Git Leak Explorer

Analysis Dashboard

https://startup-api.io
⚠️ CRITICAL SECRETS DETECTED 3
GitHub Token.github/workflows/deploy.ymlghp_16C7e42F292c6912E7710c838347Ae178B4a
Slack Token.env.productionxoxb-263594206-2162371917-token_removed
Generic API Keysrc/db/prisma.tsaccess_token = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.DEMO'
View Secrets Report →
🛡 Hardening & Config 4 failures
HEADEXPOSED
refs_headsOK
packed_refsOK
indexEXPOSED
objects_rootEXPOSED
logsOK
configEXPOSED
stashOK
info_refsOK
Full Diagnostic →
⏳ Recent History 6 commits
HEAD: aeed18f2
aeed18f ci: add GitHub Actions deploy workflow 2025-02-28
ae7e256 feat: add rate limiting middleware 2025-02-25
c0bf4de fix: rotate leaked Slack token (oops) 2025-02-20
e9d7744 feat: JWT authentication 2025-02-15
b8d7d33 init: project scaffold 2025-02-10
REFLOG temp: hardcode token for staging test (REVERTED) ORPHAN
Explore Timeline →
👤 Identities (OSINT)
3
Identified Authors

Developers and emails extracted from history.

View User List →
📂 Files (.git Index) 12 files
src/app.tsRemote ↗
src/auth/jwt.tsRemote ↗
src/routes/auth.tsRemote ↗
src/routes/users.tsRemote ↗
src/middleware/rateLimit.tsRemote ↗
src/controllers/authController.tsRemote ↗
src/db/prisma.tsRemote ↗
.github/workflows/deploy.ymlRemote ↗

+4 more files

Full Listing →
🌐 Infrastructure Map 5
API_ENDPOINT/api/v1/auth/loginsrc/routes/auth.ts
API_ENDPOINT/api/v1/userssrc/routes/users.ts
EXTERNAL_HOSTapi.startup-api.iosrc/app.ts
EXTERNAL_HOSThooks.slack.comsrc/middleware/rateLimit.ts
IP_ADDRESS10.0.1.42.env.production
Open Infrastructure Map (5) →
🔨 Brute-Force Files 4
.env.productionVERSIONED
.github/workflows/deploy.ymlVERSIONED
../../../etc/shadowLOCAL
package.jsonVERSIONED
Full Brute-Force Report →
📦 Packfiles 0

No packfiles detected.

⚠️ Other Leaks (--full-scan) 0

No additional leaks.