Your uptime monitor says everything’s fine.Your API key is in the bundle.
Nightkeep continuously watches what uptime tools can’t see — leaked keys, exposed .env files, expiring certs and domains, missing headers. From a single URL.
Free · no signup · read-only checks
| Check | Status | Last run | Category |
|---|---|---|---|
| Secrets in client bundles | 2 critical | 6h ago | Security |
| Exposed paths — .env, .git, .aws | 1 high | 6h ago | Security |
| Security headers & HTTPS | 2 low | 6h ago | Security |
| Email authentication (SPF/DMARC) | 1 high | 1d ago | Security |
| Domain & certificate expiry | expires in 14d | 1d ago | Security |
Stripe live key readable in your client bundle
Read-only probe · confirmed 31s into the scan
const stripe = new Stripe("sk_live_51H•••a9Qk");- Zero false criticals
- Confirmed findings only
- Coverage always shown
Built to scan sites shipped on
Turn one scan into a site you can trust
Identify what leaks, monitor what matters, and act before attackers — or AI engines — do.
Only confirmed findings
Every check probes your live site read-only and proves what it reports. Green means checked and good — never "not checked."
| Finding | Evidence |
|---|---|
| .env reachable — 14 variables | confirmed · GET 200 |
| Directory listing on /uploads | unverified · not scored |
| Coverage | 22 of 25 checks ran |
Fix what matters first
Findings come back ranked by real impact, each with a paste-ready prompt for Cursor, Claude Code, or Copilot.
↑ Suggested fixes (5) — ranked by what attackers try first
Move the Stripe key out of your client bundle
Add llms.txt so ChatGPT stops guessing what you do…
What attackers reach
Secrets in bundles, exposed paths, the six security headers, HTTPS enforcement — probed like an attacker, proven like an auditor.
33 security checks, counted from the registry
What AI engines say
llms.txt, schema, crawlability — whether ChatGPT, Claude and Perplexity can find, understand and cite your site.
25 AEO checks, counted from the registry
What quietly breaks
SSL, redirects, broken links, email deliverability, domain expiry — the baseline that costs trust when it fails.
30 checks — every result feeds one Website Health Score
Honest by architecture, not by promise
Read-only, always
We read what a visitor's browser can see and try the paths attackers try first. Nothing is ever exploited.
Only confirmed findings may be critical
One invented critical costs more than ten missed findings. Unverified signals are flagged, never scored.
Coverage is part of the result
A check that couldn't run lowers coverage — it never quietly counts as a pass.
Paste your URL
Production, staging or a vibe-coded prototype. No agent, no repo access, no signup.
We scan & confirm
Every check runs in parallel through one guarded, rate-limited fetcher — and proves what it reports.
You fix the five that matter
Ranked findings with paste-ready fix prompts. Then we re-scan on schedule and only ping you on new issues.
Scan it. Fix it. Trust it.
Your first scan is free and takes about a minute. See exactly what the internet sees.