Audit your .env files for security risks

Detect leaked secrets, weak passwords, insecure configurations, and missing security keys in your environment variables. Free, instant, and private.

Your .env content is analyzed in-memory and never stored. All processing happens server-side in a single request.

Secret Detection

Identifies API keys, tokens, passwords, and credentials using 30+ known secret patterns from AWS, Stripe, GitHub, OpenAI, and more.

Weak Value Analysis

Flags common weak defaults like "password123", empty values, and debug modes that should never reach production.

Actionable Fixes

Every finding includes severity classification and step-by-step remediation guidance to secure your configuration.