LaunchGuard
Supabase Scan

Free Tools

Ship ScoreLeak RadarSupabase Security ScannerFirebase Security Scanner

Legal

TermsPrivacy

Contact

teemu.sormunen@centrive.ai

What can strangers see about your app?

Leak Radar scans your app from the outside like a curious stranger or automated bot would. See exposed keys, open files, and information leaks.

100% free
No signup required
Nothing stored

How it works

01

Paste your URL

Any public web app — Next.js, React, WordPress, anything.

02

We scan like a stranger

20+ checks on your page source, file paths, headers, and admin routes.

03

See what's exposed

Severity-ranked results with evidence and fix guidance.

What Leak Radar checks

Exposed API Keys

Supabase service role keys, OpenAI keys, Stripe secret keys, AWS credentials, Firebase service accounts, and private key material in your page source.

Sensitive Files

.git/config, .env, .env.local, wp-config.php, .DS_Store, debug endpoints, and GraphQL introspection.

Admin Panels

Probes /admin, /dashboard, /_admin, /wp-admin, and /administrator for publicly reachable login pages.

Security Headers & Source Maps

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, server version disclosure, and downloadable .js.map files.

Frequently asked questions