BreachProbeONE URL, READ-ONLY
MENU
Scan free1 CRITICAL OPEN
33 issue types32 written fixes30 tables per scan2 throwaway accountsnothing written$9 report · $19 with 30 nightly re-scans

Every check the engine runs

33 issue types, grouped by what the probe reads or asks. 32 carry a written fix in the paid report.

38 OF 38/
SEVERITYCHECKWHAT IT MEANSREAD FROMFIX
CRITICALsupabase-service-role-keySupabase service_role key shipped to the browserTHE SHIPPED CODE WRITTEN
CRITICALsupabase-secret-keySupabase secret key shipped to the browserTHE SHIPPED CODE WRITTEN
CRITICALstripe-secret-keyStripe secret key shipped to the browserTHE SHIPPED CODE WRITTEN
CRITICALaws-access-keyAWS access key exposedTHE SHIPPED CODE WRITTEN
CRITICALprivate-key-blockPrivate key block shipped to the browserTHE SHIPPED CODE WRITTEN
CRITICALsupabase-jwt-signing-secretSupabase JWT signing secret shipped to the browserTHE SHIPPED CODE NONE YET
CRITICALstripe-webhook-accepts-unsignedStripe webhook accepts requests with no signatureSTRIPE ROUTES WRITTEN
CRITICALstripe-webhook-accepts-bad-signatureStripe webhook does not verify its signatureSTRIPE ROUTES WRITTEN
CRITICALrls-cross-tenantRow-level security is broken — users can read each other’s data2 SIGNED-IN USERS WRITTEN
HIGHopenai-keyOpenAI API key exposedTHE SHIPPED CODE WRITTEN
HIGHanthropic-keyAnthropic API key exposedTHE SHIPPED CODE WRITTEN
HIGHsendgrid-keySendGrid API key exposedTHE SHIPPED CODE WRITTEN
HIGHgithub-tokenGitHub token exposedTHE SHIPPED CODE WRITTEN
HIGHgeneric-secret-envServer-side secret exposed via a public env varTHE SHIPPED CODE WRITTEN
HIGHclient-side-admin-flagAdmin access decided in the browserTHE SHIPPED CODE WRITTEN
HIGHstripe-client-side-amountCharge amount looks like it is built in the browserTHE SHIPPED CODE WRITTEN
HIGHstripe-test-key-in-productionA Stripe TEST key is live on your production siteTHE SHIPPED CODE WRITTEN
HIGHopen-rest-tablesTables readable without logging in (critical when a table holds user or account data)SUPABASE REST WRITTEN
HIGHstripe-success-trusts-query-stringSuccess page shows a confirmation with nothing verifiedSTRIPE ROUTES WRITTEN
MEDIUMgoogle-api-keyGoogle API key exposedTHE SHIPPED CODE WRITTEN
MEDIUMjwt-in-localstorageAuth token stored where XSS can steal itTHE SHIPPED CODE WRITTEN
MEDIUMsequential-id-fetchRecords fetched by guessable sequential idTHE SHIPPED CODE WRITTEN
MEDIUMstripe-deprecated-redirect-to-checkoutUsing a retired Stripe.js checkout methodTHE SHIPPED CODE WRITTEN
MEDIUMstripe-js-outdated-versionLoading a retired version of Stripe.jsTHE SHIPPED CODE WRITTEN
MEDIUMmissing-hstsNo HTTPS enforcement (HSTS)RESPONSE HEADERS WRITTEN
MEDIUMmissing-frame-optionsApp can be embedded in a hostile iframe (clickjacking)RESPONSE HEADERS WRITTEN
MEDIUMmissing-cspNo Content-Security-PolicyRESPONSE HEADERS WRITTEN
MEDIUMauto-confirm-signupsAnyone can create an account with any email (no confirmation)2 SIGNED-IN USERS WRITTEN
LOWexposed-admin-routeUnguarded admin route referenced in the bundleTHE SHIPPED CODE WRITTEN
LOWdebug-mode-onDebug / verbose mode shipped to productionTHE SHIPPED CODE WRITTEN
LOWmissing-content-type-optionsMIME-type sniffing not disabledRESPONSE HEADERS WRITTEN
LOWmissing-referrer-policyNo Referrer-PolicyRESPONSE HEADERS WRITTEN
LOWrest-schema-enumerableDatabase schema is publicly enumerableSUPABASE REST WRITTEN
CLEANjwt-signing-secret-absentJWT signing secret is not in the bundleTHE SHIPPED CODE
CLEANstripe-webhook-rejects-unsignedWebhook rejects an unsigned requestSTRIPE ROUTES
CLEANstripe-webhook-rejects-bad-signatureWebhook rejects a forged signatureSTRIPE ROUTES
CLEANstripe-success-page-gatedSuccess page does not confirm on its ownSTRIPE ROUTES
CLEANrls-correctTenant isolation held on tested tables2 SIGNED-IN USERS

How the score is worked out

  1. 01Start at 100.
  2. 02Each critical takes 40, each high 22, each medium 10 and each low 4.
  3. 03Each further finding in the same severity counts 70% of the one before it, so ten low findings do not outweigh one critical.
  4. 04The score stops at 0.
  5. 0590 or more is an A, 78 a B, 62 a C, 45 a D, anything lower an F.
  6. 06Any critical finding makes the grade F. Any high finding caps it at C.

scoreFindings() IN src/lib/scan/score.ts, THE FUNCTION THAT SCORES EVERY PAID REPORT

The sample, demo-app.lovable.app

critical: 40.0 = 40.0
high: 22.0 + 15.4 = 37.4
medium: 10.0 + 7.0 + 4.9 = 21.9
low: 4.0 + 2.8 = 6.8
deducted: 106.1
100 minus 106.1, stopped at 0, is 0
one critical, so the grade is F