First Seen
Feb 18, 2026
Last Scanned
Feb 20, 2026
Findings
5
Score
40/100
Findings (5)
Detects database connection strings with credentials
postgres://user:password@192.168.1.100: Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.
Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.
Detects database connection strings with credentials
postgres://user:password@db.example.com: Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.
Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.
Detects database connection strings with credentials
postgres://user:password@db.projectref.supabase.co: Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.
Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.
Detects database connection strings with credentials
postgres://user:password@db.example.com: Remove the database connection string and replace it with an environment variable reference. Rotate the database password if the connection string was exposed publicly.
Likely FP if the connection string uses localhost with no password (e.g., mongodb://localhost:27017/mydb) or is a documented example URI.
Detects system-level package installation via brew, apt, yum, or dnf
brew install c Pin system packages to specific versions where the package manager supports it. Document the exact packages required and prefer containerized environments to avoid system-wide changes.
Likely FP if the match is standard setup documentation listing well-known system packages (e.g., apt install git curl) that are prerequisites.