
jsleak
a Go code to detect leaks in JS files via regex patterns

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Identify hardcoded secrets in static structured text

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

Tool to search secrets in various filetypes.

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github,…

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

A tool to hunt for credentials in github wild AKA git*hunt

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

A tool for pointesters to find candies in SharePoint

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

「🔑」A tool used to hunt down API key leaks in JS files and pages

Pluggable linting tool to prevent committing credential.

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

A modern git based age-encrypted secrets manager for teams.