ignore the caller’s Row Level Security.

Functions with an unsafe search path

Functions without a fixed search_path, so a caller can shadow the objects they use.

Policies that trust user_metadata

Policies that read user_metadata, which users can change themselves.

Other security advisor findings are shown too, with Supabase’s own guide for each. Supabase projects are graded on their own and don’t change your repository score.

Also in your code and live app

Supabase mistakes SafeWeave finds without the connection

In your code

The Supabase code checks flag code that turns RLS off, policies with USING (true), the service_role key in browser code or a public env var, public storage buckets, and Edge Functions that use the service_role key without checking the caller. Full findings are on Cloud and Cloud Plus; Free shows the grade and finding counts.

In your live app

On Cloud and Cloud Plus, an App URL scan runs live app checks using only the key your app already ships: tables readable by anyone, public buckets, database functions anyone can call, sign-ups without email confirmation and Supabase service keys in your website code.

How to connect

Connect Supabase in five steps

  1. 1
    In the SafeWeave sidebar, click Integrations.
  2. 2
    On the Supabase card, click Connect Supabase.
  3. 3
    Supabase asks you to choose an organisation and approve SafeWeave. Approve it.
  4. 4
    Back on Integrations, tick Monitor next to each project you want checked. SafeWeave checks it straight away.
  5. 5
    Click a project’s name to open its grade and findings.

Full guide, limits and troubleshooting: Supabase RLS & checks.

Built with an AI builder?

Lovable, Bolt, v0 and Replit apps on Supabase

FAQ

Common questions

What does the SafeWeave Supabase RLS checker check?

It reads Supabase’s own security checks (the security advisors) for the projects you choose: tables without Row Level Security, policies that are ignored because RLS is off, views that bypass it, functions with an unsafe search path, exposed auth.users and more. Each project gets a grade and a list of findings with how to fix them and a link to Supabase’s guide.

Can SafeWeave read or change my Supabase data?

No. SafeWeave only reads Supabase’s security checks for your project. It never changes your project and never reads the data in your tables. Disconnecting deletes its access straight away.

Which plans include the Supabase connection?

Cloud ($29/month, with a 14-day free trial) and Cloud Plus ($59/month). You can monitor as many Supabase projects as your plan allows repositories: 5 on Cloud, 15 on Cloud Plus.

How often are my Supabase projects checked?

Straight away when you start monitoring a project, then once a day. You can click Check now on the project’s page at any time. If a check finds a new critical issue, you get an email. If Supabase doesn’t answer, the check is marked as not finished and the previous results stay; it is never shown as clean.

Check your Supabase projects

Create a free account, start a 14-day Cloud trial and connect Supabase from Integrations.

Create a free accountView on GitHub