Tell Me When Down
How it worksWhat we checkPricing
Security reportsBlogFree toolsCompareDocs
Log inGet started
blog

Keeping small apps alive

Free-tier sleep6Security checks7Silent cron5Stripe webhooks5Vibe security9Site down2
Rows of numbered brass post office boxes, each with a keyhole, all closed.
Vibe security·August 19, 2026·8 min

Website Security Statistics 2026: 416 Newly Launched Sites Scanned

71.6% ship no Content-Security-Policy. 66% can be impersonated by email. 82.5% have no DNSSEC. But not one of 416 newly launched sites had a critical vulnerability — they're not broken, they're unhardened, and always in the same places.

Blue-lit server blades in a rack, one glowing red — free-tier services idling between requests.
Free-tier sleep·July 18, 2026·6 min

How to keep a free backend awake

Free tiers sleep when idle: Supabase pauses, Render spins down, Neon scales to zero. Here's the map — how each host sleeps, why keep-alive pings have a catch, and what actually keeps a free app responsive.

A vaulted stone cloister in low light — a database only as secure as the walls built around it.
Vibe security·July 18, 2026·7 min

How to secure a Supabase app: the five settings that matter

A Supabase app can be wide open, almost always for the same handful of reasons: RLS off, the service_role key in the browser, public buckets, unguarded functions, secrets in the bundle. Here's the map to closing each one.

A hand holding a clipboard and document in dim light — the pre-launch review nobody is handed.
Security checks·July 18, 2026·6 min

The website launch security checklist nobody hands you

You get a deploy button, not a checklist — so most sites launch with the cert valid and nothing else checked. The four things to test from your URL in seconds, plus the code-side items that cost the most.

A single dim server light in a dark rack — a free service idling, spun down and waiting for a request.
Free-tier sleep·July 18, 2026·5 min

How to stop Render spinning down your free service

Fifteen idle minutes and your free service is asleep; the next visitor waits through the cold start. Here's why keep-warm pings have a catch, and what actually keeps a free app responsive.

A dark rail track vanishing into low light — an idle service put to sleep between requests.
Free-tier sleep·July 18, 2026·5 min

How to keep a Railway app awake

Railway retired its free tier and added opt-in App Sleeping. Here's what actually happens to an idle service now, how to keep one awake without cancelling out the savings, and why a keep-alive ping can't warn you when it dies.

Light trails through a dark underpass at night — compute scaling to zero between queries.
Free-tier sleep·July 18, 2026·5 min

How to stop Neon autosuspending your database

Neon scales your compute to zero after a few idle minutes, and the next query wakes it. Here's what Scale to Zero does, why the fix depends on whether latency or a surprise bill is your real problem, and how to keep it warm safely.

A single light flickering on in a dark room — an idle app waking up for the first visitor.
Free-tier sleep·July 18, 2026·5 min

Why is my website slow the first time I open it?

Slow the first time, instant after? Your site probably isn't slow — it was asleep. Free hosting pauses an idle app and takes seconds to wake it. Here's why it happens, which hosts do it, and your three options.

A glowing neon "OPEN" sign in the dark — a database left open to anyone who holds the public key.
Vibe security·July 18, 2026·6 min

Is my Supabase database public? RLS, and how to check

Your Supabase anon key is public by design — safe only if RLS is on with a real policy. Tables made outside the Table Editor ship with it off, and USING(true) is still open. Here's how to check if your data is public.

Antique keys scattered on black — a credential left in plain sight among many.
Vibe security·July 18, 2026·6 min

My API key is showing on my website — is that bad?

An API key visible in your frontend is a shrug or an emergency depending on which kind it is. Public keys (anon, pk_, Maps) are meant to be seen; secret keys are compromised the instant they ship. How to tell, and what to do.

A grand house facade lit at night — an app that looks finished, its doors not yet checked.
Vibe security·July 18, 2026·6 min

Is my app built with AI safe? A non-developer's check

You built an app with AI, it works, and you're quietly worried it's not safe — but you can't read code. Here are the four plain-English questions that matter, and how to check each one without being a developer.

An open door spilling light into a dark room — a database left reachable without its access rules set.
Vibe security·July 18, 2026·6 min

Is Lovable secure? The one setting that decides it

A Lovable app can be wide open, and the difference is one setting most builders never touch. The anon-key/RLS model, the gap behind a 2025 CVE, and how to check yours.

A half-built structure lit at night — an app generated fast, with the doors not yet locked.
Vibe security·July 18, 2026·6 min

Is Bolt.new secure? What the generated app leaves open

Bolt.new builds a working full-stack app fast — which is why the security gets skipped. The usual gaps: a Supabase database with RLS off, secrets in the bundle, UI-only authorization. Here's how to audit yours.

A lit window seen from outside in the dark — a generated app whose internals may show more than intended.
Vibe security·July 18, 2026·6 min

Is v0 secure? Keeping a generated Next.js app's secrets in

v0's Next.js output looks production-ready, which is the trap. NEXT_PUBLIC_ bakes a var into the bundle, and a secret in a client component ships to the browser. Here's how to check a v0 app keeps its secrets in.

An unlocked padlock resting on a laptop keyboard in low light — an app shipped without its defenses set.
Vibe security·July 18, 2026·6 min

Vibe coding security risks: the checklist nobody runs

The appeal of vibe coding is that you don't read every line — which is exactly why the holes get through. Exposed secrets, a database anyone can read, rules enforced only in the UI, and how to close each one.

A weathered padlock on a dark iron gate — the certificate that secures a site, lapsed.
Security checks·July 18, 2026·5 min

Website down from an expired SSL certificate

An expired certificate is a full outage — every visitor hits a red warning, though the server's fine. Here's why auto-renewal still fails silently, why shrinking cert lifetimes make it likelier, and how to see it coming.

123
Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkSecurity reportsPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com