1
Configure Target URL
Scan only sites you own or are authorised to test. Detected secrets are analysed server-side and never shown or stored — you'll only see that an exposure exists and where to fix it.
What gets checked
Security headers & SSL Exposed .env/ config filesLeaked secret tokens Internal & external APIs SEO & semantic structure