Did you ship Stripe
keys you shouldn't have?
One indie dev woke up to an $87,000 Stripe bill from a key committed days earlier. The Stripe Safety Audit catches the 5 ways AI tools leak payment money — in 60 seconds, for $49.
sk_live_… committed to a public commit. We find every key your repo ever had, even from removed commits, and link to the right dashboard.stripe.com rotation page.
Most AI-generated code parses the webhook body without calling constructEvent. Anyone can POST a fake checkout.session.completed event and flip your DB to 'paid'.
AI puts req.body.priceId straight into checkout.sessions.create. Users pick the cheapest tier and get the most expensive product.
new Stripe(secret) ends up in a 'use client' file. Secret ships to every browser. We catch it before any user runs your JS.
Any env var prefixed NEXT_PUBLIC_ / VITE_ / EXPO_PUBLIC_ is bundled. We flag every secret-looking var with a public prefix.
Paste your live production URL — we fetch the JS and inspect for service-tier keys that survived the build.
What you get for $49
- · Every Stripe-related finding in your code, ranked by severity
- · Per-finding remediation with exact rotation URL on dashboard.stripe.com
- · Deep-link to Stripe docs for each issue class
- · File + line number for every match
- · Paste-code mode for quick checks AND full-repo mode via GitHub OAuth
- · Total time: under 60 seconds