Built for AI Builders and Vibe Coders

Don't leave your app open to hackers.
Find what your app accidentally exposed.

Your AI wrote the code. xlogs checks what's live.

xlogs is a free, read-only scanner that finds exposed secrets, open databases, private files and misconfigurations in your live app, then shows you exactly how to fix them.

Every finding freeUnlimited re-scansNo signupRead-onlyNo AI guesswork
Works with apps built on
Claude logoClaudeCodex logoCodexLovable logoLovableCursor logoCursorBolt logoBoltv0 logov0Replit logoReplitSupabase logoSupabaseand more

xlogs works with any app, on any stack.

What xlogs checks

  • Exposed keys
  • Open databases
  • Public .env files
  • Private files
  • Source maps
  • Misconfigurations
  • Risky third-party scripts
  • Tokens in browser storage
Every check we run, and what each one does not cover

See what the xlogs security scanner finds

A real scan of a real app. Every finding follows the same three steps: find it, fix it, verify it.

Scannedhttps://acme-vibesupabase.app
Sample scan• Completedin 2.4s
3things worth fixing1 critical1 high1 medium

We start with the most severe. Each one below has the evidence, a fix for your coding tool, and a way to confirm it worked.

8 checks performed

xlogs can be wrong. Treat these as leads to check, not verdicts. Confirm one against your own code before acting on it, especially before rotating a credential or changing production. Findings marked Confirmed were observed in both your source and your live site and are the most reliable.

Every fix in one paste
3 findings, ordered by severity, each with what was observed, the fix, and how to verify it.
CriticalConfirmedwe saw it happen

Supabase RLS misconfiguration

What this means
Anyone on the internet can read data from your "customers" table. This includes sensitive information like email and Stripe customer IDs. Attackers can view and export this data without logging in.
1FindEvidence (read-only)
Table
customers
Columns exposed
email, stripe_customer_id, created_at
Approx. rows
~1243 rows
We never access or store row data. Only table metadata and counts.
2FixHow to fix it
3VerifyConfirm it is gone✓
After you deploy the policies, click Rescan and xlogs confirms the table no longer returns data without a login.

Your deployment

Everything we observed. None of it is scored, and none of it is a problem by itself.

Other addresses on acme-vibesupabase.app, from public certificate logs
staging.acme-vibesupabase.appadmin.acme-vibesupabase.apppreview-42.acme-vibesupabase.app

These were issued, which is not the same as live or insecure: we did not test them. Worth a look if one is a staging or admin site you forgot was public.

224Scans run
11Checks every scan
Every scan: 11 checks · 18 key formats searched · 6 private paths requested · up to 25 bundles read
The other half

See what they tried. See what you exposed. Connect the two.

Your access log
/.env
40 requests, from 5 addresses
Your live app
/.env
Reachable, confirmed by the scan
Probed and exposed

People requested /.env, and the deployment serves it.

Drop your access log hereSee what they are probing, and whether your app exposes it. Nothing is uploaded.Apache · nginx · Vercel · Cloudflare · JSON

Demonstration, computed from a sample log by the same parser your own file would use.

Where xlogs sits
  1. Build
  2. Deploy
  3. Scan
  4. Fix
  5. Verify
  6. Ship
xlogs runs the three in the middle. You paste a URL, it shows what your deployment exposed with the evidence, hands your coding tool the fix, and re-checks it after you deploy.
Read-only
We never modify your app
The same requests any visitor's browser makes.
Private
We don't store your code or data
Database checks record table names and a row count, never row contents.
Open
You can see exactly what we test

What does xlogs check?

  • Exposed keys
  • Open databases
  • Public .env files
  • Private files
  • Source maps
  • Misconfigurations
  • Risky third-party scripts
  • Tokens in browser storage

Reads your public JavaScript bundles and looks for known secret formats.

8 externally observable categories, covering 12 finding types. Read-only, and nothing is exploited to confirm it.

xlogs is a free, read-only security scanner for websites and web applications. It inspects the parts of a deployment that are already public and reports the mistakes that get shipped by accident: secrets left in JavaScript bundles, a database that answers anonymous requests, source maps that hand over your original code, private files like .env and .gitserved to anyone who asks, DNS left pointing at a service you no longer own, scripts loaded from a CDN with a documented compromise, and missing browser security headers.

xlogs does not attack your application. It never tries to exploit anything, never writes, never logs in and never modifies your data. It makes the same kind of requests any visitor's browser already makes, and reports what came back. That boundary is the product, not a limitation: it is what lets every scan be free, repeatable and safe to run against production.

Because it observes rather than attacks, there are things it deliberately does not test. It is not a penetration test and does not probe for SQL injection, cross-site scripting or authentication flaws. Every check it runs, and what each one does not cover, is written down.

Also check code before you install it

Your AI tool suggested a package. Is it safe? Paste a public GitHub repo.

Static and read-only. We download the code and read it. We never install, run or execute it.

What the repo scanner looks for

Frequently asked questions

Free to scan. Nothing locked. No signup.

Is xlogs free, and what is included?

Yes, and nothing is locked. Every scan is free with no signup: you get all findings, a copy-paste fix for each one written for your AI coding tool, and unlimited re-scans to independently verify a fix worked. There is no paywall on results and no limit on how much you can understand about your own app.

What does xlogs check?

The security issues that actually get exploited in AI-built apps: a database anyone can read (Supabase RLS off), secret keys shipped to the browser, missing security headers, exposed source maps, and public files like .env. Each finding comes with the evidence behind it.

Is it safe to scan my live app?

Yes. Every check is read-only. xlogs makes the same kind of requests any visitor's browser already makes. It never writes, deletes, logs in, or changes anything, and it never tries to exploit what it finds.

Which tools does it work with?

Any deployed web app, including ones built with Lovable, Bolt, v0, Replit, Base44, and Cursor, and apps that use Supabase. It scans the live site, so what built it does not matter.

Does xlogs store my code or data?

No. It reads only what your app already serves publicly. For database checks it records table and column names plus an approximate row count as evidence, never the row contents.

Does xlogs use AI to scan?

No. The checks are deterministic, so the same app always produces the same result. Fixes come from a fixed knowledge base written for your coding tool, not from a model guessing.