LaunchGuard
Supabase ScanPricingHow It Works

Free Tools

Ship ScoreLeak RadarSupabase Security ScannerFirebase Security Scanner

Product

PricingHow It WorksClaude Code SkillSecurity Research

Legal

TermsPrivacy

Contact

teemu.sormunen@centrive.aiInstagram

What can strangers see about your app?

Leak Radar scans your app from the outside like a curious stranger or automated bot would. See exposed keys, open files, and information leaks.

100% free
No signup required
Nothing stored

How it works

01

Paste your URL

Any public web app — Next.js, React, WordPress, anything.

02

We scan like a stranger

20+ checks on your page source, file paths, headers, and admin routes.

03

See what's exposed

Severity-ranked results with evidence and fix guidance.

What Leak Radar checks

Exposed API Keys

Supabase service role keys, OpenAI keys, Stripe secret keys, AWS credentials, Firebase service accounts, and private key material in your page source.

Sensitive Files

.git/config, .env, .env.local, wp-config.php, .DS_Store, debug endpoints, and GraphQL introspection.

Admin Panels

Probes /admin, /dashboard, /_admin, /wp-admin, and /administrator for publicly reachable login pages.

Security Headers & Source Maps

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, server version disclosure, and downloadable .js.map files.

Frequently asked questions