SoftifyBase Security

Supabase Vulnerability Scanner

Ralph Wiggum - I'm in danger!
"I'm in danger!"
[?]
+ Add anon key (optional, for deeper testing)
[?]

[!] Only test projects you own or have explicit authorization to test

AI-assisted development can miss security holes. Test your SoftifyBase projects with 280+ attack vectors across 9 categories. Know your security posture.

9 Attack Categories. 280+ Attack Vectors.

Comprehensive coverage of every Supabase attack surface. Each category contains multiple attack vectors tested against real vulnerabilities.

-- 01

No Security

RLS Disabled

!! 02

Bad RLS

USING (true)

$$ 03

Business Logic

Price & IDOR

<> 04

Vibecoder

AI Mistakes

;-- 05

Injection

SQL & XSS

{} 06

GraphQL/Vault

Secrets

@ 07

Auth/Tenant

Multi-tenant

[DB] 08

Database

Deep Access

~/ 09

AI/Realtime

ML & WS

>> 10

Backup/Logs

Operations

Active Breach Testing

Actually attempts to exploit your Supabase with real attack vectors. No guessing - real proof of vulnerabilities.

Ralph Wiggum Loop

"I'm in danger!" - Persistent iteration until every vulnerability is found. Keeps attacking until the attack surface is fully mapped.

Fix Verification

After you apply fixes, re-runs all attacks to confirm they're actually resolved. No more "trust me, it's fixed."

[!] For Authorized Testing Only

Only test projects you own or have explicit permission to test. This scanner performs real attacks that could affect data. Use responsibly.