If you worked a lot with BaaS like Supabase or use vibe coding platforms like Lovable, you might? know they need they can leak quickly data. So I wrote a small tool: unruly. Give it a URL, it shows you what an attacker can write or read. github.com/eppser/unruly

Sep 23, 2026 · 8:37 AM UTC

3
1
82
Sort replies: Relevant Recent Liked
Replying to @EppSecurity
Nice, an outside read/write check is exactly what non-devs need. Would be great if it also tried the same requests as a second logged-in user, since 'logged in = can read everyone' is the usual next mistake.
1