xlogs
Find what your app is accidentally exposing
A read-only scan of a live site for the things that leak by accident: API keys left in the bundle, databases readable without a password, source maps shipped to production, and private files served from public paths.
About xlogs
Written for apps assembled quickly, where nobody audited the defaults — which is now most of them. The scan changes nothing and needs no access; it looks at what the site already serves to anyone who asks.
Links
Compare xlogs
Side by side with the products people weigh it against.
All alternatives to xlogs →Browse related
List your own product
Get in front of makers and early adopters. Free, and always free.
Submit your productIs this your product? Claim this listing — a work email on your own domain confirms it in one click.
Something wrong with this listing? Report it — a person reads every report, and we tell you what we decide.