Back to library
Test & PolishToolOpen sourceFreemium

TruffleHog

An open secret scanner for Git repositories, filesystems, container images, CI systems, and cloud sources, with many detectors able to verify whether discovered credentials remain active.

Visit official site
Content updated Aug 3, 2026Automated check reached the official site · Checked Aug 24, 2026

Why use it

Pre-release scanning can stop API keys, store credentials, and backend secrets from entering patches or public repositories, while verification separates historical noise from exploitable findings.

Where it fits

Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.

privacyquality-assuranceautomation

What to check

Live verification sends network requests to relevant services, so sensitive or offline environments should disable it and review logs; AGPL-3.0 duties need review before redistribution or hosted modification.

Search the site

Search resources and field guides

    Privacy settings

    Your language choice, open home-page sections, favorites, comparisons, and recent views stay in this browser. Nothing is uploaded.