BreachProbe scans shipped apps for database leaks without accounts or installs

BreachProbe is a security scanning tool that detects database leaks and vulnerabilities in deployed web applications by reading shipped JavaScript, probing Supabase REST endpoints, and checking authentication patterns. A recent commit strengthened its reliability by adding HMAC verification for Supabase JWT signing secrets and expanding the deploy check with seven new test cases. The tool requires only a single app URL, needs no account or installation, and operates in read-only mode except when creating two test accounts for cross-tenant access checks. Its sample report demonstrates a scored output with severity ratings, issue evidence, and actionable written fixes, including a Supabase row-level security policy correction using auth.uid(). The console currently covers 33 issue types across five check categories and provides written remediation guidance for 32 of them.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in