WHAT IT CATCHES
Runtime secrets in JavaScript, API responses, headers, DOM config, authenticated pages, exposed files, and generated app bundles.
Use throwaway bearer tokens or session cookies only. Authenticated scans help catch runtime leaks that appear after login.
Everything runs locally. Basic scan stays unauthenticated.
Enumerates subdomains (crt.sh + DNS) and crawls every page of the domain, then scans each one. This is an active scan — only run it against systems you own or are authorized to test.
Runtime secrets in JavaScript, API responses, headers, DOM config, authenticated pages, exposed files, and generated app bundles.
Uses Playwright and mitmproxy to inspect the running app locally, then returns a ship verdict with redacted proof, fix guidance, and a re-test command.
Detects AI provider keys, cloud credentials, SaaS tokens, database URLs, private keys, JWT/session leaks, direct object access hints, exposed files, security headers, admin endpoints, and attack-surface signals.