Skip to main content
UNPWNED
Back to Home

GITHUB REPOSITORY SECURITY

GitHub Security Scanner for Secrets, CVEs and Exposed Config

Find leaked credentials before they leave your repository. UNPWNED connects to GitHub via read-only OAuth and runs scheduled scans against the repositories you select. Findings auto-create GitHub Issues with copy-paste fix prompts for Cursor, Claude, and Copilot.

What a scan returns

Real output from the same scanner, run over a sample repository. Values are masked in the findings exactly as they are here, so a report never reprints the credential it just told you to rotate.

unpwned scan · acme/storefront
8 findings6 critical2 highacross 6 of 6 files

src/lib/aws-client.ts

  • CRITICALAWS Access Key IDline 6AKIA••••••••

src/lib/ai.ts

  • CRITICALAnthropic API Keyline 4sk-ant-••••••••
  • HIGHHardcoded Secretline 4•••••••• (87 chars)

src/app/api/checkout/route.ts

  • CRITICALStripe Live Secret Keyline 3sk_live_••••••••

scripts/release.sh

  • CRITICALGitHub Tokenline 4ghp_••••••••
  • HIGHCredential in Environment Assignmentline 4•••••••• (53 chars)

config/database.yml

  • CRITICALDatabase Connection Stringline 3postgresql:/••••••••

deploy/id_rsa

  • CRITICALPrivate Keyline 1-----BEGIN RSA PRIVATE KEY-----

A sample repository, not a customer's. Every credential in it was generated at random and authorises nothing. UNPWNED never publishes findings from a scanned domain or repository.

What it Catches

49 credential patterns

AWS keys, GCP service accounts, Stripe keys, Slack webhooks, OpenAI/Anthropic API keys, Supabase service-role keys, Firebase config blocks, GitHub PATs, JWTs, generic API key shapes, and more.

Vulnerable dependencies

Cross-references your package.json / requirements.txt / Gemfile / go.mod against OSV.dev, GitHub Advisory Database, and NVD. CVE severity ratings included.

Exposed config files

Detects committed .env, .env.local, .env.production, credentials.json, firebase.json with secrets, .git/config dumps, id_rsa private keys, wp-config.php, database.yml, Terraform state.

Source map exposure

Source maps in production reveal your full unminified source. Scanner flags accidentally published source maps and identifies which secrets they expose.

Suspicious package usage

Flags abandoned packages, packages with known supply-chain issues, and unusual dependency patterns that often indicate AI-generated code with hallucinated imports.

Workflow file gaps

Detects missing GitHub Actions hardening: pinned action versions, restricted token permissions, branch protection enforcement.

Which secrets it recognises

49 credential patterns, grouped by where the key came from. The last group matters most in practice: a private key, a database connection string or a hardcoded password carries no vendor prefix for a partner-pattern scanner to match on, so it is the kind of secret that sits in a repository longest.

AI provider keys

5

OpenAI API Key · Anthropic API Key · Google AI / Gemini Key · Hugging Face Token · Groq API Key

Cloud provider credentials

5

AWS Access Key ID · AWS Secret Access Key · Google Cloud Service Account Key · Azure Storage Account Key · Azure Client Secret

Source control and package registries

6

GitHub Token · GitHub Fine-grained Token · GitLab Personal Access Token · npm Token · PyPI Token · Docker Hub Token

Payment processors

5

Stripe Live Secret Key · Stripe Test Secret Key · PayPal Client Secret · Square Access Token · Shopify Access Token

Messaging and webhooks

5

Slack Token · Slack Webhook URL · Discord Bot Token · Discord Webhook URL · Telegram Bot Token

Email and SMS providers

7

SendGrid API Key · Resend API Key · Postmark Server Token · Mailgun API Key · Mailchimp API Key · Twilio API Key · Twilio Auth Token

Infrastructure and tooling

8

Cloudflare API Token · Vercel Token · Datadog API Key · Sentry Auth Token · Algolia Admin Key · Linear API Key · Notion Integration Token · Airtable API Key

Credential shapes with no vendor prefix

8

Private Key · JSON Web Token · Database Connection String · Basic Auth Credentials in URL · Hardcoded Password · Hardcoded Secret · Hardcoded JWT Signing Secret · Credential in Environment Assignment

How it Works

01

Connect via OAuth (read-only)

One click. UNPWNED requests read-only access. You pick which repos to expose - public or private. Revoke anytime from your GitHub settings.

02

Scheduled scans run automatically

Paid plans include continuous monitoring. Repos are re-scanned on a schedule, and we re-check every time you push to a monitored branch.

03

Issues created in your repo

Findings can auto-create GitHub Issues with severity, location, and a copy-paste fix prompt for Cursor / Claude / Copilot. No context-switching.

04

Email + webhook alerts

Get notified when a new critical finding lands. Webhooks let you wire alerts into Slack, Discord, or your own incident system.

Common Questions

Does UNPWNED scan private GitHub repositories?

Yes. UNPWNED uses GitHub OAuth with read-only scopes you grant explicitly per repository. Private repos are scanned the same way as public ones, with the same secret patterns and CVE checks. Tokens are encrypted at rest and you can revoke access at any time from your GitHub account settings.

How is this different from GitHub's built-in secret scanning?

GitHub's built-in scanner only flags partner-pattern secrets, mostly verified token formats from major providers. UNPWNED detects 49 credential patterns including AI provider keys, framework-specific keys such as Supabase service-role and Firebase config blocks, credential shapes with no vendor prefix (private keys, database connection strings, hardcoded passwords), and exposed config files like .env. UNPWNED also adds CVE scanning for dependencies and exposed config-file detection, features GitHub does not bundle together. For paid plans, UNPWNED auto-creates GitHub Issues with AI fix prompts that paste directly into Cursor or Copilot.

Does UNPWNED execute or modify my code?

No. UNPWNED uses the GitHub Contents API to read file contents and metadata. Nothing is cloned to disk, nothing is executed, no commits or pushes are made on your behalf. The only write operation UNPWNED ever performs is creating GitHub Issues, and only if you enable that feature.

How often are repos scanned?

Scans run automatically on a schedule depending on your plan. Solo: weekly. Studio: every 3 days. Scale: daily. All paid plans also re-scan when GitHub notifies us of a push to a monitored branch (via webhook).

Can I scan my GitHub repo without signing up?

For one-off scans, yes - install the UNPWNED CLI (npm install -g unpwned) and run it locally against any repository you have access to. Continuous monitoring with auto-issue creation requires a paid plan.

Will UNPWNED detect secrets in commit history?

Yes. UNPWNED scans the latest version of files plus a configurable history window. If a secret was once committed and then "removed" without rotating it, UNPWNED flags it as still exposed (because it is - the secret lives forever in git history).

Connect Your First Repo

Read-only OAuth. Pick the repos. Get findings as GitHub Issues. Cancel anytime.