
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Scan codebases and GCP projects for exposed API credentials

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

sprint encode (plan text) get enc password

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).