Leak Radar scans your app from the outside like a curious stranger or automated bot would. See exposed keys, open files, and information leaks.
Any public web app — Next.js, React, WordPress, anything.
20+ checks on your page source, file paths, headers, and admin routes.
Severity-ranked results with evidence and fix guidance.
Supabase service role keys, OpenAI keys, Stripe secret keys, AWS credentials, Firebase service accounts, and private key material in your page source.
.git/config, .env, .env.local, wp-config.php, .DS_Store, debug endpoints, and GraphQL introspection.
Probes /admin, /dashboard, /_admin, /wp-admin, and /administrator for publicly reachable login pages.
HSTS, CSP, X-Frame-Options, X-Content-Type-Options, server version disclosure, and downloadable .js.map files.