Daykeeper logodaykeeper

Can Google even see your Lovable app?

A fresh Lovable or Bolt app sends Google an empty <div id="root"> and a script tag, and that's the whole page. Paste your URL and we'll check what search can read, your security headers, and up to 5 of your script files for leaked secret keys.

We only check sites you own. It's a passive check: we read what any browser can read.

Example: acme-notes.com, built with Lovable

A made-up sample app. It's a fresh Lovable project with the default title, so Google sees almost nothing, and its sitemap is really the app's web page.

52/100

Example score (made-up app)

acme-notes.com

6 to fix, 2 to improve, 5 passed

  • ✗

    Real text without JavaScript0 of 20 points

    Your page sends almost no text before JavaScript runs. Google has to come back later to render it, and most AI search crawlers never run your JavaScript at all, so they see a blank page.

    Fix: Pre-render your public pages so the HTML has your headline and copy in it. Ask your AI: "Pre-render the homepage, pricing and blog to static HTML at build time."

  • ✗

    A way to reach you0 of 9 points

    We couldn't find an email link, a contact or help page, or a support chat widget on this page.

    Fix: Add a contact link to your footer, or a support chat widget so people can ask a question before they pay.

  • ✗

    sitemap.xml0 of 5 points

    Your /sitemap.xml returns your app's web page instead of a sitemap. Single-page apps do this when every path falls back to index.html.

    Fix: Add a sitemap.xml that lists every public page, then submit it in Google Search Console.

  • ✗

    Content-Security-Policy and framing0 of 5 points

    No Content-Security-Policy and no X-Frame-Options, so any site can load your app in a hidden frame.

    Only 21.9% of mobile pages send a Content-Security-Policy. · Web Almanac 2025, Security

    Fix: Send a Content-Security-Policy header that includes "frame-ancestors 'self'". On Vercel or Netlify, add it in your headers config.

  • ✗

    X-Content-Type-Options0 of 3 points

    No X-Content-Type-Options header.

    48% of pages send X-Content-Type-Options. · Web Almanac 2024, Security

    Fix: Send "X-Content-Type-Options: nosniff" so browsers don't guess file types.

  • ✗

    Referrer-Policy0 of 2 points

    No Referrer-Policy header, so full URLs (with any tokens in them) can leak to other sites.

    Only 17% of pages send a Referrer-Policy. · Web Almanac 2024, Security

    Fix: Send "Referrer-Policy: strict-origin-when-cross-origin".

  • !

    Page title2 of 4 points

    "acme-notes" is 10 characters.

    Fix: Make your title 30 to 60 characters: what it does, then your brand ("Invoicing for freelancers | Acme").

  • !

    Meta description2 of 4 points

    25 characters: "Lovable Generated Project"

    1 in 3 websites skip a meta description too. · Web Almanac 2025, SEO

    Fix: Stretch your meta description to 70 to 160 characters. Say who it's for and the one result they get.

  • ✓

    No secret keys in your code30 of 30 points

    We scanned the page and 1 script file and didn't find any secret keys. We also found a Supabase anon key (eyJhbG…). That one's meant to be public, as long as Row Level Security is on for every table.

    170 of 1,645 Lovable apps (about 1 in 10) left user data readable because Row Level Security was missing. · CVE-2025-48757, Matt Palmer, 2025

    UpGuard found 16,326 Supabase databases with tables anyone could read. · UpGuard, Sep 2026

  • ✓

    HTTPS6 of 6 points

    Your page loads over HTTPS.

  • ✓

    Share image (Open Graph)4 of 4 points

    You have an og:image, so links to you show a picture on X, LinkedIn and Slack.

    48% of desktop pages set an og:image. · Web Almanac 2024, Structured Data

  • ✓

    robots.txt4 of 4 points

    You have a robots.txt.

  • ✓

    Strict-Transport-Security4 of 4 points

    Browsers are told to always use HTTPS for your site.

    Only 36% of mobile pages send Strict-Transport-Security. · Web Almanac 2025, Security

What we check, and how

  • We fetch your page once from our server, following up to 3 redirects, plus robots.txt, your sitemap and up to 5 script files from your own domain (3 MB total).
  • Each check is a pass (full points), a warning (half points) or a fail (no points). Your score is the points you earned out of 100, and a leaked secret key caps it at 39.
  • Weights: secret keys 30; real text without JavaScript 20; a way to reach you 9; HTTPS 6; sitemap and framing 5 each; title, meta description, share image, robots.txt and HSTS 4 each; nosniff 3; Referrer-Policy 2.
  • We look for Stripe, OpenAI, Anthropic, AWS, GitHub and Resend keys, plus Supabase service_role keys. We show only the first 6 characters of anything we find.

Questions founders ask

Is Lovable bad for SEO?

Out of the box, a Lovable app sends almost no text in its HTML, because everything renders with JavaScript in the browser. Google can render it later, but slower, and most AI search crawlers don't run JavaScript at all. Pre-rendering your public pages fixes it.

Is my Supabase anon key safe to have in my code?

Yes, the anon key is meant to be public, as long as Row Level Security is on for every table. The service_role key is the one that must never ship to the browser, because it skips Row Level Security entirely.

What do I do if you found a secret key?

Rotate it in that service's dashboard right now, because the old one is already public. Then move it to a server-side environment variable and call the service from a backend function, like a Supabase Edge Function.

Do you try to hack my app?

No. We read what any visitor's browser reads: your page, robots.txt, sitemap.xml, response headers and up to 5 of your own script files. We never log in, submit forms or send data to your app.

Why do you ask if I own the site?

Because this is a security check, and you should only run it on your own app. Ticking the box confirms that.

Got customers asking questions? Answer them in one place.

Daykeeper gives your app a support chat widget and one inbox for every customer message. Free for 100 conversations a month. Your AI can set it up for you in one prompt.

Start free

More free tools