16,207 packages matching “hardcoded-secrets”
@capgo/capgo-sec
v1.2.0 · 4 days ago
Security scanner for Capacitor apps - detect vulnerabilities, hardcoded secrets, and security misconfigurations
No known vulnerabilities
@bernierllc/validators-secret-patterns
v1.6.0 · 2 months ago
Primitive validator for detecting hardcoded secrets and sensitive patterns in code
No known vulnerabilities
secrets-le-mcp
v2.2.4 · 4 days ago
Detect hardcoded secrets in source and config, reporting masked previews and never the values themselves.
No known vulnerabilities
sic-security
v7.0.0 · 1 month ago
SIC free code scanner — read-only static analysis for hardcoded secrets, dangerous patterns, and dependency CVEs. Zero runtime dependencies.
No known vulnerabilities
@thkimsw98/slopscan
v0.1.1 · 7 days ago
Free offline CLI that scans your local repo for hardcoded secrets and risky AI-generated code before you ship.
No known vulnerabilities
@graneth/mcp-server
v0.7.1 · 9 days ago
Account-free MCP server: catch AI-hallucinated packages (npm, PyPI, crates.io, RubyGems, Go, Packagist), risk-score the dependencies an AI agent introduces, and find hardcoded secrets before you commit. Exposes the free pre_flight_check tool over stdio.
No known vulnerabilities
leakx
v1.0.3 · 17 hours ago
A lightweight CLI tool that scans your codebase for hardcoded secrets, API keys, and passwords before they leak into version control.
No known vulnerabilities
eslint-plugin-jwt-security
v2.3.4 · 20 hours ago
ESLint plugin for JWT security — detects algorithm confusion (CVE-2022-23540), alg:none, weak or hardcoded secrets, and decode-without-verify.
No known vulnerabilities
@mlawsonking/code-guard-mcp
v1.3.0 · 1 day ago
MCP server: security scanner for AI-generated code: the agent scans its own code/diff before committing. Detects injection, SSRF, hardcoded secrets, weak crypto, unsafe deserialization, TLS-off, XSS. Deterministic, free, no LLM.
No known vulnerabilities
gitleash
v0.2.0 · 25 days ago
Keep your AI coding agent on a leash: a zero-config git hook that blocks reckless commits and force-pushes — huge diffs, deleted tests, hardcoded secrets, CI edits — before they land.
No known vulnerabilities
@cencori/scan
v0.4.8 · 6 months ago
Security scanner for AI apps. Detect hardcoded secrets, PII leaks, and exposed routes.
No known vulnerabilities
@vibecheck-ai/cli
v40.0.2 · 2 months ago
The trust layer for AI-generated software. Catches phantom dependencies, ghost API routes, fake SDK methods, and hardcoded secrets — before they ship.
No known vulnerabilities
eslint-plugin-ai-guard
v1.3.0 · 5 days ago
GitHub-native guardrails for AI-generated code. ESLint plugin and GitHub Action for detecting async reliability issues, floating promises, empty catch blocks, hardcoded secrets, SQL injection, and more. SARIF-based GitHub Code Scanning integration with PR
No known vulnerabilities
codesentinel-cli
v1.0.2 · 12 days ago
Code Sentinel AST & AI Security Auditor CLI - Scan local repositories, SD cards, live URLs, and GitHub repos for security flaws and hardcoded secrets.
No known vulnerabilities
@opzyai/mcp
v0.1.2 · 1 month ago
Local-first security check MCP server for AI coding agents — finds hardcoded secrets, exposed .env files, secrets in git history, and vulnerable dependencies in your workspace, entirely on your machine.
No known vulnerabilities
@capgo/capacitor-sec
v1.0.4 · 6 months ago
Security scanner for Capacitor apps - detect vulnerabilities, hardcoded secrets, and security misconfigurations
No known vulnerabilities
security-scanner-mcp
v1.2.0 · 2 months ago
MCP server that scans AI-generated code for security vulnerabilities (OWASP Top 10, hardcoded secrets, SQL injection, XSS)
No known vulnerabilities
ubon
v3.2.3 · 3 months ago
Security scanner for AI-generated apps (Cursor, Lovable, Windsurf, v0). Catches hardcoded secrets, prompt injection, hallucinated imports, Server Actions / Edge runtime mistakes, and the vibe-coded vulnerabilities traditional linters miss.
No known vulnerabilities
vibe-audit-security
v0.1.0 · 28 days ago
Security scanner for vibe-coded projects: local CLI and MCP server that catch the security mistakes an AI coding assistant can silently introduce (hardcoded secrets, disabled RLS, open CORS, missing security headers) before you push.
No known vulnerabilities
drykit
v0.3.2 · 3 months ago
A linter for AI behavior — catches duplicates, unregistered components, and hardcoded secrets in React projects
No known vulnerabilities