Detector rack
Paste to scan
Drop a .env or config file below. Everything is scanned locally in your browser; nothing is uploaded.
Try a sample:
Findings
If anything looks real
- Rotate the exposed key or password immediately.
- Revoke any token that was pushed to a public repo or pastebin.
- Move secrets out of .env and into a secret manager or CI/CD variables.
- Add a
.gitignorerule for.envbefore the next commit.