{"repo":"Amal-David/keyleak-detector","free":true,"listed":false,"github":"https://github.com/Amal-David/keyleak-detector","clone":"git clone https://github.com/Amal-David/keyleak-detector.git","description":"Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI.","language":"Python","stars":266,"topics":["devops","security-audit","security-tools","web","api-key-scanner","baas","chrome-extension","cybersecurity","firebase","javascript"],"license":"MIT","category":"security-tools","readme_excerpt":"KeyLeak Detector Runtime leak detector for modern web apps. Finds exposed API keys, validates BaaS misconfigurations (Supabase RLS, Firebase Security Rules), and catches secrets in JavaScript bundles -- with a Chrome extension for real-time detection. What Makes This Different Static scanners find hardcoded secrets in source code. KeyLeak finds the ones that only appear at runtime -- and then proves they're exploitable . - BaaS vulnerability scanner : Detects Supabase/Firebase/Appwrite config in minified JS bundles, extracts table names, and actively probes whether Row-Level Security is enforced. A Supabase anon key is harmless if RLS works. KeyLeak tests whether it does. - Chrome extension : Detects leaked keys in real-time as you browse. TEST button validates whether a found key is still active (supports 14 providers). JWT decoder surfaces suspicious claims (service role, admin flags, broad scopes). - Full Site Scan : Enumerates subdomains (crt.sh certificate transparency + DNS, and a deep scan auto-installs subfinder — pinned, opt-out — for far richer discovery; amass is used too if present), crawls every page of the domain, and scans them all, reporting which subdomains/pages each leak appeared on plus a per-source discovery breakdown. One command (or one click in the web UI) for a full domain audit. Authorized targets only. - 200+ first-party domain suppression : No false positives when browsing Google, AWS, Azure, GitHub, Stripe, etc. Install PyPI (recommended) Or with ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Amal-David","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Amal-David/keyleak-detector/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}