Secrets Leakage Scanner
Scan code for accidentally committed secrets and credentials.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Find the secrets that should not be in your code
Credentials committed to a repository are one of the most common and damaging security mistakes, because once pushed they are effectively public and often stay in history forever. This scanner reviews code for accidentally committed secrets, API keys, tokens, passwords, so you can find and remove them from your own repositories.
Why committed secrets are so dangerous
A secret in a commit is exposed the moment the repository is shared or made public, and removing it from the latest version is not enough, because it remains in the git history where anyone can retrieve it. The correct response is to revoke and rotate the secret, not just delete the line. Finding the exposure is the first step, and doing it before an attacker does is the whole point.
A defensive check on your own code, kept local
Scanning your own code for leaked credentials is a basic hygiene step, ideally before every push. The analysis runs entirely in your browser, so your configuration is never uploaded, which matters when it describes your own infrastructure.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
Why are committed secrets so dangerous?
Because once pushed they are effectively public, and they remain in git history even after you delete the line, where anyone with the repository can retrieve them.
Is deleting the secret from my code enough?
No. It stays in the git history. The correct response is to revoke and rotate the exposed secret, treating it as compromised, and remove it from history as well.
What kinds of secrets does it look for?
API keys, tokens, passwords and other credentials that follow recognisable patterns and should never be committed to a repository.
When should I scan?
Ideally before every push, as a hygiene step, so a secret is caught before it enters shared history rather than after.
Is my code uploaded?
No. The scan runs entirely in your browser.
Privacy & Security
Scanning done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.