I will scan your website for exposed secrets, API keys and leaked credentials
AI Safety Security Researcher
About this Gig
Exposed API keys, forgotten .env files, leaked tokens in JavaScript bundles - these are how small teams get breached. Not sophisticated attacks. Just something left open.
I'll tell you exactly what yours is exposing.
WHAT I DO
- Scan your public web surface for exposed credentials and secrets
- Check for exposed .git, .env, backup and config files
- Review JavaScript bundles for hardcoded keys and tokens
- Verify every finding manually before reporting it
WHAT YOU GET
A clear report with each finding rated by real business impact - what an attacker could actually do with it - plus exact steps to fix. Not a raw scanner dump.
WHY ME
Google VRP credited for a responsibly disclosed authentication bypass. Acknowledged by UNICEF for a high-severity exposure affecting 13,000+ accounts. I built the scanning engine I use.
IMPORTANT - AUTHORIZATION
I only test systems you own or are authorized to test. Please confirm this when ordering. Passive-first: I look, I never break. Nothing is modified, exploited or taken offline.
Message me before ordering if you're unsure about scope - I'll tell you honestly whether I can help.
Testing application:
Web application
Device:
PC
•
Mac
•
Linux
My Portfolio
FAQ
Will this take my site down?
No. Testing is passive-first and rate-limited - I observe what is publicly reachable rather than attacking it. Nothing is modified, exploited, or taken offline. Your site keeps running exactly as it was.
What if you find nothing?
You still get a full report: what was checked, what was covered, and a clean-scan confidence statement. A clean result is a useful result - it tells you where you actually stand.
Do you need my passwords or server access?
No. This is entirely external. I only look at what the public internet can already see - no credentials, no server access, no code access needed.
Can you test a site I don't own?
No. I need written authorization from the owner. This protects both of us, and it is a rule I do not make exceptions to.

