Everything on this site
Every page and section of InlineSec in one place — how the security check works, what it looks for, what it costs, and answers to common questions.
Main
The security check itself.
The four steps
What actually happens after you paste a link.
Problems we look for
The mistakes AI coding tools leave behind.
Checks
Grouped into six areas, over forty individual tests.
Guides
Every guide, check, prompt and error page on the site.
- All guides
- Guide — Security checks you can run on your own site
- Guide — An API key leaked — what to do right now
- Guide — Error messages explained, in plain English
- Guide — Is Supabase secure? What you are responsible for
- Guide — Is Lovable safe? What it gets wrong, and how to check
- Lovable — Lovable and Supabase RLS: is your database public?
- Lovable — Lovable: how API keys end up in your frontend
- Lovable — Lovable: your admin page is hidden, not protected
- Lovable — Lovable: files you deployed by accident
- Lovable — Lovable: can a script steal your users' logins?
- Lovable — Lovable: the security headers you are missing
- Lovable — Lovable and the Supabase service_role key: how it leaks
- How to check — How to check if your Supabase RLS actually works
- How to check — Supabase service_role key exposed: how to check and fix
- How to check — Is the Supabase anon key safe to expose in your frontend?
- How to check — Supabase anon key vs service_role key: the difference
- How to check — What is Row Level Security, and why your app needs it
- How to check — How to check your Firebase security rules are not open
- Key leaked — OpenAI API key leaked: what to do right now
- Key leaked — Stripe secret key leaked: immediate steps
- Key leaked — Firebase Admin key leaked: what to do
- Key leaked — AWS access key leaked: what to do right now
- Fix prompt — Prompt: turn on Supabase Row Level Security properly
- Fix prompt — Prompt: get API keys out of your frontend
- Fix prompt — Prompt: actually protect your admin pages
- Fix prompt — Prompt: stop users reading each other's data
- Fix prompt — Prompt: fix open Firebase security rules
- Fix prompt — Prompt: add the security headers you are missing
- Fix prompt — Prompt: add rate limiting to your app
- Fix prompt — Prompt: move sessions out of localStorage
- Fix prompt — Prompt: stop shipping source maps to production
- Fix prompt — Prompt: full checklist after a key leaks
- Error explained — "New row violates row-level security policy" — fix
- Error explained — Firebase: "Missing or insufficient permissions" fix
- Error explained — "Blocked by CORS policy" — what it means and how to fix
- Error explained — No 'Access-Control-Allow-Origin' header — how to fix
- Error explained — Mixed Content error on HTTPS — what it means and fix
- Error explained — "Refused to execute inline script" — CSP explained
- Error explained — 401 vs 403: what the difference actually means
Legal
What we store, and the rules for using the service.