Skip to content

Security scan

Base44's built-in check for the usual ways apps leak, like open data and exposed API keys, with a suggested fix for each problem it finds.

Dashboard, then Security, then Run Security Scan. It's free on every plan, so there's no excuse.

It checks for seven kinds of problem. The big ones for most apps are entities with missing or loose rules, API keys sitting where visitors can find them, backend functions anyone can run, and credit-using features that strangers could call to spend your credits.

Fixes are one click, and Base44 makes a checkpoint first so you can roll back. Read before you click, though. The "anyone can run this function" fix makes the function require a signed-in user, which will break a webhook or a page for signed-out visitors.

Run it before your first publish, and again whenever you add entities or change rules.

Think of it as the minimum. The scan can't know that your Invoice entity should only be visible to the customer it belongs to. That takes someone who understands the business.

Related:Row-level security, Secrets and Service role.

Where I've used it: