If SupaHunt crashes, returns unexpected results, or fails on a specific target type, open an issue with:
- Python version (
python3 --version) - The command you ran
- Error output / traceback
- Target framework (Next.js, Vite, React, SvelteKit, etc.)
Want a new attack module, payload, or detection technique? Open a feature request.
For general questions about Supabase security testing, usage tips, or attack techniques:
- Check existing issues first
- Open a new issue with the
questionlabel
If you found a security issue in SupaHunt itself (not in a target you scanned), see SECURITY.md.
SupaHunt is provided as-is for authorized security testing. The maintainers do not provide support for using this tool against systems you do not have permission to test.