Project security view
The Security view helps you find and fix security problems in your Lovable project, like vulnerable code or outdated dependencies. It shows you scan results and lets you ask Lovable to help fix issues before and after you publish your app.
Anyone building an app in Lovable needs this to make sure their project is safe from common security risks.
Do this, in order
- 1
Go to your Lovable project, then click 'More' in the toolbar and select 'Security'.
This opens the Security view where you can see all security-related information for your project.
- 2
Review the 'Deep security scan' and 'Quick security scan' cards at the top to see if your project has been scanned recently.
These cards tell you if the scan results are up to date. If not, you'll see buttons to run a scan.
- 3
If a scan is not 'Up to date', click 'Run deep scan' or 'Run quick scan' on the respective card.
Running a scan updates the security findings to reflect the current version of your project, catching any new issues.
- 4
Look at the 'security findings' panel to see any identified issues, grouped by security area and labeled by severity (Critical, Warning, Info).
This helps you understand what problems exist and prioritize fixing the most serious ones first.
- 5
Click on a finding to see details, including what could happen and technical evidence.
Understanding the details helps you decide how to address the issue.
- 6
For findings you want to fix, click 'Try to fix' on an individual finding, 'Try to fix all' for all open findings, or select multiple and click 'Try to fix selected'.
Lovable will attempt to fix these issues for you, saving you time and effort.
- 7
Review the 'Project dependencies' card and click 'Review' to see a list of your project's packages and any known vulnerabilities.
Outdated or vulnerable dependencies are a common source of security risk, and this helps you identify them.
- 8
If there are known issues in your dependencies, click 'Try to fix all' on the dependency list.
This asks Lovable to update vulnerable dependencies, improving your project's security.
- 9
If a finding doesn't apply to your project, open its '…' menu and choose 'Ignore finding', providing a reason.
This removes irrelevant findings from your active list, allowing you to focus on actual risks, but should be done carefully.
Paste this into your project
Please review my project's security. I'd like to run a deep scan and then get recommendations on how to fix any critical findings. Also, check my project dependencies for known issues and suggest updates.
Words decoded
- Dependencies
- These are pre-made pieces of software (like building blocks) that your project uses to do certain things. If these building blocks have known flaws, your project can become vulnerable.
- Vulnerabilities
- These are weaknesses or flaws in your project's code or its building blocks that could be exploited by someone with bad intentions to cause harm or gain unauthorized access.
- MCP server
- This refers to a specific part of Lovable's internal system that handles how your app communicates and operates. An 'unprotected MCP server' means it might be exposed in a way that could be risky.
- Credits
- These are a form of currency or usage allowance within Lovable's system. Some advanced features or automated actions might 'consume credits', meaning they use up a portion of your allowance.
- Static analysis
- This is a way of checking your project's code for problems without actually running the app. It's like proofreading your code for common mistakes or security flaws.
- Software composition analysis
- This is a method to identify and evaluate the open-source and third-party components (dependencies) used in your project, looking for known security vulnerabilities or licensing issues.
- EPSS score
- This is a number that estimates how likely it is that a known security weakness (vulnerability) will actually be used by attackers. A low score means it's less likely to be exploited in the real world.
Where people get stuck
- Publishing your project with 'Critical' security findings, which are often serious vulnerabilities.
- Ignoring security findings without carefully considering if they truly don't apply to your project.
- Not running scans regularly, especially after making significant changes or updating dependencies, leading to outdated security information.
- Relying solely on automated scans and not complementing them with conversational security reviews for a broader perspective.
- Forgetting to review and test changes made by automated fixes, as they might not always be perfect for your specific needs.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.