Findings
11 findings from scan scn_8f21c4. Each carries the evidence that produced it.
| Severity | Finding | Object | Category | First seen | Status |
|---|---|---|---|---|---|
| Critical | Row Level Security disabled on realtime.subscription RLS-001 | realtime.subscription | RLS Security | 2026-08-12 | Open |
| Critical | Row Level Security disabled on net._http_response RLS-001 | net._http_response | RLS Security | 2026-08-12 | Open |
| Critical | Potential cross-tenant access through SECURITY DEFINER function FUNC-001 | public.get_invoice(uuid) | Tenant Isolation | 2026-08-12 | Open |
| High | Anonymous role granted access to public.webhook_endpoints PERM-001 | public.webhook_endpoints | Permissions | 2026-08-12 | Open |
| High | Anonymous role granted access to public.pricing_plans PERM-001 | public.pricing_plans | Permissions | 2026-08-12 | Open |
| Medium | Policy "Users can view profiles" does not constrain rows to a tenant RLS-010 | public.profiles | Tenant Isolation | 2026-08-12 | Open |
| Medium | INSERT policy "Members create tickets" has no WITH CHECK RLS-020 | public.support_tickets | RLS Security | 2026-08-12 | Open |
| Medium | Mutable search_path on public.refresh_usage_totals() FUNC-010 | public.refresh_usage_totals() | Functions | 2026-08-12 | Open |
| Medium | Storage bucket "avatars" is publicly readable STOR-001 | storage.avatars | Storage | 2026-08-12 | Open |
| Medium | public.v_customer_billing bypasses policies on public.invoices, public.customers VIEW-001 | public.v_customer_billing | Views | 2026-08-12 | Open |
| Low | Anonymous role granted access to realtime.subscription PERM-001 | realtime.subscription | Permissions | 2026-08-12 | Open |
Unlock Full Audit (Demo)
Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
This is a sample project. You can unlock it for testing, or run your own scan to use your credits on a real database.
Ready to scan your own database?