Gallery
About
Sentris scans your Supabase repo, not just the live URL — the two are not the same thing. Missing RLS policies, service_role keys hardcoded in source, public storage buckets, routes that take an id and never check who is asking, security definer functions anyone can call. Every finding comes with masked evidence, the exact line, row counts, status codes — and a copy-paste fix. I scanned 2,144 public vibe-coded repos while building it: 40.6% had a critical exposure. Free scan, no login.
Comments (2)
Finally someone scanning the repo not just the live URL.
wonder how many false positives it throws on those service_role key scans
Related Products
Reswardo — Bóveda privada para tu legado digital
Reswardo — Production-ready encrypted digital legacy and continuity SaaS
SteelSuit
External web security scanner: TLS, headers, secrets & CVEs
Ad Blocker
FormCrab.com
Get messages while you hide your email
XCloak
MyVault — Personal Command Center
All-in-one personal vault for passwords, files, bills, and expenses.
ComingUp