Verified purchaser
Until Sept 25, 2026, any NoCodeBackend account could get YOUR databases' secret keys with just your email. I reported it privately; they replied "we don't see any issues" while deploying the fix. They never reset existing keys.
UPDATE (Oct 3, 2026): Full report with timeline and evidence: https://ncb-disclosure-2026.pages.dev/
If you use NoCodeBackend, do these now:
1. Regenerate the secret key of every database (Database Settings). The vendor says it did not force a reset, so keys issued before Sept 25 keep working until you do.
2. Check your data for changes or deletions you didn't make.
3. If your databases hold your own customers' data, consider telling them it may have been readable, and check what your privacy law requires.
What was wrong
A dashboard API (/api/databases/list) returned the database list for whatever email address was in the request. It checked that you were logged in, but not that the email was yours. Signing up is free, so "logged in" was no barrier. The answer included each database's sk_live secret key: the key your app uses to read, write and delete records through the Data API. NoCodeBackend's own docs say that key is simply passed as a Bearer token. No login, no cookie.
To be precise: it exposed database keys, not dashboard logins. Those keys are what open your data.
Separately, the shared database server had port 3306 (MariaDB) open to the whole internet. Shodan, a third-party scanner, recorded it on Sept 23, before my report.
I tested only my own account and saw no one else's data. The vendor's own audit agrees: it found nothing "beyond your own isolated verification on your own account." The vendor's own description of its fix confirms the rest: it added an ownership check "so no account can ever query another user's databases."
What happened after I reported it (Sept 25, UTC)
09:36 I send a private report with reproduction steps and fixes, giving 90 days before publication.
09:45 Support: "Let our security team go over it and we will respond you back soon."
11:07 In a separate email, I ask for a refund of two prepaid add-ons bought directly from NoCodeBackend.
11:10 Support: "We don't see a any issues for the critical vulnerabilities you reported. The architecture works as expected." Refund declined.
Same day: the endpoint starts returning 403, and port 3306 is closed.
Later, in private, I'm told my "only intention was to get refund somehow," then offered a $250 coupon. I declined it.
On Sept 28, under this review, the vendor wrote: "you are 100% right on our communication," and "Replying 'we don't see any issues' while our engineering team was actively deploying the fixes was the wrong response." I appreciate that. But its Q&A answer the same day calls my report an "extreme mischaracterization" and makes claims the record doesn't support:
- "When we asked you to provide any logs or evidence... you were unable." None of the vendor's emails to me asked for logs or evidence. Only the vendor has server logs.
- I demanded a refund "within just 9 minutes." It was 91 minutes, in a separate email, after their acknowledgment. 9 minutes was their reply time.
- The refund was "well past AppSumo's 60-day refund window." I asked about add-ons bought on NoCodeBackend's own site, not on AppSumo.
- I had used it "for over 90 days" / "3 months." A comment under the same answer says "more than nine months."
- "Databases remain private, firewalled, and fully secure." Port 3306 was open to the internet until Sept 25; the vendor itself says it has since restricted it.
What's still missing
- No email to users. Keys issued before Sept 25 still work unless each user regenerates them.
- "Zero unauthorized access" over what period? They haven't said how far back their logs go, or since when the endpoint behaved this way.
Why I'm publishing
I didn't want to. If they had told users "we had a bug, it's fixed, please regenerate your keys," my private report would have been the end of it. Most buyers here aren't security specialists and can't judge this from a forum thread. The 90-day window in my report existed so the issue could be fixed; the vendor confirmed the fix publicly on Sept 28, so there's no reason to wait. The report contains no keys and nothing that identifies any other user.
On the refund: yes, I asked, after reporting, for prepaid add-ons that never reached production use. It doesn't change whether the flaw was real. The vendor's own fix shows it was. I'm not asking for anything in exchange for this review or the report.
The product
The idea is good, and the AI database setup and MCP features genuinely save time. I evaluated them on small test databases. Before this, I'd have given it 4 stars. But a backend's first job is to keep each customer's data to that customer, and how a vendor handles a reported flaw is part of the product. Until users are told, I can't recommend putting customer data here.
Riya_NoCodeBackend
Sep 28, 2026Hi Miyan,
Thank you for this thorough, detailed review and for responsibly reporting these findings to us.
First, we want to address your primary critique directly: you are 100% right on our communication, and we own that.
When your email arrived with a request for a full $1,500+ refund after 9 months of purchase, alongside the disclosure, our team reacted defensively to the refund demand instead of giving your technical report the immediate acknowledgment, gratitude, and professionalism it deserved.
Replying "we don't see any issues" while our engineering team was actively deploying the fixes was the wrong response. We were focused on the code, but we failed on the communication, and we sincerely apologize for that.
Now, we want to address the technical substance of your review transparently for the entire AppSumo community:
1. Rapid Remediation (Fixed in Minutes)
As you noted in your review, patching fast is competent engineering. The moment your report came in, our team did not hesitate:
* We added strict caller-to-token ownership validation on the database listing endpoint so no account can ever query another user's databases.
* We restricted raw database port access at the network firewall level so all traffic must traverse our authenticated, encrypted API gateway.
* Following your disclosure, we conducted an end-to-end security audit across all 150+ platform endpoints to ensure strict ownership checks and input guardrails are uniform across the entire codebase.
2. Was Customer Data Compromised?
Following the deployment, we conducted a forensic investigation across our Cloudflare edge logs, application logs, and database query logs.
The records confirmed that, beyond your own isolated verification on your own account, there was zero automated scraping, unauthorized third-party exfiltration, or compromised records.
Furthermore, for any customer who ever wants to rotate credentials as standard security hygiene, NoCodeBackend provides instant 1-click Secret Key Regeneration directly in the Database Settings dashboard.
3. The Refund Context
To be transparent with the community: our refund refusal was strictly because the purchase was made 9 months ago, well beyond AppSumo's 60-day policy.
However, we should have separated our business policy from our technical gratitude. We should have simply said:
"Thank you for the report. You are right, and it has been patched immediately."
4. What This Means for NoCodeBackend Users
No software is immune to bugs, but what defines a platform is how fast and seriously its team responds:
* Your findings were investigated, patched, and deployed live to production in minutes.
* Comprehensive log audits confirmed zero customer data was compromised.
* Our infrastructure and API security are stronger today because of your report.
We appreciate the time you took to audit the platform and help us improve our security posture.
If you are open to it, our team would welcome the opportunity to connect with you directly to demonstrate the hardened architecture and thank you properly.
Best regards,
Riya & The NoCodeBackend Team