Live secrets get scraped from GitHub in < 30 seconds

Did you ship Stripe
keys you shouldn't have?

One indie dev woke up to an $87,000 Stripe bill from a key committed days earlier. The Stripe Safety Audit catches the 5 ways AI tools leak payment money — in 60 seconds, for $49.

Live secret key in source

sk_live_… committed to a public commit. We find every key your repo ever had, even from removed commits, and link to the right dashboard.stripe.com rotation page.

Forgeable webhook handler

Most AI-generated code parses the webhook body without calling constructEvent. Anyone can POST a fake checkout.session.completed event and flip your DB to 'paid'.

Client-controlled price ID

AI puts req.body.priceId straight into checkout.sessions.create. Users pick the cheapest tier and get the most expensive product.

Stripe SDK in client bundle

new Stripe(secret) ends up in a 'use client' file. Secret ships to every browser. We catch it before any user runs your JS.

NEXT_PUBLIC_STRIPE_SECRET

Any env var prefixed NEXT_PUBLIC_ / VITE_ / EXPO_PUBLIC_ is bundled. We flag every secret-looking var with a public prefix.

Stripe key in deployed bundle

Paste your live production URL — we fetch the JS and inspect for service-tier keys that survived the build.

What you get for $49

Start free previewNo card required for the preview.