About SupaExplorer
SupaExplorer checks whether a Supabase-based app leaks credentials. Pasting a URL runs a scan that looks for leaked Supabase project URLs, anonymous keys and service-role keys in the site's JavaScript files and reports the exact files involved, and a Chrome extension flags exposed keys, vulnerable tables and insecure endpoints while browsing. The site says it scans for more than a dozen API services and needs no signup for the free tools.
A Supabase project audit connects directly to a project and lists which tables lack row-level security, which can be read publicly and which records are visible, giving an inventory with RLS status. The Pro tier adds AI-written fix recommendations with SQL snippets for RLS policies, audit snapshots to compare over time, subdomain discovery, team collaboration and shareable PDF reports. It is aimed at developers who ship apps quickly and want to verify their database is locked down.
Key features
- URL scanner for exposed Supabase keys
- Chrome extension that detects leaks while browsing
- Project audit showing tables without RLS
- Report of the files that expose keys
- AI-written SQL fixes for RLS policies on Pro
- Audit snapshots and PDF reports on Pro
Good fit for
- Checking an app before launch for leaked keys
- Auditing which Supabase tables are publicly readable
- Sharing security findings with clients or a team
SupaExplorer: questions and answers
- What is SupaExplorer used for?
- SupaExplorer is a security scanner for Supabase apps that finds exposed keys in a site's code, shows which tables are readable and suggests fixes for access rules. It is a good fit for checking an app before launch for leaked keys, auditing which Supabase tables are publicly readable and sharing security findings with clients or a team.
- Is SupaExplorer free?
- Yes. SupaExplorer has a free plan, and paid plans start at $9 per month.
- Is SupaExplorer open source?
- No. SupaExplorer is proprietary (closed-source) software and can't be self-hosted. In the Security category, open-source options include CISO Assistant, Gitleaks and TruffleHog.
- What are some alternatives to SupaExplorer?
- SupaExplorer competes with CheckVibe, Aikido Security and Snyk.
Open-source alternatives to SupaExplorer
See all
CISO Assistant
Security
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & A
OSSvs Vantaβ 4.5k
Gitleaks
Security
Find secrets with Gitleaks π
MITvs GitGuardianβ 30k
TruffleHog
Security
Find, verify, and analyze leaked credentials
AGPL-3.0vs GitGuardianβ 28k
osquery
Security
SQL powered operating system instrumentation, monitoring, and analytics.
OSSvs Taniumβ 24k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snykβ 17k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snykβ 13k
SaaS alternatives to SupaExplorer
See all
CheckVibe
Security
Scans live sites for security, SEO and performance issues left behind by AI coding agents
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS
Invicti
Security
Web application security scanning platform formerly known as Netsparker
SaaS
Vibe App Scanner
Security
Automated external security scanner for AI-built apps with one-click AI-ready fix instructions
SaaS

