Machina Scan.
Paste the URL of an app you own. One read-only pass checks for secrets in the bundle, open database tables, missing headers, and exposed paths, then ranks what it found by how much it can hurt you. Nothing is stored.
ScanRead-only, under thirty seconds
machina scanidle
> awaiting a url
Reads the page, its scripts, a few known paths, and public database tables, read-only. Looks for leaked keys, a service-role token, missing security headers, open CORS, exposed .env and .git, and Supabase tables readable with the public key.