Back to Guides
Guide7 October 2026

How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. How does Decloak detect exposed secrets in a SPA?
  3. How does Decloak find vulnerable third - party scripts?
  4. What does the free scan cover?
  5. When should I move beyond the free scan?
  6. Quick checklist for a pre - audit SPA review
  7. How to act on the findings
  8. Where to learn more

Key takeaways

How does Decloak detect exposed secrets in a SPA?

Decloak’s free scan examines every file that the browser can request, including inline scripts, external JavaScript bundles and HTML comments. It flags any high - entropy string that looks like an AWS, Google, Stripe or GitHub key, as well as JWTs and private - key blocks. The finding shows the exact location (file and line) but never stores the secret itself, proving the exposure without keeping a copy.

Steps

  1. Open the free Decloak scanner at https://decloak.com/scan.
  2. Paste the public URL of your single - page app and press Start Scan.
  3. Wait ~15 seconds for the report to appear.
  4. In the JavaScript CVE section (Layer 4) look for entries labeled Potential secret in JavaScript - each entry lists the file and a redacted snippet.

How does Decloak find vulnerable third - party scripts?

Layer 4 uses the Retire.js vulnerability database to match library names and versions found in every <script src> tag or bundled file. It also flags dangerous code patterns such as eval(), innerHTML sinks and wildcard postMessage targets. Layer 7 adds platform - specific checks; for example, if a Supabase service_role key appears in client - side code it will be reported as a publicly readable database credential.

Steps

  1. After the scan finishes, expand the JavaScript CVE section.
  2. Review entries that list a library name, version and CVE ID (e.g., jquery 3.4.0 - CVE - 2019 - 11358).
  3. Check the dangerous pattern subsection for eval() or missing Subresource Integrity (integrity attribute).
  4. If the report shows a publicly readable Supabase table or exposed service_role key, treat it as a critical secret leak.

What does the free scan cover?

The free tier runs eight core layers:

  1. HTTP/TLS posture
  2. Static HTML analysis
  3. Rendered - page network behaviour
  4. JavaScript CVE scanning (vulnerable libraries, dangerous patterns, secret strings)
  5. Tag manager intelligence
  6. Third - party domain mapping
  7. Vibe - coded platform security (exposed platform secrets)
  8. AI - written executive summary All of these run without authentication and return a graded, shareable report in about 15 seconds.

When should I move beyond the free scan?

If you need deeper CI/CD integration, consider the paid tiers:

Quick checklist for a pre - audit SPA review

ItemDecloak layerHow to verify
Hard - coded API keys, JWTs, private - key blocksLayer 4 (JavaScript CVE)Look for Potential secret in JavaScript entries
Out - of - date third - party librariesLayer 4 (JavaScript CVE)Review library name, version and CVE list
Missing Subresource Integrity on external scriptsLayer 4 (dangerous pattern)Check for Missing SRI warnings
Mixed - content HTTP resources on HTTPS pageLayer 3 (network behaviour)Look for Mixed content entries
Platform - specific secrets (Supabase service_role, Bubble Data API)Layer 7 (vibe - coded platform)Review Publicly readable database or Exposed service_role findings

How to act on the findings

  1. Remove or rotate any secret that appears in the report. Move it to a server - side environment variable and reference it via a backend endpoint.
  2. Upgrade vulnerable libraries to the latest patched version. If you cannot upgrade immediately, add Subresource Integrity with the correct hash and consider loading the library from a trusted CDN.
  3. Add integrity= attributes to all external scripts and stylesheets.
  4. Fix mixed content by updating all http:// URLs to https:// or proxying them through a secure endpoint.
  5. Enable platform security controls - for Supabase enable Row Level Security on every table and never ship the service_role key to the client.
  6. Re - run the free Decloak scan to confirm the issues are resolved before the formal audit.

Where to learn more


Running Decloak’s free scan gives you a fast, evidence - backed view of secret exposure and vulnerable scripts, letting you fix the most critical problems before an auditor walks through your code.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary