Secrets in plain sight
Catch privileged credentials bundled into the JavaScript your app sends to browsers, or published through NEXT_PUBLIC_ variables.
CLIENT-SIDE CREDENTIALSFREE REPO SCANSECURITY FOR VIBE CODERS
Your idea is ready for the world. Make sure your app is, too. Find the security oversights. Get the fix. Keep shipping.
Connect GitHub for one free scan. No card.
SECURITY / OVERVIEW
A secret credential belongs on the server.
Set boundaries for what the browser can load.
Move privileged credentials to server-only code. Rotate any key that was exposed.
Real context. Specific fixes. No mystery score.
MADE FOR THE STACK
YOU ALREADY SHIP WITH
01 / THE BLIND SPOTS
AI can help you build fast. Security details can still slip through. Here’s what Clod checks in your repository — once for free when you connect GitHub, and on every push with the PR bot.
Catch privileged credentials bundled into the JavaScript your app sends to browsers, or published through NEXT_PUBLIC_ variables.
CLIENT-SIDE CREDENTIALSReview security headers that help protect your app against common browser-based attacks.
SECURITY HEADERSFind Stripe webhook routes that act on a payload without verifying its signature first.
STRIPE WEBHOOKSFind Supabase tables your migrations create without ever turning on row-level security.
SUPABASE RLSFind the controls, links and images that a screen reader cannot name, so the people using one aren’t locked out.
ACCESSIBILITY MARKUPFind session cookies your server code sets without httpOnly or secure, so a script on the page can’t walk off with them.
COOKIE FLAGS02 / FROM REPO TO FIX
Start free on your repo.
Stay covered on every push.
Install the Clod app on the repository you want checked. No card.
Clod scans that repository right away and reports findings by severity, with evidence.
Subscribe to scan every push and get a pull request with the fix.
03 / SIMPLE BY DESIGN
Connect GitHub and scan your repository once for free. When you want every push checked and the fix written for you, add the PR bot.
Connecting GitHub is the only setup.
04 / STAY IN THE LOOP
An email when Clod adds new checks. No charge, no commitment.
A FEW THINGS TO KNOW
Yes. Connect GitHub and Clod scans your repository straight away, once, for free.
Nothing. Installing the Clod app on GitHub gives you one free scan of one repository. It reports findings and opens no pull requests. Scanning every push, with fixes, is the PR bot.
A report covers the checks that ran, not every possible vulnerability. Clod is designed to catch common oversights and explain fixes; it does not replace a full security review.