secret
Stripe secret key exposed in client bundle
STRIPE_SECRET_KEY is readable in main.js. Anyone can extract it from the browser and charge or refund on your account.
This is an illustrative example, not a real scan result.
3 security findings
Checks your live site for exposed credentials and third-party data collection.
STRIPE_SECRET_KEY is readable in main.js. Anyone can extract it from the browser and charge or refund on your account.
A marketing analytics script fires on first paint, before any cookie consent is collected.
The landing page loads no third-party analytics or ad scripts — consistent with your stated policy.
Paid plans re-scan automatically and alert you the moment something changes.