#1API key scanning, credential leak detection, and secret management tools.
Kitploit recommended

A tool for secrets management, encryption as a service, and privileged access management
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Find, verify, and analyze leaked credentials

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Simple and flexible tool for managing secrets

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Incredibly fast crawler designed for OSINT.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

A vulnerability scanner for container images and filesystems

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Snyk CLI scans and monitors your projects for security vulnerabilities.

OpenSSF Scorecard - Security health metrics for Open Source