Be the bug
to find the bug.
Paste your app URL. Get an instant security report. Fix vulnerabilities before attackers find them. Built for apps made with Lovable, Bolt, and v0.
3 free scans per month. No credit card required.
80% of Lovable apps have critical security issues
Most apps built with AI tools ship without Row Level Security. This means all data is publicly accessible to anyone with the Supabase URL.
What Aphido scans
Real browser-based scanning with Playwright. Not just static analysis — we test your live app like an attacker would.
Missing RLS Detection
Find tables without Row Level Security — the #1 vulnerability in Supabase apps. Anyone can read ALL your data.
Exposed Credentials
Detect Supabase URLs and API keys leaked in frontend JavaScript. Attackers use these to access your database directly.
PII Exposure
Scan for personal data (emails, phone numbers, BSN, credit cards) accessible without authentication.
Storage Buckets
Check for publicly accessible storage buckets containing sensitive files, user uploads, or private documents.
Performance Audit
Core Web Vitals, load time, and bundle analysis. Know your FCP, LCP, and TTFB before your users complain.
Accessibility Check
WCAG 2.1 AA compliance scan. Make sure your app works for everyone, including screen reader users.
How it works
Paste your URL
Enter the URL of your Lovable, Bolt, or v0 app.
We scan everything
Playwright loads your app, intercepts network traffic, and tests for vulnerabilities.
Fix with confidence
Get actionable findings with SQL commands you can copy-paste to fix each issue.
Why Aphido?
Generic security scanners don't understand Supabase. Aphido was built specifically for apps made with AI tools.
| Feature | Generic scanners | Aphido |
|---|---|---|
| Deep Supabase scanning | ||
| RLS bypass detection | ||
| Dutch PII detection (BSN) | ||
| Auto-fix commands | ||
| Full audit (security + a11y + perf) | partial | |
| Free tier | limited |
Security Guides
Learn how to secure your app with our free, in-depth guides.
Don't ship insecure apps
Scan your Lovable, Bolt, or v0 app in 60 seconds. Free.