Find exposed secrets and vulnerabilities in any GitHub repo.
Paste a GitHub URL, get a security report in seconds. Share a badge in your README.
| Engine | What it finds | Rules |
|---|---|---|
| Betterleaks | Exposed API keys, tokens, webhooks | 150+ patterns |
| OpenGrep | XSS, SQL injection, command injection, insecure patterns | 3,000+ SAST rules |
| Trivy | Known CVEs in dependencies | Real vulnerability database |
| Built-in checks | Hardcoded secrets, missing lockfiles, dangerous functions | 14 regex patterns |
Each repo gets a Vibe Safety Score (0-100) and a letter grade (A-F).
- Instant scanning — paste a URL, get results in seconds
- Auto-scan on visit —
git.exposed/owner/repotriggers a scan automatically - Fix It For Me — AI generates a PR to fix findings (Pro)
- Continuous monitoring — GitHub webhooks rescan on every push (Pro)
- Commit status checks — pass/fail status on every push (Pro)
- GitHub OAuth — sign in to scan private repos
- SVG badge — embed your score in any README
- Share links —
git.exposed/owner/repois the report URL
git clone https://github.com/mimu-sh/git.exposed.git
cd git.exposed
pnpm install
cp .env.example .envEdit .env with your database URL:
# Required
DATABASE_URL=postgresql://user:pass@host/dbname?sslmode=require
# Optional — scanner backend (without this, built-in regex checks run)
SCANNER_BACKEND_URL=http://localhost:4000
SCAN_SECRET=any-shared-secretTip
See .env.example for all available environment variables including GitHub OAuth, billing, and webhook configuration.
cd apps/web && npx drizzle-kit pushpnpm turbo devOpen http://localhost:3000.
pnpm turbo test # 87 unit tests
cd apps/web && pnpm test:e2e # 24 e2e tests (Playwright)The backend runs Betterleaks, OpenGrep, and Trivy for deep scanning. Without it, the frontend uses built-in regex checks.
cd apps/api
SCAN_SECRET=any-shared-secret PORT=4000 npx tsx src/index.tsNote
The backend requires betterleaks, opengrep, and trivy binaries installed. See the Dockerfile for installation steps.
git.exposed/
├── apps/
│ ├── web/ Next.js 16 — frontend, API routes, auth
│ └── api/ Hono — scanner backend, fix worker
├── packages/
│ └── shared/ DB schema, types, scoring, GitHub utils
┌─────────────────────┐ ┌──────────────────────┐
│ Next.js 16 (Vercel)│──────▶│ Hono API (Railway) │
│ - Scan API │ │ - Betterleaks │
│ - Report pages │ │ - OpenGrep │
│ - Auth (OAuth) │ │ - Trivy │
│ - Billing (LS) │ │ - Fix worker │
│ - Webhook handler │ │ - pg-boss queue │
└────────┬────────────┘ └──────────────────────┘
│
┌────▼────┐
│ Neon │
│Postgres │
└─────────┘
| Grade | Score | Meaning |
|---|---|---|
| A | 90-100 | Clean — ship it |
| B | 80-89 | Minor issues |
| C | 70-79 | Needs attention |
| D | 50-69 | Significant problems |
| F | 0-49 | Do not deploy |
Deductions: critical (-25), high (-15), medium (-8), low (-3), info (0).
| Layer | Technology |
|---|---|
| Frontend | Next.js 16, React 19, Tailwind CSS 4 |
| Backend | Hono 4, tsx |
| Database | Neon PostgreSQL, Drizzle ORM |
| Auth | Auth.js v5 (GitHub OAuth) |
| Billing | Lemon Squeezy |
| AI Fixes | GitHub Copilot SDK (BYOK), Octokit |
| Queue | pg-boss |
| Testing | Vitest, Playwright, axe-core |
| CI/CD | GitHub Actions, Turborepo |
| Deploy | Vercel (frontend), Railway (backend) |
| Command | Description |
|---|---|
pnpm turbo dev |
Start all services |
pnpm turbo build |
Build all packages |
pnpm turbo test |
Run unit tests |
pnpm turbo lint |
Lint all packages |
pnpm dev --filter=@repo/web |
Frontend only |
pnpm dev --filter=@repo/api |
Backend only |