DevMeth

10 checks in this theme

Secrets scanning for AI-built apps

Hardcoded API keys, committed .env files, secrets in client bundles and git history — 10 checks that catch what AI tools leak. Scan free.

Where AI-built apps leak secrets

Not in exotic places — in the same five every time: a source file where the key was faster than env plumbing, an .env committed "just to make CI pass", a client bundle carrying a server-only key behind the wrong prefix, git history holding a key that was deleted but never rotated, and workflow files printed secrets into logs.

Why AI tools generate it

Code models were trained on docs and examples full of real-shaped keys, so they fill placeholders with plausible credentials instead of failing. And when you ask for "make it work now", the fastest path to a working demo is a hardcoded value — env plumbing is the step that demos fine without.

How the scan detects it

Deterministic pattern and entropy detectors run over your source, committed env files, client bundles, git history, and CI workflows — the same input always produces the same findings. Every hit is masked to prefix + last 4 before it ever leaves the scan pipeline.

The 10 checks

IDCheckSeverity
C1Hardcoded API Keys Check — Are Secrets in Your Code?Critical
C10Database Password in Code Check — Is a Connection Password in Your Source?Critical
C2Secrets in Git History Check — Are Deleted Keys Still Recoverable?Critical
C26.gitignore Gaps Check — Does Your Ignore Keep Secrets Out of the Repo?Hygiene
C29Seed & Backup Data Leak Check — Is Real User Data in Your Repo?High
C3Committed .env File Check — Are Your Real Credentials in the Repo?Critical
C30.env.example Real Values Check — Are Placeholders Actually Placeholders?High
C4Secrets in Client Bundle Check — Is Your Key Shipped to Every Browser?Critical
C5Live Secret in JS Check — Is a Real Key in the JavaScript Your Site Serves?Critical
C8Supabase Service Role Key Check — Is Your Admin Key in Browser Code?Critical

FAQ

DevMeth checks the 48 known AI-code failure patterns — not a penetration test or a security guarantee.

Check your app — free

10 Critical checks, no signup, results in about two minutes. Every finding is masked and carries a paste-ready fix prompt.

Run the free scan