BreachProbeONE URL, READ-ONLY
MENU
Scan free1 CRITICAL OPEN
33 issue types32 written fixes30 tables per scan2 throwaway accountsnothing written$19 report · $39 with 30 nightly re-scans

BREACHPROBE / SECURITY SCANNERS FOR VIBE-CODED APPS

LaunchGuard vs Supabase Security Advisor

The same 6 criteria for both, with the page each figure came from and the day it was read.

SECTIONS

2 compared· 6 criteria, identical for every column· every competitor figure read off that company's own page· last verified 2026-09-18

On what it costs, LaunchGuard is Free · Pro $29/month and Supabase Security Advisor does not publish it. On what it needs from you, LaunchGuard is A URL; sign-up to see full key details and Supabase Security Advisor is Access to your Supabase project, through Studio, MCP, the CLI or the Management API. On tests as a signed-in user, LaunchGuard is Yes and Supabase Security Advisor does not publish it. On tests one user reading another's rows, LaunchGuard is Yes, as a saved guard and Supabase Security Advisor does not publish it. On re-checks after you ship, LaunchGuard is Every deploy, on Pro and Supabase Security Advisor is Automatically. On what you get, LaunchGuard is Findings, the request receipt, and a fix and Supabase Security Advisor is A numbered list of lint findings. BreachProbe publishes this table and is one of the things in it, so read the case for the other side below rather than taking the table's word for it. Every figure was read off the named company's own page on or since 2026-09-18; the URLs and the dates are at the foot of this page, and a job re-fetches each one on a schedule and fails when a figure is no longer on the page it came from.

THE TABLESecurity scanners for vibe-coded apps compared on the same 6 criteria
CRITERIONLAUNCHGUARDSUPABASE SECURITY ADVISOR
What it costsFree · Pro $29/month“Free $0 forever … Pro $29 / month”. The free tier is not a findings paywall: “It is not a paywall on findings.”Not publishedThe advisors documentation states no price; they are part of the dashboard.
What it needs from youA URL; sign-up to see full key details“Signing up (still free, no card) reveals the full leaked key and the fix prompt.”Access to your Supabase project, through Studio, MCP, the CLI or the Management APIThe documentation was rewritten after this row was read on 4 September 2026. It now says "You or an agent can pull the same checks from: Studio: Security Advisor and Performance Advisor. MCP: get_advisors with type set to security or performance. CLI: supabase db advisors. Management API: security advisors and performance advisors." The dashboard is one of four routes rather than the only one.
Tests as a signed-in userYes“Logged-in tests included: we sign in as a real user, not just a stranger”.Not publishedThe advisors inspect the project's own configuration; the documentation describes no test of a running app as a signed-in user.
Tests one user reading another's rowsYes, as a saved guardThe free tier saves “up to 2 guards … for a cross-user leak, a payment bypass, or any rule you name”.Not published
Re-checks after you shipEvery deploy, on Pro“It re-checks on every deploy, automatically, the moment you ship”.Automatically"The advisors run automatically in Studio. After an authorized fix, rerun the relevant advisor and confirm that the finding no longer appears."
What you getFindings, the request receipt, and a fix“Every finding, and the receipt: the exact request we sent and what your app sent back”.A numbered list of lint findingsThe published check list includes “0002 auth users exposed” and “0003 auth rls initplan”.

Every figure below was read off that company's own page; each source URL and the date it was read are listed at the foot of this page. BreachProbe is the publisher of this table and is not one of the 2 compared — it scores these rather than competing with them.

“Not published” means that company does not state the figure on the page cited at the foot of this page. It is not a claim that no such figure exists. A company that publishes no limit most likely has none — but “most likely” is not a fact, and this table prints what was read rather than what was inferred.

TESTS AS A SIGNED-IN USERwhether the tool authenticates and probes as a real account, rather than only reading what an anonymous stranger can reach
TESTS ONE USER READING ANOTHER'S ROWSthe two-account test. It is the only check that can tell a working row-level security policy from one that is merely present
ANSWERS4 questions

LaunchGuard vs Supabase Security Advisor — what it costs?

LaunchGuard: Free · Pro $29/month. “Free $0 forever … Pro $29 / month”. The free tier is not a findings paywall: “It is not a paywall on findings.”. Supabase Security Advisor does not state it on supabase.com. The advisors documentation states no price; they are part of the dashboard. Read from launchguard.dev and supabase.com on 2026-09-18.

LaunchGuard vs Supabase Security Advisor — what it needs from you?

LaunchGuard: A URL; sign-up to see full key details. “Signing up (still free, no card) reveals the full leaked key and the fix prompt.”. Supabase Security Advisor: Access to your Supabase project, through Studio, MCP, the CLI or the Management API. The documentation was rewritten after this row was read on 4 September 2026. It now says "You or an agent can pull the same checks from: Studio: Security Advisor and Performance Advisor. MCP: get_advisors with type set to security or performance. CLI: supabase db advisors. Management API: security advisors and performance advisors." The dashboard is one of four routes rather than the only one. Read from launchguard.dev and supabase.com on 2026-09-18.

LaunchGuard vs Supabase Security Advisor — tests as a signed-in user?

LaunchGuard: Yes. “Logged-in tests included: we sign in as a real user, not just a stranger”. Supabase Security Advisor does not state it on supabase.com. The advisors inspect the project's own configuration; the documentation describes no test of a running app as a signed-in user. Read from launchguard.dev and supabase.com on 2026-09-18. Tests as a signed-in user here means whether the tool authenticates and probes as a real account, rather than only reading what an anonymous stranger can reach.

When should I pick LaunchGuard, and when Supabase Security Advisor?

LaunchGuard — You ship every week and want the check to run itself. LaunchGuard is the only tool in this table that re-checks on every deploy automatically and keeps a history — “Memory: we remember every result and every call you made” — and at $29/month that is cheaper than buying a one-off report every month. It also covers Firebase, which BreachProbe does not. Supabase Security Advisor — You have not run anything yet. It is already inside the dashboard you are logged into, it runs on its own, and it sees things no external scanner can — an unindexed foreign key, a table with RLS disabled, a function with a mutable search path. Run it first, whatever else you do. It reads your project's configuration rather than your shipped app, which is why it is a different check and not a lesser one.

WHEN TO PICK ANOTHERWhen each of these is the right pick

BreachProbe does not sell any of these and has nothing to gain from which one you choose — it scores them. Each case below is the one that option genuinely wins.

LaunchGuard

You ship every week and want the check to run itself. LaunchGuard is the only tool in this table that re-checks on every deploy automatically and keeps a history — “Memory: we remember every result and every call you made” — and at $29/month that is cheaper than buying a one-off report every month. It also covers Firebase, which BreachProbe does not.

Supabase Security Advisor

You have not run anything yet. It is already inside the dashboard you are logged into, it runs on its own, and it sees things no external scanner can — an unindexed foreign key, a table with RLS disabled, a function with a mutable search path. Run it first, whatever else you do. It reads your project's configuration rather than your shipped app, which is why it is a different check and not a lesser one.

HEAD TO HEADOther Security scanners for vibe-coded apps compared head to head
SOURCESWhat was checked, and when

Prices and limits move, and a page quoting a stale one is worth less than a page quoting none. Every source is printed here so a reader can check it against the day they are reading this, and a job re-fetches each of these URLs on a schedule and fails when a figure above no longer appears on the page it came from.

TOOLSOURCEGAVEREAD
LaunchGuardwww.launchguard.dev/pricingWhat it costs, What it needs from you, Tests as a signed-in user, Tests one user reading another's rows, Re-checks after you ship, What you get2026-09-18
Supabase Security Advisorsupabase.com/docs/guides/database/database-advisorsWhat it costs, What it needs from you, Tests as a signed-in user, Tests one user reading another's rows, Re-checks after you ship, What you get2026-09-18

Last verified 2026-09-18. https://breachprobe.thecompound.tech/compare/launchguard-vs-supabase-security-advisor