Security audits for Framer sites.

Most of a Framer site is not code. The parts that are, code components and custom code, are where the risk collects: pasted API keys, imports from unknown hosts, content turned into markup. We review both, plus the live pages, and hand you the fixes.

Get a quote

Why it matters

A component that needs to call an API needs a key, and standing up a server to hold that key is a bigger job than the component itself. So the key goes in the file, the component works, and it ships to every visitor's browser. We built the free Thunkle Security Scanner on the Framer Marketplace to catch exactly this, and it has a hard limit we are open about: Framer's plugin API cannot read the custom code under Settings, and it cannot see your published pages. A clean scan is not a clean site. The audit is the human review of everything, including the parts no plugin can reach.

What you get.

Code component review

Every component read for embedded credentials across fifteen key formats. We decode Supabase tokens and branch on the role, because a service role key is critical and a publishable key is not a finding at all. Flagging safe keys teaches you to ignore the report.

Custom code review

The scripts under Settings that no plugin can read: keys pasted into head and body code, tracking snippets, and anything a third party could swap out from under you.

Live page and network review

What your published site actually sends and receives, including what any database or backend wired in from the browser returns to an unauthenticated visitor.

Imports and dangerous patterns

Modules imported from hosts nobody recognises, dangerouslySetInnerHTML fed by content a visitor can influence, eval on external strings, and secrets read from URL parameters.

Redirect health

Redirects whose destination page was deleted and silently became null, chains, loops, and rules fighting over the same source path. Invisible in the editor, and a mess after most migrations.

Prioritised report and free re-review

Every finding rated by severity with a concrete fix, and a free re-check of the same surface once you have applied them.

How it works.

  1. 01

    Access

    You share the published URL and invite us to the project as a viewer, which is what lets us read the custom code a plugin cannot.

  2. 02

    Review

    We read the components and custom code by hand and test the live site from outside, including any backend it talks to.

  3. 03

    Report

    You get a clear, prioritised write-up within days, plus a call to walk through it and the fix for each finding.

  4. 04

    Re-review

    After you apply the fixes, we verify the keys are rotated and the holes are closed.

Common questions.

I ran the free Thunkle Security Scanner and it found nothing. Do I still need an audit?
The plugin covers code components, and we are precise about its limits: Framer's plugin API cannot read the custom code under Settings or your published pages. If you keep keys or scripts there, no plugin will ever see them. The audit reviews everything, which is why it exists alongside the free scanner rather than instead of it.
There are keys visible in my site. Is that automatically bad?
No, and treating every key as a leak is how real ones get missed. Publishable Stripe keys, Firebase browser keys and Supabase anon keys are designed to be public. A Supabase service role key or any secret key in a page is critical. Knowing which is which is most of the job, and every finding we report tells you which you have.
My Framer site has a database behind it. What changes?
Framer handles the front end, so anything with a database behind it is usually wired in from the browser and the key sits in the page. That is fine only if the access rules behind that key hold, so we test what the backend actually returns to an unauthenticated visitor, not just what the site displays.
Can you fix the issues, not just find them?
Yes. We can make the changes in your project, move keys behind a small server where one is needed, and rotate anything that has already been exposed. Or we hand your builder a clear prioritised list.
How much does a Framer site audit cost?
It is scoped to a fixed quote up front, with no hourly meter, and typically starts around $500 depending on the size of the site. You will know the price before we begin.

Related services.

Let's build something real.

Tell us about your app or idea. You'll get a clear plan and a fixed quote back within 24 hours.

Get a quote