Scan your repository
Paste a link to a PUBLIC GitHub repository. We'll check it for leaked keys and dangerous mistakes. Free: 5 scans a day (10 if you log in). Nothing is stored.
Paste a link to a PUBLIC GitHub repository. We'll check it for leaked keys and dangerous mistakes. Free: 5 scans a day (10 if you log in). Nothing is stored.
Secrets accidentally left in your code — before someone else finds them.
Whether anyone on the internet can reach your data.
Whether someone can get into your app without a username and password.
Why a limit? Scans cost us compute. 5 a day covers a check-fix-recheck cycle; logging in doubles it.
This is a pre-launch check that catches the common, dangerous mistakes — not a guarantee of one hundred percent security. No tool replaces a full audit, but most high-profile leaks happen for exactly the reasons we check.
Your code is used only during the check and deleted right after. No copies. Any keys we find are masked and never stored — we just show you the spot where you need to remove them.
The scanner engine is open source — check the code yourself: github.com/Nqspq/defcod-engine
We keep adding checks — database rules, auth, dependencies. Leave your email and we'll let you know when new ones land. No spam.