A static security review of a Supabase project: missing Row Level Security, policies that allow everyone, and missing write policies. Findings are explained in plain English with a fix you can paste into your editor. This preview never uses a review credit and never touches a live site. The full independent review is a separate step.
Your code never leaves your control. Your project is scanned the moment you upload it, and the files are discarded immediately afterward — nothing is stored, kept, or used to train anything.
Pick your project folder. We only read .sql, .toml, .json, and .example files — everything else (including node_modules) is skipped in your browser and never uploaded. The scan runs, then your files are discarded.
The scan looks at your database access rules, which live in your SQL migration files. That is almost always the supabase/migrations folder — the .sql files inside it are the whole point.
supabase/migrations.supabase/migrations folder instead of the project root so you stay under the file limit.No Supabase project? The scan needs Supabase-style migration files; if yours are named differently, upload the folder that holds your .sql schema changes.
Only works for a path the server can reach. Uploaded scans are not monitored; a server-reachable path can be re-scanned by a monitoring subscription.
Ready. Choose your project folder to run the scan.