Your OpenAI key is in your JavaScript
Anything your app's code holds, every visitor downloads. A key in there is a key anyone can copy and spend.
live app: leaked API keys in the bundle
Your AI SDK runs in the browser
Builders sometimes flip a setting literally named dangerouslyAllowBrowser. It hands your AI key to every visitor.
live app: AI SDK called from the browser
Your Supabase master key is public
The service_role key ignores every access rule. In front-end code it means anyone can read, change or delete all of your data.
live app + repo: service_role key in browser code
A table shipped without rules
Your Supabase anon key is meant to be public. Row Level Security is what stops it reading everything. We read your migrations and flag every table that never turned it on.
repo: Supabase migrations without RLS
Your Firebase rules say "anyone"
Rules left in test mode let anyone on the internet read or write your data without signing in. We read the rules files in your repo.
repo: open Firebase rules files
There is a password in your GitHub repo
Keys pasted into code, or a whole .env file, get synced to GitHub along with everything else. We find them and tell you which to rotate.
repo: committed secrets and .env files
A package you use has a known hole
Your app runs on hundreds of open source packages. We look up the exact versions you have and tell you what to bump.
repo: vulnerable dependencies (OSV.dev)
Any website can act as your users
Server code that lets any site call your API with your users' cookies attached. A page they visit somewhere else could read their data.
repo: CORS open to any origin with credentials