Always-on website monitoring

Your uptime monitor says everything’s fine.Your API key is in the bundle.

Nightkeep continuously watches what uptime tools can’t see — leaked keys, exposed .env files, expiring certs and domains, missing headers. From a single URL.

Free · no signup · read-only checks

Tracked Checksmystore.demo.app
6 open findings · updated 6h ago
Re-run scan⟳ Export report
CheckStatusLast runCategory
Secrets in client bundles2 critical6h agoSecurity
Exposed paths — .env, .git, .aws1 high6h agoSecurity
Security headers & HTTPS2 low6h agoSecurity
Email authentication (SPF/DMARC)1 high1d agoSecurity
Domain & certificate expiryexpires in 14d1d agoSecurity

Stripe live key readable in your client bundle

Read-only probe · confirmed 31s into the scan

CriticalConfirmed
/assets/index-b3f2.jsline 1043
const stripe = new Stripe("sk_live_51H•••a9Qk");
Copy fix prompt~2 min ›Anyone can charge your account.

Built to scan sites shipped on

Next.jsViteSupabaseLovablev0Vercel
Key features

Turn one scan into a site you can trust

Identify what leaks, monitor what matters, and act before attackers — or AI engines — do.

Only confirmed findings

Every check probes your live site read-only and proves what it reports. Green means checked and good — never "not checked."

FindingEvidence
.env reachable — 14 variablesconfirmed · GET 200
Directory listing on /uploadsunverified · not scored
Coverage22 of 25 checks ran

Fix what matters first

Findings come back ranked by real impact, each with a paste-ready prompt for Cursor, Claude Code, or Copilot.

↑ Suggested fixes (5) — ranked by what attackers try first

Move the Stripe key out of your client bundle

High impactConfirmed~2 min fix

Add llms.txt so ChatGPT stops guessing what you do…

Security

What attackers reach

Secrets in bundles, exposed paths, the six security headers, HTTPS enforcement — probed like an attacker, proven like an auditor.

33 security checks, counted from the registry

AEO

What AI engines say

llms.txt, schema, crawlability — whether ChatGPT, Claude and Perplexity can find, understand and cite your site.

25 AEO checks, counted from the registry

Health

What quietly breaks

SSL, redirects, broken links, email deliverability, domain expiry — the baseline that costs trust when it fails.

30 checks — every result feeds one Website Health Score

Honest by architecture, not by promise

01

Read-only, always

We read what a visitor's browser can see and try the paths attackers try first. Nothing is ever exploited.

02

Only confirmed findings may be critical

One invented critical costs more than ten missed findings. Unverified signals are flagged, never scored.

03

Coverage is part of the result

A check that couldn't run lowers coverage — it never quietly counts as a pass.

How it works
Step 1

Paste your URL

Production, staging or a vibe-coded prototype. No agent, no repo access, no signup.

Step 2

We scan & confirm

Every check runs in parallel through one guarded, rate-limited fetcher — and proves what it reports.

Step 3

You fix the five that matter

Ranked findings with paste-ready fix prompts. Then we re-scan on schedule and only ping you on new issues.

Scan it. Fix it. Trust it.

Your first scan is free and takes about a minute. See exactly what the internet sees.