SECRETS BELONG OUTSIDE YOUR CODE

Catch the secret.
Keep the control.

Find potential credentials before they become someone else’s discovery. Scan locally, understand the finding, and know what to do next.

Open source · Rules + entropy · No credential verification

secretsense / preview01

01 const config = {

02   apiToken: "[REDACTED]"

03 };

POTENTIAL EXPOSUREHigh

One finding. A clear next step.

Review the token locally. If exposed, revoke it, replace it, and inspect access logs.

✓ Value redactedIllustrative preview
15Service-specific patterns
In memoryLocal demo processing
Your machineInstall the local scanner

A SMALL CHECK. A BETTER HABIT.

From a signal to a next step.

01 / DETECT

Look for the telltale signs.

Service patterns and entropy checks identify potential credentials in UTF-8 source text.

02 / UNDERSTAND

See what needs attention.

Review locations, severity, and explanations. A match is a candidate, never proof of validity.

03 / RESPOND

Take the right next step.

Service-specific guidance helps you rotate credentials, review access, and clean up source.

PREFER YOUR TERMINAL?

Keep it in your workflow.

Install from this checkout. Scan files, directories, or bounded Git history.

python -m pip install -e ./coresecretsense scan ./my-projectThe CLI also exports JSON, HTML, and SARIF reports.