Don't leave your app open to hackers.
Find what your app accidentally exposed.
Your AI wrote the code. xlogs checks what's live.
xlogs is a free, read-only scanner that finds exposed secrets, open databases, private files and misconfigurations in your live app, then shows you exactly how to fix them.
Codexxlogs works with any app, on any stack.
What xlogs checks
- Exposed keys
- Open databases
- Public .env files
- Private files
- Source maps
- Misconfigurations
- Risky third-party scripts
- Tokens in browser storage
See what the xlogs security scanner finds
A real scan of a real app. Every finding follows the same three steps: find it, fix it, verify it.
We start with the most severe. Each one below has the evidence, a fix for your coding tool, and a way to confirm it worked.
8 checks performed
xlogs can be wrong. Treat these as leads to check, not verdicts. Confirm one against your own code before acting on it, especially before rotating a credential or changing production. Findings marked Confirmed were observed in both your source and your live site and are the most reliable.
Supabase RLS misconfiguration
Your deployment
Everything we observed. None of it is scored, and none of it is a problem by itself.
These were issued, which is not the same as live or insecure: we did not test them. Worth a look if one is a staging or admin site you forgot was public.
See what they tried. See what you exposed. Connect the two.
People requested /.env, and the deployment serves it.
Demonstration, computed from a sample log by the same parser your own file would use.
- Build
- Deploy
- Scan
- Fix
- Verify
- Ship
What does xlogs check?
- Exposed keys
- Open databases
- Public .env files
- Private files
- Source maps
- Misconfigurations
- Risky third-party scripts
- Tokens in browser storage
Reads your public JavaScript bundles and looks for known secret formats.
8 externally observable categories, covering 12 finding types. Read-only, and nothing is exploited to confirm it.
xlogs is a free, read-only security scanner for websites and web applications. It inspects the parts of a deployment that are already public and reports the mistakes that get shipped by accident: secrets left in JavaScript bundles, a database that answers anonymous requests, source maps that hand over your original code, private files like .env and .gitserved to anyone who asks, DNS left pointing at a service you no longer own, scripts loaded from a CDN with a documented compromise, and missing browser security headers.
xlogs does not attack your application. It never tries to exploit anything, never writes, never logs in and never modifies your data. It makes the same kind of requests any visitor's browser already makes, and reports what came back. That boundary is the product, not a limitation: it is what lets every scan be free, repeatable and safe to run against production.
Because it observes rather than attacks, there are things it deliberately does not test. It is not a penetration test and does not probe for SQL injection, cross-site scripting or authentication flaws. Every check it runs, and what each one does not cover, is written down.
Also check code before you install it
Your AI tool suggested a package. Is it safe? Paste a public GitHub repo.
Frequently asked questions
Free to scan. Nothing locked. No signup.
Is xlogs free, and what is included?
Yes, and nothing is locked. Every scan is free with no signup: you get all findings, a copy-paste fix for each one written for your AI coding tool, and unlimited re-scans to independently verify a fix worked. There is no paywall on results and no limit on how much you can understand about your own app.
What does xlogs check?
The security issues that actually get exploited in AI-built apps: a database anyone can read (Supabase RLS off), secret keys shipped to the browser, missing security headers, exposed source maps, and public files like .env. Each finding comes with the evidence behind it.
Is it safe to scan my live app?
Yes. Every check is read-only. xlogs makes the same kind of requests any visitor's browser already makes. It never writes, deletes, logs in, or changes anything, and it never tries to exploit what it finds.
Which tools does it work with?
Any deployed web app, including ones built with Lovable, Bolt, v0, Replit, Base44, and Cursor, and apps that use Supabase. It scans the live site, so what built it does not matter.
Does xlogs store my code or data?
No. It reads only what your app already serves publicly. For database checks it records table and column names plus an approximate row count as evidence, never the row contents.
Does xlogs use AI to scan?
No. The checks are deterministic, so the same app always produces the same result. Fixes come from a fixed knowledge base written for your coding tool, not from a model guessing.
