FREE REPOSITORY SECURITY TOOLS

Start with the risk you need to check.

Each tool uses the same read-only Pallos scanner, but explains the relevant checks, evidence, and limits before you submit a public repository.

FREE GITHUB SECRET SCANNER

Check a public GitHub repository for exposed secrets.

Scan a public GitHub repository for committed credential patterns, exposed API keys, and client/server secret boundary mistakes. No account required.

Open this tool
SUPABASE RLS CHECKER

Find Supabase access rules that deserve a closer look.

Review a public repository for risky Supabase Row Level Security policies, service-role key exposure, and weak access assumptions.

Open this tool
NEXT.JS SECURITY SCANNER

Review a Next.js repository before you launch.

Scan a public Next.js repository for exposed secrets, weak authorization, risky routes, webhook mistakes, and unsafe server/client boundaries.

Open this tool

Already have the repository URL?

Paste it into the free scanner. No account, payment, or GitHub connection is required for public code.

Run a free scan