Scan my app for exposed secrets with practical checks
A practical guide to finding leaked API keys, tokens, and private credentials in source files, Git history, client bundles, and logs before launch.
Blog
Practical, no-jargon guides to help you find and fix the vulnerabilities AI leaves behind.
A practical guide to finding leaked API keys, tokens, and private credentials in source files, Git history, client bundles, and logs before launch.
A practical post-incident guide to Claude Code safety: what changed after the leak, what to verify in the npm package, and what users should do now.
A clear breakdown of the Claude Code leak, the exposed npm build, what was actually disclosed, and why the March 31, 2026 incident matters to developers.
A practical prelaunch security review for AI-built apps. Use this checklist to catch secret leaks, weak auth, unsafe endpoints, and risky defaults before launch.
A practical security review for AI-built apps before launch. Check auth, secrets, data access, unsafe actions, logs, headers, and dependency risk.
The biggest security failures in AI-built apps are usually simple: leaked secrets, broken auth, unsafe file handling, and skipped review before launch.