Local Scanner for Security Gaps in Lovable, Bolt, and Replit AppsLocal Scanner for Security Gaps in Lovable, Bolt, and Replit Apps
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Ergin's avatar
pro
• 2h
I turned the checks I run on Lovable, Bolt and Replit apps into a small scanner.
Run one command in your app's folder and it lists the gaps that expose data or money, file by file: keys that end up in the browser, the Supabase service role in client code, tables without row-level security, Stripe webhooks nobody verifies, AI routes anyone can call.
It runs locally, has no dependencies, never uploads your code, and masks every key it finds. Add --ci and it fails the build when anything is red.
It is heuristics, not a guarantee. But it catches the things I look for in the first hour of an audit.
What is the first thing you check before a launch?
Post image
Post image
TRUEFRAME logo
what does it flag most on lovable apps? im guessing exposed keys
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started