App Security Scanner

Free website security scanner for exposed keys and open databases

xlogs is a read-only security scanner for deployed web apps. It reads what your site already serves publicly and flags secrets in JavaScript bundles, databases that answer anonymous requests, exposed source maps, private files like .env, risky scripts and missing security headers. Each finding comes with evidence and a fix you can paste into your coding tool.

Our verdict

Run it on an app built with Lovable, Bolt, Cursor or similar before you share the link. It tells you what a stranger could see, explains how to fix it, and lets you re-scan to confirm the fix worked. It is not a penetration test and says so, so use it as a first pass.

Why we like it: Scans are free with no signup, include every finding and allow unlimited re-scans. The checks are deterministic, so the same app gives the same result, and the methodology page lists each check and what it does not cover.

The catch: It only looks at what is publicly visible. It does not test for SQL injection, cross-site scripting or login flaws, and it warns that its findings are leads to confirm, not verdicts.

In the directory

What we feature from App Security Scanner