GITHUB REPOSITORY SECURITY
GitHub Security Scanner for Secrets, CVEs and Exposed Config
Find leaked credentials before they leave your repository. UNPWNED connects to GitHub via read-only OAuth and runs scheduled scans against the repositories you select. Findings auto-create GitHub Issues with copy-paste fix prompts for Cursor, Claude, and Copilot.
What a scan returns
Real output from the same scanner, run over a sample repository. Values are masked in the findings exactly as they are here, so a report never reprints the credential it just told you to rotate.
src/lib/aws-client.ts
- CRITICALAWS Access Key IDline 6AKIA••••••••
src/lib/ai.ts
- CRITICALAnthropic API Keyline 4sk-ant-••••••••
- HIGHHardcoded Secretline 4•••••••• (87 chars)
src/app/api/checkout/route.ts
- CRITICALStripe Live Secret Keyline 3sk_live_••••••••
scripts/release.sh
- CRITICALGitHub Tokenline 4ghp_••••••••
- HIGHCredential in Environment Assignmentline 4•••••••• (53 chars)
config/database.yml
- CRITICALDatabase Connection Stringline 3postgresql:/••••••••
deploy/id_rsa
- CRITICALPrivate Keyline 1-----BEGIN RSA PRIVATE KEY-----
A sample repository, not a customer's. Every credential in it was generated at random and authorises nothing. UNPWNED never publishes findings from a scanned domain or repository.
What it Catches
49 credential patterns
AWS keys, GCP service accounts, Stripe keys, Slack webhooks, OpenAI/Anthropic API keys, Supabase service-role keys, Firebase config blocks, GitHub PATs, JWTs, generic API key shapes, and more.
Vulnerable dependencies
Cross-references your package.json / requirements.txt / Gemfile / go.mod against OSV.dev, GitHub Advisory Database, and NVD. CVE severity ratings included.
Exposed config files
Detects committed .env, .env.local, .env.production, credentials.json, firebase.json with secrets, .git/config dumps, id_rsa private keys, wp-config.php, database.yml, Terraform state.
Source map exposure
Source maps in production reveal your full unminified source. Scanner flags accidentally published source maps and identifies which secrets they expose.
Suspicious package usage
Flags abandoned packages, packages with known supply-chain issues, and unusual dependency patterns that often indicate AI-generated code with hallucinated imports.
Workflow file gaps
Detects missing GitHub Actions hardening: pinned action versions, restricted token permissions, branch protection enforcement.
Which secrets it recognises
49 credential patterns, grouped by where the key came from. The last group matters most in practice: a private key, a database connection string or a hardcoded password carries no vendor prefix for a partner-pattern scanner to match on, so it is the kind of secret that sits in a repository longest.
AI provider keys
5OpenAI API Key · Anthropic API Key · Google AI / Gemini Key · Hugging Face Token · Groq API Key
Cloud provider credentials
5AWS Access Key ID · AWS Secret Access Key · Google Cloud Service Account Key · Azure Storage Account Key · Azure Client Secret
Source control and package registries
6GitHub Token · GitHub Fine-grained Token · GitLab Personal Access Token · npm Token · PyPI Token · Docker Hub Token
Payment processors
5Stripe Live Secret Key · Stripe Test Secret Key · PayPal Client Secret · Square Access Token · Shopify Access Token
Messaging and webhooks
5Slack Token · Slack Webhook URL · Discord Bot Token · Discord Webhook URL · Telegram Bot Token
Email and SMS providers
7SendGrid API Key · Resend API Key · Postmark Server Token · Mailgun API Key · Mailchimp API Key · Twilio API Key · Twilio Auth Token
Infrastructure and tooling
8Cloudflare API Token · Vercel Token · Datadog API Key · Sentry Auth Token · Algolia Admin Key · Linear API Key · Notion Integration Token · Airtable API Key
Credential shapes with no vendor prefix
8Private Key · JSON Web Token · Database Connection String · Basic Auth Credentials in URL · Hardcoded Password · Hardcoded Secret · Hardcoded JWT Signing Secret · Credential in Environment Assignment
How it Works
Connect via OAuth (read-only)
One click. UNPWNED requests read-only access. You pick which repos to expose - public or private. Revoke anytime from your GitHub settings.
Scheduled scans run automatically
Paid plans include continuous monitoring. Repos are re-scanned on a schedule, and we re-check every time you push to a monitored branch.
Issues created in your repo
Findings can auto-create GitHub Issues with severity, location, and a copy-paste fix prompt for Cursor / Claude / Copilot. No context-switching.
Email + webhook alerts
Get notified when a new critical finding lands. Webhooks let you wire alerts into Slack, Discord, or your own incident system.
Common Questions
Does UNPWNED scan private GitHub repositories?
Yes. UNPWNED uses GitHub OAuth with read-only scopes you grant explicitly per repository. Private repos are scanned the same way as public ones, with the same secret patterns and CVE checks. Tokens are encrypted at rest and you can revoke access at any time from your GitHub account settings.
How is this different from GitHub's built-in secret scanning?
GitHub's built-in scanner only flags partner-pattern secrets, mostly verified token formats from major providers. UNPWNED detects 49 credential patterns including AI provider keys, framework-specific keys such as Supabase service-role and Firebase config blocks, credential shapes with no vendor prefix (private keys, database connection strings, hardcoded passwords), and exposed config files like .env. UNPWNED also adds CVE scanning for dependencies and exposed config-file detection, features GitHub does not bundle together. For paid plans, UNPWNED auto-creates GitHub Issues with AI fix prompts that paste directly into Cursor or Copilot.
Does UNPWNED execute or modify my code?
No. UNPWNED uses the GitHub Contents API to read file contents and metadata. Nothing is cloned to disk, nothing is executed, no commits or pushes are made on your behalf. The only write operation UNPWNED ever performs is creating GitHub Issues, and only if you enable that feature.
How often are repos scanned?
Scans run automatically on a schedule depending on your plan. Solo: weekly. Studio: every 3 days. Scale: daily. All paid plans also re-scan when GitHub notifies us of a push to a monitored branch (via webhook).
Can I scan my GitHub repo without signing up?
For one-off scans, yes - install the UNPWNED CLI (npm install -g unpwned) and run it locally against any repository you have access to. Continuous monitoring with auto-issue creation requires a paid plan.
Will UNPWNED detect secrets in commit history?
Yes. UNPWNED scans the latest version of files plus a configurable history window. If a secret was once committed and then "removed" without rotating it, UNPWNED flags it as still exposed (because it is - the secret lives forever in git history).
Connect Your First Repo
Read-only OAuth. Pick the repos. Get findings as GitHub Issues. Cancel anytime.
