Git Leak Explorer

Analysis Dashboard

http://legacy-ecommerce.shop
⚠️ CRITICAL SECRETS DETECTED 6
AWS Access Key ID.envAKIAIOSFODNN7EXAMPLE
AWS Access Key ID.envAKIAI44QH8DHBEXAMPLE
DB Connection Stringconfig/database.phpmysql://shop_user:Pr0d!Secure#2025@db.internal.shop:3306/sho
Stripe Live Keysrc/checkout/stripe_integration.phpsk_live_4eC39HqLyjWDarjtT1zdp7dc
Generic API Keyconfig/mail.phpSG.ngeVfQFYQlKU0ufo8ZohRA.TxmrHwrjABcd1234EXAMPLEKEY5678abcd
View Secrets Report →
💾 Git Stash Recovered High Priority

2 files with pending modifications detected.

Investigate Changes in History →
🛡 Hardening & Config 8 failures
HEADEXPOSED
refs_headsEXPOSED
packed_refsEXPOSED
indexEXPOSED
objects_rootEXPOSED
logsEXPOSED
configEXPOSED
stashEXPOSED
info_refsOK
Full Diagnostic →
⏳ Recent History 6 commits
HEAD: bd045e5f
bd045e5 fix: remove debug prints from checkout 2025-01-15
1e28659 feat: add product recommendations engine 2025-01-10
35ef9ca chore: update DB credentials for prod migration 2025-01-08
3aec7a8 fix: patch SQL injection in search endpoint 2025-01-05
0efd250 init: initial project structure 2024-12-20
STASH WIP: migrating payment gateway to Stripe STASH
Explore Timeline →
👤 Identities (OSINT)
3
Identified Authors

Developers and emails extracted from history.

View User List →
📂 Files (.git Index) 15 files
src/checkout/payment.phpRemote ↗
src/recommendations.phpRemote ↗
src/catalog.phpRemote ↗
src/search.phpRemote ↗
src/cart.phpRemote ↗
src/user/auth.phpRemote ↗
src/admin/dashboard.phpRemote ↗
config/database.phpRemote ↗

+7 more files

Full Listing →
🌐 Infrastructure Map 8
API_ENDPOINT/api/v1/productssrc/catalog.php
API_ENDPOINT/api/v1/checkoutsrc/checkout/payment.php
API_ENDPOINThttps://api.stripe.com/v1/chargessrc/checkout/stripe_integration.php
EXTERNAL_HOSTdb.internal.shopconfig/database.php
EXTERNAL_HOSTsmtp.sendgrid.netconfig/mail.php
IP_ADDRESS203.0.113.45.env
IP_ADDRESS198.51.100.22.env
EXTERNAL_HOSTcdn.legacy-ecommerce.shoppublic/index.php
Open Infrastructure Map (8) →
🔨 Brute-Force Files 5
.envVERSIONED
config.phpLOCAL
wp-config.phpLOCAL
backup.sqlLOCAL
../../etc/passwdLOCAL
Full Brute-Force Report →
📦 Packfiles 1
pack-a1b2c3d4e5f6.pack
Status: Downloaded | Files: 142
⚠️ Other Leaks (--full-scan) 1