Know what your public site leaks.

2 min read Original article ↗

hackymacky

Paste a URL. We check client bundles for secrets and probe anon Supabase permissions.

Opt-in · domain verify for deep scans · fingerprints only · no row dumps

How it works

Live

What ships today.

Paste a URL for a preview. Claim the domain for the deep sweep. The free tier is the product.

  • Preview

    Paste a URL

    Secrets in the client bundle and what your Supabase anon key can actually reach. No account.

  • Claim

    Deep probes

    After domain verify: storage, RPC, anon writes, and auth posture — plus a copy-paste fix on every finding.

  • Score

    Score and history

    A 0–100 on every scan, a sparkline, a diff vs the last full scan, and owner triage that survives rescans.

  • Daily

    Rescans and mail

    Verified projects rescan every day. The project page shows what changed overnight. Score drops and new highs can email you or post to Slack — titles only, never secrets.

  • Badge

    Public score badge

    Opt-in SVG for READMEs and sites. Score only. Findings stay private.

  • Report

    Shareable report

    Tokenized Markdown and PDF. Remediations, not plaintext secrets or row dumps.

  • CI

    Optional CI gate

    GitHub Action that can fail a job on critical — or high. Public URL. Accessory glue, not the product.

  • MCP

    scan_url + report

    stdio for Cursor and Claude. Preview needs no login. Deep findings use a dashboard API key or a share token.

Built for

Next.jsSupabaseVercel

Claim

Prove the domain, unlock the deep scan.

One DNS TXT record or one file. Either is enough. We do not scan storage, RPC, or anon writes until you verify.

DNS TXT

Name @

hackymacky-verify=a91f4c7e2d8b6035f1c4e9a7b25d80f3

File

/.well-known/security-scan.txt

Token on one line. Serve 200, no redirect.

Your token is generated when you add the project. The sample above is not a real one.

Claim a domain