nowfound

Alternatives

Products that do what SecurityScan.dev does

Find leaked API keys & open Supabase/Firebase in 20 seconds

  1. 1

    Scan, Detect & Protect Your Supabase Data

    Jan 2026 · supaguard.pro

  2. 2

    Scan websites for exposed Supabase data and API leaks

    Mar 2026 · leakscope.tech

  3. 3KD

    I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

    Nov 2025 · github.com

  4. 4

    Check if your secrets and API keys have leaked on GitHub.

    2023

  5. 5

    See your leaked API keys before attackers do

    Jan 2026

  6. 6

    An open source Firebase alternative

    2020

  7. 7

    The open source Firebase alternative.

    2020

  8. 8

    Secret scanning for shipped-too-fast websites

    Jan 2026 · supaleak.com

  9. 9ST

    Hi HN — we've built a testing framework for Supabase that spins up fast, isolated Postgres databases for each test case. It’s designed to make RLS policies easy to validate with real database state, without global test fixtures or mock auth. Features: - Instant isolated Postgres DBs per test - Automatic rollback after each test - RLS-native testing with `.setContext()` for auth simulation - Flexible seeding (SQL, CSV, JSON, JS) - Works with Jest, Mocha, and any async test runner - CI-friendly (runs cleanly in GitHub Actions) We also published example projects and a free set of tutorials:…

    Nov 2025 · npmjs.com

  10. 10AT

    A bunch of developers and myself have created RepliByte - an open-source tool to seed a development database from a production database. Features: - Support data backup and restore for PostgreSQL, MySQL and MongoDB - Replace sensitive data with fake data - Works on large database (> 10GB) (read Design) - Database Subsetting: Scale down a production database to a more reasonable size - Start a local database with the prod data in a single command - On-the-fly data (de)compression (Zlib) - On-the-fly data de/encryption (AES-256) - Fully stateless (no server, no daemon) and lightweight…

    2022

  11. 11FL

    Hi, HN! As a cofounder of Couchbase, I pioneered mobile sync, and I’ve always wanted to bring the speed and reliability of local-first data to the web, incubating PouchDB among other efforts. I learned the constraints of real world financial applications at McKinsey & Company FinLab, and Merkle integrity research at Protocol Labs taught me smart contract data structures. As part of the JavaScript community (and early hosting provider for NPM) I’ve been waiting, and now with the availability of APIs like Passkeys and Origin Private Filesystem, I’m happy to say the browser is ready to support…

    2024 · fireproof.storage

  12. 12

    One-click scans for Supabase security peace of mind.

    Oct 2025

  13. 13
    Yikes3

    Find auth gaps and leaked secrets in your vibe-coded app

    Feb 2026 · yikessecurity.com

  14. 14

    Find the data leaks in your app before buyers do

    Jul 2026 · keelscan.com

  15. 15SO

    Heya HN! We put together a post [0] explaining the motivation for building Supafana in some detail, but in short: we wanted a way to get to database graphs with an effort similar to starting a Supabase project - in essence, in a few clicks. It feels unusual to open-source what is essentially a SaaS infrastructure project, but it also feels pretty great - all our code is here: https://github.com/fogbender/supafana We have some discount codes available - let me know if you want one ([email protected]). Thanks for reading! [0]…

    2024 · supafana.com

  16. 16

    Catch exposed API keys and secrets while you browse

    Jul 2026

  17. 17

    We're open-sourcing Sighthound today, our rules-based static security scanner. What makes it special is that it's coded in rust and uses tree-sitter as it's AST making it very fast and easily extensible. Why build another scanner in 2026? We wanted to improve some of our detection outcomes but noticed the current open source scanners like Semgrep/Opengrep we're capped by a bunch of adoption limitations such as being written in OCaml, requiring a lot of work to add a language parser, and the rulesets were licensed differently and required paid offerings. It also felt that licensing was…

    Jul 2026 · github.com

  18. 18

    Scan any website for leaked secrets in seconds

    Feb 2026 · nullgaze-ohm8.vercel.app

  19. 19

    Free security scan for apps you built with AI

    21d ago · uxcontinuum.com

  20. 20

    Free security scan that tells you exactly how to fix it

    Jun 2026

  21. 21

    Build Safer Supabase Apps with supabase-test

    Nov 2025 · x.com

  22. 22CS

    Hi everyone, GitHub's CodeQL is a powerful semantic code analysis engine for identifying vulnerabilities across codebases. We've extended CodeQL to support Solidity, the most popular programming language for smart contracts. CodeQL enables you to query code as though it were data, and it's open-source (OSS). You can check it out here: . The product page is available at . CodeQL has its own licensing model, which you can find at https://codeql.github.com/. TL;DR: CodeQL is free for research and open-source projects.

    2024 · github.com

  23. 23

    60% of startups leak API keys on GitHub. Find & Auto fix.

    Mar 2026 · cyber-guard-nine.vercel.app

  24. 24

    AI-powered vulnerability scanning for modern web apps

    8d ago · vetora.site

Ranked by how close each launch is in meaning, then by votes. Refine with a description →